Security policy & vulnerability disclosure
Rules for security researchers and how to report a vulnerability to AMBER 360.
Updated: 16 August 2026
1. Scope
This policy covers the AMBER 360 website (360-amber.com) and its subdomains, public forms, and the private partner area.
Out of scope: social media accounts, third-party services (booking system, payment provider), and the physical security of the venue.
2. Research rules
We welcome good-faith research. Not permitted:
- disrupting service availability (DoS, DDoS, load testing);
- social engineering against our staff or contractors;
- accessing, modifying, or retaining other people's personal data;
- physical intrusion onto the venue;
- automated bulk form submissions and spam;
- publicly disclosing a vulnerability before it's fixed.
3. How to report
Email [FILL: email_security]. Please include a description, reproduction steps, and a screenshot if you can.
- Acknowledgement — within 3 business days.
- Assessment and status — within 14 days.
- Public credit — if you'd like it.
We don't currently pay monetary rewards for vulnerability reports. We say so plainly to avoid setting the wrong expectation.
4. Safe harbour for researchers
If you follow the rules above, we will not pursue legal action against you and will treat your research as authorized.
