Hall of Fame
We ship infrastructure, not excuses. Security researchers who responsibly disclose vulnerabilities in Onidel systems get credited here.
How reports get classified
Every disclosure is triaged by severity. Higher impact findings get higher rewards β and first crack at the top of the honor roll.
Critical
Full system compromise or arbitrary takeover of another customer's account, e.g. remote code execution with elevated privileges.
High
Exposed platform secrets, auth bypass, or unauthorised access to another customer's data without any victim interaction, e.g. IDOR or SSRF.
Medium
Acting as another customer with some required interaction, or access-control gaps limited to a single service, e.g. stored XSS.
Low
Billing or quota bypass, and other lower-impact issues like open redirects that can't be chained into something more severe.
Informational
Low-risk findings with no direct exploit path, e.g. internal IP leaks, default-config quirks, or verbose non-sensitive errors.
These are illustrative examples, not an exhaustive list. Rewards and severity are determined at our discretion based on real-world impact.
The board
Every researcher who's helped us close a real vulnerability, ranked in the order they were accepted.
> no_entries_found
The board is empty. Submit the first valid report and claim the top slot.
Found a vulnerability?
Report it responsibly and we'll credit you here. We take every submission seriously and move fast to get it fixed.