Security
Reporting a security issue
Ambit builds infrastructure whose entire value is that it keeps regulated data where it belongs. We take reports about our own security seriously and we appreciate the people who make them.
How to report
Email [email protected]. Please include:
- What you found and where (URL, hostname, product or component).
- Steps to reproduce, or a proof of concept, in enough detail for us to confirm it.
- The impact as you understand it.
- How you would like to be credited, if at all.
If the report contains sensitive material, say so in the first message and we will arrange an encrypted channel before you send it.
What we commit to
- We acknowledge reports within three business days.
- We keep you informed as we confirm, fix and close the issue.
- We credit researchers who ask to be credited once a fix is released.
- We will not pursue legal action against anyone who researches in good faith, follows this policy, avoids privacy violations and service disruption, and gives us reasonable time to fix what they find before disclosing it.
In scope
- ambit-technologies.com and its subdomains.
- Ambit software and services that Ambit operates.
Out of scope
- Denial of service, volumetric testing, or anything that degrades availability.
- Social engineering of Ambit staff, customers or partners; physical attacks.
- Findings in third-party services we use (such as Cloudflare or Google) rather than in our use of them; please report those to the provider.
- Customer sites running Ambit equipment. Testing against a customer's facility requires that customer's written permission.
No bounty program yet
We do not currently run a paid bounty program. We do say thank you, publicly if you wish.