Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Avalara
Avalara HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Avalara? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 3 Oct 2026.

What it pays, by severity

Critical amount not published 15 reports
High amount not published 42 reports
Medium amount not published 159 reports
Low amount not published 97 reports

Intake & responsiveness · last 90 days

Reports received
30
in 90 days
Resolved
325
all time, last one 19 days ago
Participants
208
hunters engaged
Response efficiency
50%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 16 days 30–40
6 Sep 30 reports 3 Oct

Response targets it sets itself

First response
1 day
Triage
10 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 43 days (24 snapshots): intake up 2 reports; response efficiency down 7 points.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

216 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 vulnera 745 117 / 134 87%
2 arielrachamim 161 23 / 23 100%
3 csc_ 85 15 / 15 100%
4 sadra_asadi 70 11 / 13 85%
4 swapnil755 56 7 / 7 100%
5 tejaspawar172000 49 6 / 7 86%
6 thpless 44 4 / 8 50%
7 me_satori 40 10 / 10 100%
8 afb 35 5 / 5 100%
8 m0hsn 35 5 / 5 100%
8 xbow 35 6 / 8 75%
11 thebee0x 34 7 / 9 78%
12 demon1c 32 11 / 12 92%
13 0xa1w 28 4 / 4 100%
13 ayaa101 28 5 / 10 50%
13 rocket_the_raccoon 28 4 / 4 100%
15 drakenkun 23 4 / 9 44%
15 rocky_y 23 4 / 5 80%
15 xpp3rt 23 4 / 4 100%
18 dk4trin 21 3 / 3 100%
18 erickfernandox 21 3 / 3 100%
18 rjz4 21 3 / 4 75%
21 ashiquremon63 20 5 / 10 50%
22 ar6aaz 18 4 / 4 100%
22 mysanismine 18 4 / 4 100%

Showing the top 25 of 216 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 1 Oct 2026.

Tax compliance software for your industry and tax type.

Responsiveness
50% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Oct 2022
Scope entries
15 HackerOne’s count

Scope

15 assets
AssetTypeEligibilityMax severity
*.3ce.com WILDCARD submit only Critical
*.avalara.com WILDCARD submit only Critical
*.avalara.io WILDCARD submit only Critical
*.avalara.net WILDCARD submit only Critical
*.avalarabrasil.com.br WILDCARD submit only Critical
Show all 15 assets
AssetTypeEligibilityMax severity
*.certexpress.com WILDCARD submit only Critical
*.crowdreason.com WILDCARD submit only Critical
*.davosalestax.com WILDCARD submit only Critical
*.impendulo.com WILDCARD submit only Critical
*.inposia.com WILDCARD submit only Critical
*.netleglobal.com WILDCARD submit only Critical
*.papercrane.io WILDCARD submit only Critical
*.track1099.com WILDCARD submit only Critical
*.ttrus.com WILDCARD submit only Critical
avalara.com URL submit only Critical