Arbor AI
Bug bounty Managed triageArbor Intelligence, Inc.
Inference, agent tool calling and retrieval. We pay for boundaries crossed, not for text we wish the model had not written.
- Accepting reports
- $300 – $20,000
- 9 assets in scope
- Launched Aug 2023
- arbor-ai.example
Read the policy · first response 2 business days
Response times
- first response
- 9 hours
- triage
- 2 days
- reward
- 12 days
- resolution
- 37 days
Program to date
- Resolved
- 738
- Total paid
- $688K
- Thanked
- 167
- Average
- $2,744
Rewards by severity
Final amounts depend on demonstrated impact, report quality and asset criticality.
| Severity | CVSS | Reward | Typical findings |
|---|---|---|---|
| Critical | 9.0 – 10.0 | $7,500 – $20,000 | Escape from the tool sandbox to the host, cross-tenant read of weights or checkpoints, retrieval injection that exfiltrates another customer's indexed documents. |
| High | 7.0 – 8.9 | $2,800 – $7,000 | Tool-call escalation that invokes a tool the calling identity does not hold, injected content that drives an unauthorised write through a connector, inference authentication bypass. |
| Medium | 4.0 – 6.9 | $850 – $2,600 | Retrieval scoping that returns a document from another workspace in the same tenant, bounded tool-argument injection, cache confusion returning another session's completion. |
| Low | 0.1 – 3.9 | $300 – $800 | Errors that expose internal routing, missing limits on a billable endpoint, prompt fragments retained in logs past the documented window. |
In scope
9 assets listed, 8 eligible for a reward. Anything not on this list is out of scope.
| Asset | Type | Max severity | Reward | Notes |
|---|---|---|---|---|
| https://api.arbor-ai.example/v2 | API | Critical | Eligible | Inference: completions, embeddings, batch jobs and file upload. 30 rps sustained; batch work counts against the same budget. |
| https://agents.arbor-ai.example/v1 | API | Critical | Eligible | Agent runtime, tool calling and the code interpreter sandbox. Five concurrent sessions, prefixed bbp-. Escapes to the host pay the ceiling. |
| arbor-lm-3 (hosted inference endpoint) | AI model | Critical | Eligible | Serving path for the flagship model. Reaching another tenant's context or the weights themselves is Critical however ordinary the underlying bug is. |
| arbor-embed-2 (hosted embedding model) | AI model | High | Eligible | Embedding service behind retrieval. Index poisoning and cross-workspace recall are in scope; poison only indexes you own. |
| https://gateway.arbor-ai.example | API | High | Eligible | Enterprise gateway with per-tool policy, in scope since May 2026. Ask for a second workspace before testing anything that crosses tenants here. |
| https://console.arbor-ai.example | URL | High | Eligible | Workspace console: keys, connectors, datasets, billing. Connector credential handling is the part worth your weekend. |
| weights.arbor-ai.example | Network | Critical | Eligible | Artifact storage and the signed-URL service in front of it. Two access-control findings came out of the closed phase in 2025. |
| https://api.arbor-ai.example/v1 | API | Medium | Eligible | Frozen on the 2023 schema, caps at Medium, switches off on 31 January 2027. If it also reproduces on v2, report it on v2. |
| gallery.arbor-ai.example | URL | Medium | No reward | Community connector gallery. We forward to the author and delist anything malicious within a day, but we did not write the code and we do not pay for it. |
Out of scope
| Asset | Why |
|---|---|
| Model output quality, refusal behaviour and factual accuracy | Evaluation work rather than vulnerability research. The model feedback form reaches the team that owns it and reaches them faster than we would. |
| playground.arbor-ai.example | Unauthenticated public sandbox with throwaway state, no tenant data and no connectors attached. |
| Open-weight models we host without modification | Behaviour inherent to the published weights belongs with the people who published them. Our serving path around them is in scope. |
| docs.arbor-ai.example and the changelog | Static content, no authentication, nothing customer-specific behind it. |
| Customer prompts, datasets and agents on the platform | Other people's work. If a customer's own agent is badly configured, that is a conversation for them. |
Findings that will be closed as informative
- Making the model produce disallowed, offensive or embarrassing text with no boundary crossed.
- Single-turn instruction-override prompts that change tone or persona and nothing else.
- Hallucinated facts, invented citations and arithmetic errors in model output.
- Roleplay and refusal bypasses where the only outcome is different text on a screen.
- Recovering the default system prompt, which is published in our documentation.
- Token-cost inflation and context exhaustion presented as denial of service.
