AA

Arbor AI

Bug bounty Managed triage

Arbor Intelligence, Inc.

Inference, agent tool calling and retrieval. We pay for boundaries crossed, not for text we wish the model had not written.

  • Accepting reports
  • $300 – $20,000
  • 9 assets in scope
  • Launched Aug 2023
  • arbor-ai.example
Submit a report

Read the policy · first response 2 business days

Response times

first response
9 hours
triage
2 days
reward
12 days
resolution
37 days

Program to date

Resolved
738
Total paid
$688K
Thanked
167
Average
$2,744

Rewards by severity

Final amounts depend on demonstrated impact, report quality and asset criticality.

SeverityCVSSRewardTypical findings
Critical 9.0 – 10.0 $7,500 – $20,000 Escape from the tool sandbox to the host, cross-tenant read of weights or checkpoints, retrieval injection that exfiltrates another customer's indexed documents.
High 7.0 – 8.9 $2,800 – $7,000 Tool-call escalation that invokes a tool the calling identity does not hold, injected content that drives an unauthorised write through a connector, inference authentication bypass.
Medium 4.0 – 6.9 $850 – $2,600 Retrieval scoping that returns a document from another workspace in the same tenant, bounded tool-argument injection, cache confusion returning another session's completion.
Low 0.1 – 3.9 $300 – $800 Errors that expose internal routing, missing limits on a billable endpoint, prompt fragments retained in logs past the documented window.

In scope

9 assets listed, 8 eligible for a reward. Anything not on this list is out of scope.

AssetTypeMax severityRewardNotes
https://api.arbor-ai.example/v2 API Critical Eligible Inference: completions, embeddings, batch jobs and file upload. 30 rps sustained; batch work counts against the same budget.
https://agents.arbor-ai.example/v1 API Critical Eligible Agent runtime, tool calling and the code interpreter sandbox. Five concurrent sessions, prefixed bbp-. Escapes to the host pay the ceiling.
arbor-lm-3 (hosted inference endpoint) AI model Critical Eligible Serving path for the flagship model. Reaching another tenant's context or the weights themselves is Critical however ordinary the underlying bug is.
arbor-embed-2 (hosted embedding model) AI model High Eligible Embedding service behind retrieval. Index poisoning and cross-workspace recall are in scope; poison only indexes you own.
https://gateway.arbor-ai.example API High Eligible Enterprise gateway with per-tool policy, in scope since May 2026. Ask for a second workspace before testing anything that crosses tenants here.
https://console.arbor-ai.example URL High Eligible Workspace console: keys, connectors, datasets, billing. Connector credential handling is the part worth your weekend.
weights.arbor-ai.example Network Critical Eligible Artifact storage and the signed-URL service in front of it. Two access-control findings came out of the closed phase in 2025.
https://api.arbor-ai.example/v1 API Medium Eligible Frozen on the 2023 schema, caps at Medium, switches off on 31 January 2027. If it also reproduces on v2, report it on v2.
gallery.arbor-ai.example URL Medium No reward Community connector gallery. We forward to the author and delist anything malicious within a day, but we did not write the code and we do not pay for it.

Out of scope

AssetWhy
Model output quality, refusal behaviour and factual accuracyEvaluation work rather than vulnerability research. The model feedback form reaches the team that owns it and reaches them faster than we would.
playground.arbor-ai.exampleUnauthenticated public sandbox with throwaway state, no tenant data and no connectors attached.
Open-weight models we host without modificationBehaviour inherent to the published weights belongs with the people who published them. Our serving path around them is in scope.
docs.arbor-ai.example and the changelogStatic content, no authentication, nothing customer-specific behind it.
Customer prompts, datasets and agents on the platformOther people's work. If a customer's own agent is badly configured, that is a conversation for them.

Findings that will be closed as informative

  • Making the model produce disallowed, offensive or embarrassing text with no boundary crossed.
  • Single-turn instruction-override prompts that change tone or persona and nothing else.
  • Hallucinated facts, invented citations and arithmetic errors in model output.
  • Roleplay and refusal bypasses where the only outcome is different text on a screen.
  • Recovering the default system prompt, which is published in our documentation.
  • Token-cost inflation and context exhaustion presented as denial of service.
  • Training-data membership guesses with no reproducible extraction behind them.
  • Injection shown only against your own content, in your own workspace, with your own tools.
  • Findings that depend on a customer pasting their own key into a hostile document.
  • Scanner output against the inference API with no manual validation.

