> ## Documentation Index
> Fetch the complete documentation index at: https://www.diadata.org/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Bounty Program

> If you report security issues within our live backend, smart contracts, and production operations, we offer a security bounty program. DIA Security Bounty awards are granted solely at DIA's discretion. You agree that submitting a report does not guarantee that you will be eligible for a reward. To be eligible for a bounty, be sure to follow these requirements:

1. Make sure you can describe the security issue you found in a concise and reproducible way.

2. The security issue is part of the live backend, smart contracts, and production operations. Deprecated components are explicitly not eligible for rewards.

3. Contact us first. If you use or publish the vulnerability you will not be eligible for a bounty payout. Our contact address is [security@diadata.org](mailto:security@diadata.org).

4. Give us time to assess and address the issue. Sometimes behaviour can be perceived as security issue.

We will grade severity of reported issues and use the CVSS scale as a guideline. The ultimate decision about the severity we consider to be achieved remains in our discretion.

|          |                  |
| -------- | ---------------- |
| Severity | Payout           |
| Low      | 500 - 2500 USDC  |
| Medium   | 2500 - 5000 USDC |
| High     | 5000 - 7500 USDC |

Payouts will be conducted in an established ERC20 stablecoin like USDC. Please make sure to be able to receive ERC20 tokens. We will also require an invoice and identification in order to settle any payment.
