Bug bounty

Find a security bug. Get paid for it.

My AI Fin App holds people's bank connections, budgets and debts. If you find a way to reach data that isn't yours, I want to hear it from you first, and I'll pay for it. This page says what's in scope, what isn't, how to test without hurting anyone, and what happens after you write in.

Report a vulnerability

Paid rewards

Valid, original reports are rewarded. The amount depends on severity and the quality of the report.

Safe harbor

Good-faith research under these rules is authorized. I won't pursue you for it.

A person replies

Reports go to the person who builds the app. Expect a first reply within a few business days.

In scope

Anything a signed-in user can reach, and the pieces behind it:

  • The web app at www.myaifin.app, including everything under /app.
  • The edge functions the app calls on qvmgeoeigwztyrzayykn.supabase.co/functions/v1/.
  • The database's access rules: reading or changing another household's rows is exactly what this program exists for.
  • The assistant connector at www.myaifin.app/mcp, its OAuth endpoints, and personal access tokens.
  • The iOS and Android apps.
  • Sign-in, two-factor authentication, password reset, account recovery and household invitations.

What I care about most

  • Reading or changing another user's or another household's financial data.
  • Taking over an account, or getting past two-factor authentication.
  • Getting hold of a bank connection token, or acting on someone else's bank connection.
  • Calling an edge function or the assistant connector as someone you aren't.
  • Stored cross-site scripting, server-side request forgery, or code execution on anything in scope.

Out of scope

These aren't eligible for a reward. Some are real problems for someone else; report those to that someone.

  • The infrastructure of Plaid, Supabase, Vercel, Google or Apple. Report those to their own programs.
  • Denial of service, load testing, or anything that degrades the app for other people.
  • Social engineering, phishing, or physical attacks against users or anyone who works on the app.
  • Findings from automated scanners without a working proof of impact.
  • Missing security headers, cookie flags, or email records (SPF, DKIM, DMARC) with no demonstrated impact.
  • Clickjacking on pages with no sensitive action, self-XSS, and logout CSRF.
  • Rate limits on endpoints that don't guard a secret or cost money.
  • Version numbers, stack traces, or outdated libraries without a way to exploit them.
  • Anything that needs a rooted or jailbroken phone, or someone else's unlocked device in your hand.

Rules of engagement

  • Test only against accounts you created. To test household isolation, make two free accounts and try to cross from one to the other.
  • If you see data that isn't yours, stop. Don't keep it, change it, or look further; say what you saw in your report.
  • Don't connect anyone's bank but your own, and don't disconnect or disturb other people's connections.
  • Keep automated traffic low. Nothing that would slow the app down for real households.
  • One vulnerability per report, unless several only matter together.
  • Keep it private until it's fixed, or for 90 days after you report it, whichever comes first. We can agree on a different date.
  • Asking for payment before you'll share the details is extortion, not research, and ends the conversation.

Rewards

Amounts aren't published. Each valid report is paid according to its real-world impact, how much of that impact you demonstrated, and how clear the report is. A short, reproducible report of a critical bug earns more than a long one about a minor one.

Critical

Highest reward

Reading or changing any household's data, account takeover without user interaction, stealing bank connection tokens.

High

Significant reward

Bypassing two-factor authentication, stored XSS in the app, acting as another user through an edge function.

Medium

Reward

Leaking limited personal data of another user, CSRF on a sensitive action, weaknesses in invitation or reset links.

Low

Credit, and a reward at my discretion

Issues with real but small impact, or that need unlikely conditions.

  • The first report of an issue gets the reward. Later duplicates get thanks.
  • Rewards are paid once the issue is confirmed, by a method we agree on.
  • You're responsible for any tax on a reward. I can't pay where the law forbids it, including to people on sanctions lists.

How to report

support@myaifin.app

Email the address below with "Security" in the subject line. Please include:

  • What you found, and how serious you think it is.
  • Step-by-step reproduction: the URLs, the requests, and the accounts you used (yours).
  • What an attacker could actually do with it.
  • Anything you saw that wasn't yours. Say so, and stop there.
  • How you'd like to be credited, if at all.

What happens next

  1. 1

    Acknowledged

    A reply within a few business days confirming I have your report.

  2. 2

    Assessed

    I reproduce it and tell you the severity I've given it, usually within two weeks.

  3. 3

    Fixed

    I fix it and let you know, so you can check the fix if you'd like.

  4. 4

    Paid and credited

    The reward is paid, and you're added to the thanks list below if you want to be.

Safe harbor

If you follow this page in good faith, I consider your research authorized. I won't take legal action against you or report you to law enforcement for it, and if a third party takes action against you over research that followed these rules, I'll make it known that it was authorized.

Good faith means you avoided harm to users, didn't access or keep more data than you needed to show the problem, and gave me reasonable time to fix it before telling anyone else. If you're unsure whether something is allowed, ask first.

Thanks

No one yet. The first name here could be yours.

This program is run at my discretion and may change or end at any time. Rewards are decided case by case. Testing that breaks these rules isn't covered by safe harbor.