Contact: mailto:security@amandil.ai Contact: https://amandil.ai/ Expires: 2027-05-27T00:00:00.000Z Preferred-Languages: en Canonical: https://amandil.ai/.well-known/security.txt Policy: https://github.com/seanturner001/amandil-site/security/policy # Reporting a security issue # # Amandil is a small team. Email security@amandil.ai with the subject line # "[SECURITY]" and we will respond within 5 business days. # # We commit to: # - Acknowledging receipt of your report within 5 business days # - Validating and prioritizing the issue based on severity # - Coordinating disclosure timing with you in good faith # - Crediting you in any public advisory unless you prefer otherwise # # In-scope: # - amandil.ai and all subdomains # - github.com/seanturner001/amandil-site # # Out of scope: # - Social engineering of Amandil employees # - Physical security # - DoS / volumetric attacks # - Vulnerabilities requiring already-compromised customer accounts # # Safe harbor: good-faith research conducted within the scope of this # policy is welcomed. We will not pursue legal action against researchers # who follow this policy and report in good faith.