# Vulnerability disclosure for amplified.ai # https://www.rfc-editor.org/rfc/rfc9116 # # If you believe you have found a security vulnerability with a demonstrable # impact on the confidentiality, integrity, or availability of our service or # our customers' data, please report it to the contact below. We will # acknowledge in-scope reports and keep you updated on our progress. # # NO BUG BOUNTY # # Amplified does not operate a bug bounty programme. We do not offer monetary # rewards, gift cards, swag, or other compensation for vulnerability reports. # Please do not submit a report expecting payment, and do not make payment a # condition of disclosure. # # OUT OF SCOPE # # We do not accept reports consisting solely of automated scanner output, or # findings with no demonstrated security impact. This includes, but is not # limited to: # # - missing or misconfigured HTTP response headers # - SPF, DKIM, or DMARC record configuration # - TLS version, cipher suite, or certificate chain preferences # - software version or banner disclosure # - missing rate limiting without a demonstrated attack # - self-XSS, or issues requiring a fully compromised client # - best-practice observations without plausible and reproducible security impact # # Reports that consist solely of automated output and do not explain a plausible # security impact may be closed without further response. # # TESTING # # Please do not access, modify, or exfiltrate data belonging to other users, # and do not run automated scanning that degrades service availability. Test # only against accounts you own. Contact: mailto:security@amplified.ai Expires: 2027-07-01T00:00:00.000Z Preferred-Languages: en Canonical: https://www.amplified.ai/.well-known/security.txt Policy: https://trust.amplified.ai Bug-Bounty: False