Bug bounty
The proctoring industry's first public bug bounty.
In scope
| Category | Examples | Severity |
|---|---|---|
| Network escape | DNS tunneling, SNI spoofing, VPN side-channels, DoH/DoT bypass, direct-IP routing to an AI service during an enrolled exam session. | Critical–High |
| Device-side bypass | Process injection, firewall tamper with no telemetry, overlay rendering that evades screen-capture exclusion checks, local-LLM detection evasion. | High–Critical |
| Signal spoofing | Forging HMAC-signed telemetry, impersonating a candidate peer, crafting admin-API requests that bypass the bearer token flow. | High |
Rewards
Reward tiers scale with exploitability and customer impact. Critical findings (unauthenticated network escape or admin takeover) are our highest payouts. Lower-severity findings (rate-limit bypasses, information leaks, client-side UX flaws) still receive recognition and a CVE entry where applicable. We're a limited, invite-friendly program right now; exact amounts are confirmed in writing with each researcher before disclosure.
CVE-log commitment
Every resolved finding is published with affected versions, fix commit, and credit to the researcher (unless anonymity is requested), within 90 days of resolution. We do not bury findings and we do not gag researchers. The public log is launching alongside our first cohort of resolved reports. Until then, resolved-finding summaries are shared directly with the reporting researcher.
For disclosure, email security@aiseptor.com directly with a repro and severity estimate. This inbox is triaged by the security team, not routed through general support. PGP key available on request. Full program terms and scope addenda are published alongside the CVE log.