- Training-data membership guesses with no reproducible extraction behind them.
- Injection shown only against your own content, in your own workspace, with your own tools.
- Findings that depend on a customer pasting their own key into a hostile document.
- Scanner output against the inference API with no manual validation.
Program policy
Program overview
Arbor AI runs a hosted inference API, an agent runtime that calls tools on a customer's behalf, model artifact storage, and a retrieval pipeline that indexes customer documents. About 6,800 organisations build on it. The program opened in August 2023 with the inference API and nothing else; everything that makes it interesting was added later, and each addition is a line in the history beside this policy.
One misunderstanding accounts for more closed reports than every other cause combined, so we settle it here. We pay for prompt injection and agent misbehaviour when it crosses a real trust or privilege boundary. We do not pay for making a language model say something. Those are different claims, and the difference is not how clever the prompt was. In 2024, sixty-one percent of what we closed was the second thing; the taxonomy below was published in February 2025 to stop that, and it worked.
A boundary crossing means the model, or an agent acting on its output, did what the requesting identity was not entitled to do: read another tenant's data, invoke a tool outside the session's grant, write through a connector it does not hold, or reach infrastructure the sandbox exists to contain. If your finding ends with surprising text and nothing else happened, it belongs to the model team and not to us.
Testing rules and expectations
Free workspaces are at console.arbor-ai.example. Since January 2026 you can ask for a second one at no cost for cross-tenant work; say in the report which was the attacker and which the victim.
- Thirty requests per second on inference and five concurrent agent sessions. Batch jobs draw on the same budget.
- Put your handle in
X-Arbor-Researchon every request and prefix agent session names withbbp-. - Poison only indexes you own. Never plant a payload in a shared dataset, a gallery connector or another customer's corpus.
- Stop at proof: one document identifier, one tool invocation, one directory listing from outside the sandbox. Do not enumerate because the model made it easy.
- Prohibited: denial of service, cost-exhaustion campaigns, social engineering, physical attempts, and anything aimed at the providers we run on.
- Delete what you retrieved that is not yours within 72 hours, confirm it in the thread, and keep it confidential after the report closes.
The three questions
Answer these before submitting an injection finding. A "no" anywhere closes the report, and we would rather you knew that tonight than in a fortnight.
- Did the injected content originate outside the trust boundary of the identity running the session (a retrieved document, a tool response, a page an agent fetched)?
- Did the model or the agent then perform an action, rather than produce text?
- Was that action outside what the calling identity could have done directly?
Indirect injection through retrieval that makes an agent read and return another tenant's file answers yes three times and pays at Critical. A request that makes the model adopt a persona fails at question two.
Proving write access
If you find a way to write, do not prove it by causing damage. Prove it with the smallest change that can be attributed to you and undone in the same minute.
- One or two punctuation characters. Delete a full stop, add a comma. Nothing longer, nothing visible, no payload, no changed number or amount.
- Only on a record you created yourself. Never another user's record, never site content, never anything the public can see.
- Revert within sixty seconds, in the same run, without being asked.
- Capture four states: before, after the change, after the revert, and an independent re-read confirming the revert held.
- If it cannot be reverted, do not change it. Report the write primitive and stop. A row count and a column list already prove database access.
Every request must carry headers that let us separate your traffic from a real attack in our logs:
X-Bug-Bounty: arbor-ai
X-Research-Account: <the account you submit the report under>
X-Authorisation-Ref: <engagement or report reference>
X-Request-Id: <unique per request>
User-Agent: sentinel-research/<handle> (+<this page>)
scripts/proof_of_write.py performs exactly this sequence, refuses any host
outside the scope above, refuses a diff longer than two characters, always
attempts the revert, and writes a timestamped evidence file. Run it without
--execute first, then attach the evidence to your report.
Safe harbor
Good-faith research inside this scope is authorised. We will not pursue legal action, will not complain to your cloud provider, and if a third party asks whether you were allowed to do this, we will tell them in writing that you were.
Good faith here means you worked in workspaces you control, limited retrieval to what the proof required, degraded nothing for anyone else, and gave us time to fix it. Authorisation ends if you keep another tenant's prompts, documents or embeddings beyond proof, use a sandbox escape to wander into unrelated infrastructure, attempt to reconstruct weights once the access path is proven, or publish before the agreed date.
Reward decisions
CVSS v3.1 sets the band; the boundary crossed sets the position in it. We rank boundaries tenant, workspace, session, tool grant. Anything crossing the tenant boundary is Critical however ordinary the bug looks underneath.
