Legal
Responsible Disclosure
If you find a security problem in AAMDM or aamdm.com, we want to hear about it. This page explains how to report it and what to expect.
Last updated:
1. Scope
This policy covers:
- aamdm.com and its subdomains operated by us
- The AAMDM service and its APIs, as they become available
Systems operated by Apple or other third parties are outside our scope. Please report issues in those directly to the vendor.
2. How to report
Email security@aamdm.com. Plain text is fine. Please do not include real personal data, and do not disclose the issue publicly before we have had a chance to fix it. Our security contact is also published in /.well-known/security.txt.
3. What to include
The more of the following you can give us, the faster we can act:
- A description of the issue and its likely impact
- The affected URL, endpoint or component
- Steps to reproduce, or a proof of concept
- Any logs, screenshots or request samples that help
- How you would like to be credited, if at all
4. What you can expect from us
We will acknowledge your report within 3 business days. After that we will assess it, keep you informed as we investigate, and tell you when it is fixed. We aim to fix confirmed issues promptly, in proportion to their severity. With your permission we are happy to credit you.
5. Safe harbor
If you act in good faith and follow this policy, we will not pursue legal action against you, or ask law enforcement to, for your research. Good faith means that you:
- Make a reasonable effort to avoid harm to users, privacy and availability
- Access only as much data as needed to demonstrate the issue, and stop once you have
- Do not modify or delete data, or share what you find with others before we have fixed it
- Give us reasonable time to respond before any disclosure
This safe harbor applies only to our own systems. It cannot bind third parties.
6. Out of scope
Please do not report, or test for, the following:
- Denial-of-service or volumetric attacks, or load and stress testing
- Social engineering of our staff, customers or providers, and physical attacks
- Spam, or automated scanner output with no demonstrated impact
- Missing security headers or cookie flags with no demonstrable impact
- Vulnerabilities in third-party services we do not control
- Accessing, or trying to access, another customer’s data
7. Other reports
To report misuse of the service rather than a vulnerability, see the Acceptable Use Policy. We do not currently offer a bug bounty.
Operated by ISHI KOI FARM COMPANY LIMITED, Tax ID 0601224050, 185 Loc Vuong, Nam Dinh 10000, Vietnam.