AqtaAqta

Trust centre · Closed programme

Forgery bounty

The forgery bounty ran from 27 August to 12 September 2026 and is closed. No reward, payment or other compensation is offered for any report. While it ran, outside researchers reported real defects in our verifiers. Each was fixed and covered by a published test.

Still worth reporting

A forged receipt, a change to a signed field that a verifier still accepts, a false inclusion proof, a removal hidden from the public log, or bytes on which the TypeScript and Python verifiers disagree. Everything needed is public: the formats and verifiers on GitHub, the published key, the public log, and a production receipt on aqta.ai/verify.

How to report
Email security@aqta.ai with the record or proof, the verifier command that accepts it, and the verifier version. If we reproduce it, we fix it, publish it as a conformance vector and credit you by name if you want. We reply as soon as we can; no response time is promised.
Not in scope
Attacks on Aqta infrastructure, accounts or people: report those to security@aqta.ai under the disclosure policy. Receipts signed with a demo key, which each demo response carries so you can tamper with them. Anything that needs the issuer private key: that is an incident, so tell us immediately.
What a signature never proved
That the computation ran, that every decision was recorded, or that a decision was right. Those limits are in the threat model.

Published by Aqta Technologies Limited, Dublin. Nothing on this page is an offer of payment. Good-faith research under these rules will not be met with legal action.