generated: '2026-09-19' method: searched probe: true source: https://github.com/getambr/ambr/blob/master/SECURITY.md raw: security/getamber-dev-SECURITY.md description: >- Ambr publishes a vulnerability disclosure policy as SECURITY.md in its public GitHub repository (getambr/ambr, fetched 2026-09-19 from raw.githubusercontent.com, saved verbatim to security/getamber-dev-SECURITY.md). It is NOT surfaced as RFC 9116 security.txt (/.well-known/security.txt 404 on getamber.dev and ambr.run), there is no bug-bounty programme on HackerOne/Bugcrowd/Intigriti, and probe-security-programs.py therefore found nothing — this artifact was written from the repository file, which is a real, provider-authored, publicly reachable policy. policy: - https://github.com/getambr/ambr/blob/master/SECURITY.md contact: - mailto:hello@ambr.run channel: email response_commitments: acknowledgement: within 48 hours initial_assessment: within 5 business days scope: - Smart contract AmbrContractNFT.sol on Base L2 - API endpoints at getamber.dev/api/v1/* - Reader Portal at getamber.dev/reader/* - A2A endpoint at getamber.dev/api/a2a out_of_scope: - Third-party dependencies (report to the respective project) - Social engineering attacks - Denial of service attacks rules: - Do not open a public GitHub issue for security vulnerabilities - Include a description, steps to reproduce and potential impact bug_bounty: false safe_harbor: not stated evidence: - source: https://raw.githubusercontent.com/getambr/ambr/HEAD/SECURITY.md http_status: 200 fetched: '2026-09-19' kind: SECURITY.md - source: https://getamber.dev/.well-known/security.txt http_status: 404 - source: https://ambr.run/.well-known/security.txt http_status: 404 trust_center: none