Onidel
hall_of_fame.sh

Hall of Fame

We ship infrastructure, not excuses. Security researchers who responsibly disclose vulnerabilities in Onidel systems get credited here.

onidel@security:~
./severity_levels

How reports get classified

Every disclosure is triaged by severity. Higher impact findings get higher rewards β€” and first crack at the top of the honor roll.

Critical

$500

Full system compromise or arbitrary takeover of another customer's account, e.g. remote code execution with elevated privileges.

High

$200 – $400

Exposed platform secrets, auth bypass, or unauthorised access to another customer's data without any victim interaction, e.g. IDOR or SSRF.

Medium

$100 – $200

Acting as another customer with some required interaction, or access-control gaps limited to a single service, e.g. stored XSS.

Low

$25 – $50

Billing or quota bypass, and other lower-impact issues like open redirects that can't be chained into something more severe.

Informational

$0 – $25

Low-risk findings with no direct exploit path, e.g. internal IP leaks, default-config quirks, or verbose non-sensitive errors.

These are illustrative examples, not an exhaustive list. Rewards and severity are determined at our discretion based on real-world impact.

./honor_roll

The board

Every researcher who's helped us close a real vulnerability, ranked in the order they were accepted.

cat honor_roll.log

> no_entries_found

The board is empty. Submit the first valid report and claim the top slot.

Found a vulnerability?

Report it responsibly and we'll credit you here. We take every submission seriously and move fast to get it fixed.