Auriga Retail
PublicManaged triageAuriga Retail welcomes research across its storefront, shopping apps and checkout API. Anything that lets an attacker change a price, take over an account or read another customer's order is treated as critical.
Scope
Rewards by severity
| Severity | Examples | Bounty |
|---|---|---|
| Critical | RCE, auth bypass, mass data exposure | $2,400 – $6,000 |
| High | SSRF, stored XSS, privilege escalation | $920 – $2,300 |
| Medium | IDOR, CSRF on sensitive actions | $220 – $560 |
| Low | Reflected XSS, minor info disclosure | $40 – $110 |
Rules & policy
Test only assets listed in scope. Never access, modify or delete data that does not belong to your test account.
Use your own test accounts. Stop immediately if you encounter another user's data and report it.
No denial-of-service, automated scanning at scale, or social engineering of staff or users.
Report each vulnerability once, with clear reproduction steps and evidence. Duplicates are closed against the earliest valid report.
Keep findings confidential until Auriga confirms a fix and agrees to disclosure. Good-faith research is authorized and will not be pursued legally.
Recent activity
Found something on Auriga Retail?
Submit a structured report with steps and evidence. Managed triage reviews it, and a valid finding is rewarded by severity.