Why we run this program
Gladia processes audio for enterprises — sales calls, medical consultations, customer support, and voice agents. That data is often sensitive, sometimes regulated, and always someone else's. We're SOC 2 and ISO 27001 certified, independently audited for HIPAA compliance, and GDPR compliant, because our customers can't afford a breach.
No internal team catches everything — our API surface is large and constantly evolving. We run this program because we'd rather hear about a vulnerability from a researcher than from a customer. If you find one, we want to know, and we'll reward you for it.
In-scope assets
| Asset | Priority |
|---|---|
| api.gladia.io | Highest |
| app.gladia.io | High |
| Official SDKs (npm, PyPI) | Medium |
| gladia.io | Low |
Out-of-scope
- All other
*.gladia.iosubdomains - Third-party services (Intercom, Stripe dashboard, Google Workspace)
- Social engineering or phishing attacks on staff
- Physical security
- Denial of Service (DoS/DDoS)
- Assets not owned or operated by Gladia
- Vulnerabilities requiring physical access
- Reports from automated scanners without manual validation
Qualifying vulnerabilities
- Authentication or authorization bypass
- Cross-tenant data access
- SQL/NoSQL injection
- Remote code execution
- Server-side request forgery (SSRF)
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Webhook signature bypass or replay
- Audio data leakage across accounts
- API key or token leakage
- Any vulnerability impacting the confidentiality, integrity, or availability of user data
Non-qualifying issues
- Missing or invalid HTTP headers (without demonstrated impact)
- Cookie flags
- Clickjacking (without demonstrated impact)
- SSL/TLS configuration issues
- Account enumeration
- SPF/DKIM issues
- Rate-limiting issues
- Password policy issues
- Self-exploitation
- Issues with no demonstrable security impact
- Results from automated scanning tools without manual validation
Research guidelines
Do
- Test only against assets explicitly listed as in-scope
- Use your own test accounts, and only your own data
- Stop as soon as you confirm a vulnerability, and report it promptly
- Keep the details confidential until we've deployed a fix
- Give us reasonable time to remediate before any disclosure
Do not
- Access, modify, or delete data belonging to other users
- Exfiltrate or retain any data you encounter, including audio and transcripts
- Degrade or disrupt our services (no DoS/DDoS, spam, or load testing)
- Use social engineering, phishing, or physical attacks against Gladia staff or facilities
- Run automated scanners that generate high volumes of traffic without prior agreement
- Publicly disclose a vulnerability before it is resolved and coordinated with us
Rewards
| Severity | Reward |
|---|---|
| Critical | $2,000 |
| High | $1,000 |
| Medium | $250 |
| Low | $50 |
Rewards are determined by the Gladia security team based on severity and impact. Non-security issues are not eligible for monetary rewards.
Response SLAs
| Stage | Timeline |
|---|---|
| Acknowledgment | 5 business days |
| Triage decision | 15 business days |
| Payment (after fix verification) | 30 business days |
Safe harbor
Gladia SAS and Gladia Inc. consider security research conducted in good faith under this policy to be authorized activity. If you comply with this policy, we will:
- Consider your research authorized and lawful, and will not initiate or support legal action against you for it
- Not report your activity to law enforcement, and will make it known that your actions were conducted in compliance with this policy should any third party pursue legal action
- Work with you to understand and resolve the issue quickly
- Protect your identity and keep your report confidential, and not share your personal information without your consent
This authorization applies only to activity that:
- Is limited to the in-scope assets listed above
- Acts in good faith and complies with this policy and applicable law
- Does not access, disclose, alter, or delete data belonging to other users
- Does not disrupt or degrade Gladia services
- Reports vulnerabilities promptly and does not publicly disclose them before resolution
If in doubt about whether a specific action is authorized, contact us at security@gladia.io before proceeding.
Coordinated disclosure
Researchers may publicly disclose vulnerability details 90 days after the fix is deployed, or sooner with written mutual agreement. Disclosure must:
- Not include exploit code that could harm Gladia customers
- Reference the Gladia Bug Bounty Program
- Be shared with us in draft form 5 business days before publication
How to report
Submit all reports through our dedicated form at gladia.io/bug-bounty-report. Include:
- Description of the vulnerability
- Steps to reproduce
- Affected asset and endpoint
- Impact assessment
- Any supporting evidence (screenshots, logs, proof of concept)
Please submit vulnerabilities through the form rather than by email — we use it to ensure fair precedence. For any questions about the program, reach us at security@gladia.io.
Eligibility
- Must not be a current or former Gladia employee
- Must not violate any applicable law
- Must be the first to report the vulnerability
- Must not publicly disclose before fix
Hall of fame
With permission, we credit researchers who responsibly disclose valid vulnerabilities.