Getamber Dev Vulnerability Disclosure
Ambr publishes a vulnerability disclosure policy as SECURITY.md in its public GitHub repository (getambr/ambr, fetched 2026-09-19 from raw.githubusercontent.com, saved verbatim to security/getamber-dev-SECURITY.md). It is NOT surfaced as RFC 9116 security.txt (/.well-known/security.txt 404 on getamber.dev and ambr.run), there is no bug-bounty programme on HackerOne/Bugcrowd/Intigriti, and probe-security-programs.py therefore found nothing — this artifact was written from the repository file, which is a real, provider-authored, publicly reachable policy.
Ambr runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.