Security
Security
Found a security problem in an Ambolt site or tool? Tell us at hello@ambolt.dev. Every report is read.
Report a vulnerability
Write to hello@ambolt.dev with the subject "Security". Please include:
- what you found and where (the address or the product and version),
- the steps to reproduce it, and what an attacker could do with it,
- how to reach you, and whether you want to be thanked by name.
Please do not access other people's data, do not degrade the service, and give us a reasonable time to fix the problem before you publish it.
What you can expect
- A written answer within 3 working days, confirming that we have the report.
- Updates while we work on it, and a note when it is fixed.
- A thank-you on this page if you want one. We do not run a paid bounty programme.
Scope
- ambolt.dev, app.ambolt.dev and api.ambolt.dev
- the Ambolt Link Checker WordPress plugin, once it is released
- the packages published as
@ambolt/*on npm andambolton PyPI, and the Ambolt MCP server
Out of scope
- denial-of-service and volume testing,
- social engineering, phishing and physical attacks,
- reports from automated scanners without a shown impact,
- missing headers or best-practice notes on static pages without a shown impact,
- third-party services we use (report those to the provider).
Safe harbour
If you act in good faith and within this policy, we will not take legal action against you for your research, and we will treat your report as authorised. If in doubt, ask first.
How the site is built
- Every page is static and served with a strict content security policy: scripts, fonts and styles come only from ambolt.dev itself.
- No third-party scripts, no tracking cookies and no analytics vendors.
- HTTPS only; plain HTTP is redirected.
- The crypto tools never hold keys or funds; they produce unsigned transactions that you sign yourself.
- We keep as little data as the tools need; the privacy policy lists it.
The machine-readable contact is at /.well-known/security.txt.