Submit
Send a clear report with affected surface, impact, reproduction steps, and evidence.
Help secure Nixtla, TimeGPT, and the open forecasting ecosystem before risks reach production.
01 - Program Scope
Focus on vulnerabilities that could affect TimeGPT workflows, customer operations, open source packages, or the public Nixtla web experience.
02 - Report Flow
Simple steps from first report to researcher credit. We aim for clarity, speed, and fair recognition.
Send a clear report with affected surface, impact, reproduction steps, and evidence.
We acknowledge the report and prioritize it by reach, exploitability, and harm.
The issue is reproduced, scoped, and mapped to a practical remediation path.
Eligible reports are reviewed for severity, quality, novelty, and remediation help.
Researchers can receive public credit after coordinated disclosure is complete.
03 - Rewards
Rewards are based on practical risk, report quality, exploitability, affected surface, and remediation value.
| Severity | Qualifying Impact | Examples | Reward Range | Triage |
|---|---|---|---|---|
| Critical [P0] | Full system compromise or unauthorized broad data access | RCE, admin takeover, mass secret exposure | $5,000 - $10,000+ | 24 hours |
| High [P1] | Significant impact requiring limited interaction | Privilege escalation, auth bypass, sensitive exposure | $500 - $5,000 | 48 hours |
| Medium [P2] | Limited impact or partial compromise | Stored XSS, IDOR with low impact, information disclosure | $100 - $500 | 3 days |
| Low [P3] | Minor issue with limited security impact | Reflected XSS, weak headers, minor misconfiguration | $25 - $100 | 7 days |
04 - Rules And Safe Harbor
These rules protect researchers, customers, and Nixtla systems while allowing useful security work to move quickly.
Safe Harbor
If you follow the rules and avoid harm, we will work with you to review, validate, and remediate the report.
/ Ask A Question +Test only systems and accounts you own or have explicit permission to use.
Do not access, modify, retain, or exfiltrate customer or personal data.
Do not attempt phishing, vishing, baiting, employee targeting, or physical intrusion.
Do not perform attacks that degrade, disrupt, or test service capacity.
Report privately and wait for a coordinated disclosure window before publishing.
Comply with all laws and stay inside the published program scope.
Ready to report
Share the affected surface, security impact, reproduction steps, and evidence so we can validate the issue quickly.