Security
Report a vulnerability.
Email security@olaa.com. You hear back within two business days; criticals are fixed within seven.
Scope
olaa.com, app.olaa.com, api.olaa.com, pages/spaces hosts, the Slack/Teams/Discord apps. Out of scope: third-party services, social engineering, denial of service, automated scanning that degrades service.
Bounty
Critical (tenant isolation, credential exposure, approval bypass): $2,000–$10,000. High: $500–$2,000. Medium: $100–$500. Paid in cash or Olaa credits (worth 50% more). Duplicates and known issues listed here are not eligible.
Safe harbor
Good-faith research that follows this policy will not lead to legal action. Do not access data that is not yours; stop and report as soon as you confirm an issue.
Thanks
Researchers who report valid issues are listed here with their permission.