Tool-call escalation is scored by what the tool can do, not by how it was reached. Making a search tool run twice is Low. Driving a write-capable connector to change a record has started at High since September 2026, and is Critical when the record is not yours.
Non-determinism is expected and must be stated: since June 2025 every injection report carries the number of attempts and the number of successes, and the award reflects the rate rather than the best run. We pay once per root cause, so five payloads against one unfiltered retrieval path are one award. Chains earn up to 25% on top, and a regression test we adopt into our evaluation suite earns a flat 1,000 USD.
Disclosure policy
Ninety days from triage, extended by agreement where a fix needs retraining or a model rollout rather than a code change. We tell you which case yours is in the first week, because the two have very different shapes and you should not have to guess.
Publish once the fix ships or the window closes. Redact tenant and workspace identifiers, document contents, customer-derived vectors, internal routing names and checkpoint references. Working payloads may be published in full once mitigated; we have never asked anyone to hold one back.
Report quality
Injection and agent findings reproduce less reliably than ordinary web bugs, so we ask for more than most programs do:
- Both workspace identifiers, marked attacker and victim, and the model identifier you used.
- The complete session transcript including tool calls and responses, as text rather than screenshots.
- The payload verbatim and exactly where it was planted.
- Attempts and successes, as numbers.
- The boundary you believe was crossed, mapped to the three questions above.
- Your
X-Arbor-Researchhandle and the UTC window of the session.
Hall of fame
Researchers who have reported valid issues to this program.
| # | Researcher | Country | Reports | Points |
|---|---|---|---|---|
| 1 | toolcall_tam | United States | 44 | 5,980 |
| 2 | rag_poisoner | Finland | 37 | 5,314 |
| 3 | sandbx | India | 41 | 4,602 |
| 4 | vecn0rm | Ukraine | 29 | 4,015 |
| 5 | dani.oro | Spain | 33 | 3,470 |
| 6 | embedspill | Sweden | 22 | 2,905 |
| 7 | logitbias | Taiwan | 26 | 2,431 |
| 8 | ctxwindow | Nigeria | 18 | 2,060 |
| 9 | connector_mara | Czechia | 15 | 1,733 |
| 10 | tokenizer_tk | South Korea | 13 | 1,402 |
| 11 | grounded_gil | Israel | 11 | 1,108 |
| 12 | promptmule | Malaysia | 9 | 844 |
| 13 | retrieval_rin | Japan | 8 | 602 |
| 14 | toolgrant | Chile | 5 | 415 |
Program updates
-
Write-capable connectors start at High
A tool that can change something now scores from the High band up, whatever the injection path looked like. Read-only tool misuse stays where it was.
-
Enterprise gateway in scope, sandbox escapes at the ceiling
The per-tool policy gateway is testable at High, and an escape from the interpreter sandbox to the host now pays the full 20,000 USD. That is the single most expensive finding on this program.
-
Second workspace issued on request
Cross-tenant work needed two paid workspaces, which priced out exactly the researchers we wanted. Ask and you get a second one within a day, tagged so our detection team knows what it is.
-
Model artifact storage opened for testing
The signed-URL service in front of the weight store is in scope. Two access-control findings were fixed during the closed phase before this went public.
-
Injection reports must state attempts and successes
After a long argument about a finding that reproduced twice in fifty tries, every non-deterministic report carries its success rate. We pay at the rate the exploit actually achieves, not at its best run, and we say so in the award note.
-
Injection taxonomy published
Sixty-one percent of everything we closed in 2024 was a refusal bypass with no boundary crossed. The three questions below are now published so nobody spends a weekend on a report we close in a minute.
-
Jailbreaks moved out of scope in writing
Prompts that only change what the model says are not vulnerabilities and never were, but the policy had not said it plainly. It says it plainly now, and the queue halved in a fortnight.
-
Agent runtime and tool calling added to scope
Tool calling arrived in the product in April and in the program in June, with the interpreter sandbox as its own scope line. Six of the first twenty reports were valid, which is a better rate than the inference API has ever managed.
-
Retrieval pipeline in scope, Critical ceiling to 15,000 USD
Indexing and recall join the program and the top band moves from 6,000. Retrieval is where injected content stops being a prompt and starts being data we trusted.
-
Open to everyone
Fifteen weeks of closed testing with eleven researchers ends today. Two of them are still in the top five.
-
Program launched on the inference API
Inference only, four bands from 200 to 6,000 USD, and no idea yet how much of the queue would be people asking a model to swear.