Skip to content

Security: getambr/ambr

Security

SECURITY.md

Security Policy

Reporting Vulnerabilities

If you discover a security vulnerability in Ambr, please report it responsibly.

Email: hello@ambr.run

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact

Do not open a public GitHub issue for security vulnerabilities.

We will acknowledge receipt within 48 hours and provide an initial assessment within 5 business days.

Scope

  • Smart contract (AmbrContractNFT.sol) on Base L2
  • API endpoints at getamber.dev/api/v1/*
  • Reader Portal at getamber.dev/reader/*
  • A2A endpoint at getamber.dev/api/a2a

Out of Scope

  • Third-party dependencies (report to the respective project)
  • Social engineering attacks
  • Denial of service attacks

There aren't any published security advisories