Vulnerability Disclosure Policy

Amberior Ltd welcomes reports of security vulnerabilities affecting our website. This policy explains how to report an issue and what to expect.

Last updated: .

Scope

This policy covers the public website at https://amberior.com/. Other subdomains, email services, third-party services, and future products are outside its scope.

Report an issue

Email with the affected URL, a description of the issue and its potential impact, and steps to reproduce it. Include only the evidence needed to explain the problem.

Do not send passwords, access tokens, or personal data. If sensitive evidence is necessary, contact us first to arrange a suitable way to share it.

Testing boundaries

You may report issues encountered during normal use of the website. Contact us for written permission before carrying out active security testing. This policy does not grant permission to access non-public systems or test third-party infrastructure.

Do not disrupt the website, run denial-of-service tests, use social engineering, or access, modify, or delete other people's data. If you encounter sensitive data, stop and report the issue without investigating further.

Our response and disclosure

We aim to acknowledge reports within five working days. We will review the issue, ask for more information if needed, and keep you informed of relevant progress. Resolution time depends on the nature of the issue.

Please give us reasonable time to investigate and address the issue before publishing details, and contact us to coordinate disclosure. We will agree any public acknowledgement with you before naming you.

This is a reporting process, not a paid bug bounty programme.

Security contact and responsibilities