Olaa

Security

Report a vulnerability.

Email security@olaa.com. You hear back within two business days; criticals are fixed within seven.

Scope

olaa.com, app.olaa.com, api.olaa.com, pages/spaces hosts, the Slack/Teams/Discord apps. Out of scope: third-party services, social engineering, denial of service, automated scanning that degrades service.

Bounty

Critical (tenant isolation, credential exposure, approval bypass): $2,000–$10,000. High: $500–$2,000. Medium: $100–$500. Paid in cash or Olaa credits (worth 50% more). Duplicates and known issues listed here are not eligible.

Safe harbor

Good-faith research that follows this policy will not lead to legal action. Do not access data that is not yours; stop and report as soon as you confirm an issue.

Thanks

Researchers who report valid issues are listed here with their permission.