Program policy

Program overview

Arbor AI runs a hosted inference API, an agent runtime that calls tools on a customer's behalf, model artifact storage, and a retrieval pipeline that indexes customer documents. About 6,800 organisations build on it. The program opened in August 2023 with the inference API and nothing else; everything that makes it interesting was added later, and each addition is a line in the history beside this policy.

One misunderstanding accounts for more closed reports than every other cause combined, so we settle it here. We pay for prompt injection and agent misbehaviour when it crosses a real trust or privilege boundary. We do not pay for making a language model say something. Those are different claims, and the difference is not how clever the prompt was. In 2024, sixty-one percent of what we closed was the second thing; the taxonomy below was published in February 2025 to stop that, and it worked.

A boundary crossing means the model, or an agent acting on its output, did what the requesting identity was not entitled to do: read another tenant's data, invoke a tool outside the session's grant, write through a connector it does not hold, or reach infrastructure the sandbox exists to contain. If your finding ends with surprising text and nothing else happened, it belongs to the model team and not to us.

Testing rules and expectations

Free workspaces are at console.arbor-ai.example. Since January 2026 you can ask for a second one at no cost for cross-tenant work; say in the report which was the attacker and which the victim.

  • Thirty requests per second on inference and five concurrent agent sessions. Batch jobs draw on the same budget.
  • Put your handle in X-Arbor-Research on every request and prefix agent session names with bbp-.
  • Poison only indexes you own. Never plant a payload in a shared dataset, a gallery connector or another customer's corpus.
  • Stop at proof: one document identifier, one tool invocation, one directory listing from outside the sandbox. Do not enumerate because the model made it easy.
  • Prohibited: denial of service, cost-exhaustion campaigns, social engineering, physical attempts, and anything aimed at the providers we run on.
  • Delete what you retrieved that is not yours within 72 hours, confirm it in the thread, and keep it confidential after the report closes.

The three questions

Answer these before submitting an injection finding. A "no" anywhere closes the report, and we would rather you knew that tonight than in a fortnight.

  1. Did the injected content originate outside the trust boundary of the identity running the session (a retrieved document, a tool response, a page an agent fetched)?
  2. Did the model or the agent then perform an action, rather than produce text?
  3. Was that action outside what the calling identity could have done directly?

Indirect injection through retrieval that makes an agent read and return another tenant's file answers yes three times and pays at Critical. A request that makes the model adopt a persona fails at question two.

Proving write access

If you find a way to write, do not prove it by causing damage. Prove it with the smallest change that can be attributed to you and undone in the same minute.

  • One or two punctuation characters. Delete a full stop, add a comma. Nothing longer, nothing visible, no payload, no changed number or amount.
  • Only on a record you created yourself. Never another user's record, never site content, never anything the public can see.
  • Revert within sixty seconds, in the same run, without being asked.
  • Capture four states: before, after the change, after the revert, and an independent re-read confirming the revert held.
  • If it cannot be reverted, do not change it. Report the write primitive and stop. A row count and a column list already prove database access.

Every request must carry headers that let us separate your traffic from a real attack in our logs:

X-Bug-Bounty:        arbor-ai
X-Research-Account:  <the account you submit the report under>
X-Authorisation-Ref: <engagement or report reference>
X-Request-Id:        <unique per request>
User-Agent:          sentinel-research/<handle> (+<this page>)

scripts/proof_of_write.py performs exactly this sequence, refuses any host outside the scope above, refuses a diff longer than two characters, always attempts the revert, and writes a timestamped evidence file. Run it without --execute first, then attach the evidence to your report.

Safe harbor

Good-faith research inside this scope is authorised. We will not pursue legal action, will not complain to your cloud provider, and if a third party asks whether you were allowed to do this, we will tell them in writing that you were.

Good faith here means you worked in workspaces you control, limited retrieval to what the proof required, degraded nothing for anyone else, and gave us time to fix it. Authorisation ends if you keep another tenant's prompts, documents or embeddings beyond proof, use a sandbox escape to wander into unrelated infrastructure, attempt to reconstruct weights once the access path is proven, or publish before the agreed date.

