Contact: mailto:security@amboss.com Canonical: https://amboss.com/.well-known/security.txt Encryption: https://www.amboss.com/.well-known/pgp-key.txt Policy: https://www.amboss.com/us/legal/privacy-policy-overview Hiring: https://careers.amboss.com/ Expires: 2027-06-05T22:00:00.000Z Preferred-Languages: en, de Acknowledgments: # Please note that AMBOSS SE does not currently operate a bug bounty or financial reward program. However, we value your contribution and will keep you updated on our progress. # Please use our PGP public key. Import the key into your PGP client, encrypt your report, and then send it to security@amboss.com. Submissions without encryption are also accepted. Out-of-Scope Issues # Spam or social engineering techniques. # Vulnerabilities in third-party software without a direct impact on AMBOSS systems. # Missing security headers that do not lead to a direct exploit (e.g., CSP, HSTS). # Self-XSS or vulnerabilities requiring unlikely user interaction. # Rate-limiting or "brute force" issues on non-sensitive endpoints.