Good-faith testing only
Test only systems and accounts you own or have explicit permission to use.
Help secure Nixtla, TimeGPT, and the open forecasting ecosystem before risks reach production.
Focus on vulnerabilities that could affect TimeGPT workflows, customer operations, open source packages, or the public Nixtla web experience.
Simple steps from first report to researcher credit. We aim for clarity, speed, and fair recognition.
[01]
Submit
Send a clear report with affected surface, impact, reproduction steps, and evidence.
[02]
Triage
We acknowledge the report and prioritize it by reach, exploitability, and harm.
[03]
Validate
The issue is reproduced, scoped, and mapped to a practical remediation path.
[04]
Reward
Eligible reports are reviewed for severity, quality, novelty, and remediation help.
[05]
Credit
Researchers can receive public credit after coordinated disclosure is complete.
Rewards are based on practical risk, report quality, exploitability, affected surface, and remediation value.
| Severity | Qualifying Impact | Examples | Reward Range | Triage |
|---|---|---|---|---|
| Critical [P0] | Full system compromise or unauthorized broad data access | RCE, admin takeover, mass secret exposure | UP TO $10,000 | 24 hours |
| High [P1] | Significant impact requiring limited interaction | Privilege escalation, auth bypass, sensitive exposure | UP TO $5,000 | 48 hours |
| Medium [P2] | Limited impact or partial compromise | Stored XSS, IDOR with low impact, information disclosure | $100 - $500 | 3 days |
| Low [P3] | Minor issue with limited security impact | Reflected XSS, weak headers, minor misconfiguration | $25 - $100 | 7 days |
These rules protect researchers, customers, and Nixtla systems while allowing useful security work to move quickly.
Safe Harbor
If you follow the rules and avoid harm, we will work with you to review, validate, and remediate the report.
/ Ask A Question +Test only systems and accounts you own or have explicit permission to use.
Do not access, modify, retain, or exfiltrate customer or personal data.
Do not attempt phishing, vishing, baiting, employee targeting, or physical intrusion.
Do not perform attacks that degrade, disrupt, or test service capacity.
Report privately and wait for a coordinated disclosure window before publishing.
Comply with all laws and stay inside the published program scope.
Share the affected surface, security impact, reproduction steps, and evidence so we can validate the issue quickly.