If you have found a security issue in any AmpVerve product or service, we want to hear from you and we will not take legal action against good-faith research.
How to report
Email security@ampverve.com. PGP encryption is supported; request our current public key in your first message.
What to include
A clear description of the issue and the asset affected (URL, component, or service name)
Steps to reproduce, including any required accounts, payloads or proof-of-concept
The impact you believe the issue has, and any suggested mitigation
Your name or handle for credit, if you would like to be acknowledged
Our commitments
Acknowledgement within 5 business days of your report
Triage within 10 business days, with a CVSS severity assigned
Fix targets: Critical 30 days, High 60 days, Medium 90 days, Low best-effort
Coordinated disclosure: we agree a public-disclosure timeline with you, defaulting to 90 days from triage
Safe harbor
AmpVerve will not pursue legal action against researchers who:
Make a good-faith effort to avoid privacy violations, destruction of data, and degradation of service
Only interact with accounts they own or have explicit permission to access
Stop testing as soon as a vulnerability is confirmed and report it promptly
Do not disclose the issue publicly until we have agreed a coordinated date
Out of scope
Denial-of-service or volumetric attacks against any AmpVerve service
Social engineering of AmpVerve staff, customers, or partners
Physical security testing of AmpVerve offices, data centres, or any partner site
Findings that require root/jailbreak on a customer device
Reports from automated scanners with no demonstrated impact
Vulnerabilities in third-party services we list as subprocessors — report those to the respective vendor
Recognition
We do not currently run a paid bug-bounty programme. We do publish a Hall of Fame for researchers who report valid issues, with their consent.