Reward decisions

CVSS v3.1 sets the band; the boundary crossed sets the position in it. We rank boundaries tenant, workspace, session, tool grant. Anything crossing the tenant boundary is Critical however ordinary the bug looks underneath.

Tool-call escalation is scored by what the tool can do, not by how it was reached. Making a search tool run twice is Low. Driving a write-capable connector to change a record has started at High since September 2026, and is Critical when the record is not yours.

Non-determinism is expected and must be stated: since June 2025 every injection report carries the number of attempts and the number of successes, and the award reflects the rate rather than the best run. We pay once per root cause, so five payloads against one unfiltered retrieval path are one award. Chains earn up to 25% on top, and a regression test we adopt into our evaluation suite earns a flat 1,000 USD.

Disclosure policy

Ninety days from triage, extended by agreement where a fix needs retraining or a model rollout rather than a code change. We tell you which case yours is in the first week, because the two have very different shapes and you should not have to guess.

Publish once the fix ships or the window closes. Redact tenant and workspace identifiers, document contents, customer-derived vectors, internal routing names and checkpoint references. Working payloads may be published in full once mitigated; we have never asked anyone to hold one back.

Report quality

Injection and agent findings reproduce less reliably than ordinary web bugs, so we ask for more than most programs do:

  • Both workspace identifiers, marked attacker and victim, and the model identifier you used.
  • The complete session transcript including tool calls and responses, as text rather than screenshots.
  • The payload verbatim and exactly where it was planted.
  • Attempts and successes, as numbers.
  • The boundary you believe was crossed, mapped to the three questions above.
  • Your X-Arbor-Research handle and the UTC window of the session.

Hall of fame

Researchers who have reported valid issues to this program.

#ResearcherCountryReportsPoints
1 toolcall_tam United States 44 5,980
2 rag_poisoner Finland 37 5,314
3 sandbx India 41 4,602
4 vecn0rm Ukraine 29 4,015
5 dani.oro Spain 33 3,470
6 embedspill Sweden 22 2,905
7 logitbias Taiwan 26 2,431
8 ctxwindow Nigeria 18 2,060
9 connector_mara Czechia 15 1,733
10 tokenizer_tk South Korea 13 1,402
11 grounded_gil Israel 11 1,108
12 promptmule Malaysia 9 844
13 retrieval_rin Japan 8 602
14 toolgrant Chile 5 415

Program updates

  1. Write-capable connectors start at High

    A tool that can change something now scores from the High band up, whatever the injection path looked like. Read-only tool misuse stays where it was.

  2. Enterprise gateway in scope, sandbox escapes at the ceiling

    The per-tool policy gateway is testable at High, and an escape from the interpreter sandbox to the host now pays the full 20,000 USD. That is the single most expensive finding on this program.

  3. Second workspace issued on request

    Cross-tenant work needed two paid workspaces, which priced out exactly the researchers we wanted. Ask and you get a second one within a day, tagged so our detection team knows what it is.

  4. Model artifact storage opened for testing

    The signed-URL service in front of the weight store is in scope. Two access-control findings were fixed during the closed phase before this went public.

  5. Injection reports must state attempts and successes

    After a long argument about a finding that reproduced twice in fifty tries, every non-deterministic report carries its success rate. We pay at the rate the exploit actually achieves, not at its best run, and we say so in the award note.

  6. Injection taxonomy published

    Sixty-one percent of everything we closed in 2024 was a refusal bypass with no boundary crossed. The three questions below are now published so nobody spends a weekend on a report we close in a minute.

  7. Jailbreaks moved out of scope in writing

    Prompts that only change what the model says are not vulnerabilities and never were, but the policy had not said it plainly. It says it plainly now, and the queue halved in a fortnight.

  8. Agent runtime and tool calling added to scope

    Tool calling arrived in the product in April and in the program in June, with the interpreter sandbox as its own scope line. Six of the first twenty reports were valid, which is a better rate than the inference API has ever managed.

  9. Retrieval pipeline in scope, Critical ceiling to 15,000 USD

    Indexing and recall join the program and the top band moves from 6,000. Retrieval is where injected content stops being a prompt and starts being data we trusted.

  10. Open to everyone

    Fifteen weeks of closed testing with eleven researchers ends today. Two of them are still in the top five.

  11. Program launched on the inference API

    Inference only, four bands from 200 to 6,000 USD, and no idea yet how much of the queue would be people asking a model to swear.