Skip to content

Vulnerability Disclosure Policy

How to report a security vulnerability or a suspected incident, and what we will do about it.

Version
1.0
Last updated
18 September 2026

Advigator welcomes reports from security researchers, customers and anyone else who finds a weakness in our systems. This is also the publicly accessible process for submitting, tracking, responding to and resolving data privacy and security vulnerability notifications, and incidents involving the actual or suspected misuse of Amazon data, as required by the Amazon Ads Partner Network Policies.

How to report

Email: security@advigator.com

Machine-readable contact details are published at advigator.com/.well-known/security.txt.

Please include: what you found, where (URL, endpoint, parameter), how to reproduce it step by step, what impact you believe it has, and how we can contact you. Screenshots or a short recording help. If you have a PGP key preference, say so and we will arrange an encrypted channel.

If you believe customer data or Amazon data has actually been accessed or misused, say so in the subject line — those reports are escalated immediately.

What we commit to

Step Our commitment
Acknowledgement Within 2 business days
Initial assessment and severity triage Within 5 business days
Status updates At least every 10 business days while the report is open
Remediation of critical issues Immediately on confirmation, with a fix or mitigation as fast as we can safely deploy one
Resolution notice When the fix is live, with credit to you if you want it

We will tell you honestly if we decide not to fix something, and why.

Scope

In scope: advigator.com and dashboard.advigator.com.

Out of scope: third-party services we use but do not control (report those to the provider); findings that require physical access to a user’s device; social engineering of our staff or customers; denial-of-service and volumetric testing; reports generated solely by an automated scanner with no demonstrated impact; missing best-practice headers with no exploitable consequence; and issues in Amazon’s own services, which should go to Amazon.

Rules of engagement

To keep testing safe for our customers:

  • Use only your own account and your own test data.
  • Do not access, modify, download or retain another customer’s data. If you encounter it accidentally, stop, do not save it, and tell us in your report.
  • Do not degrade the service: no denial-of-service, no load testing, no mass automated scanning.
  • Do not make changes to live advertising accounts — they cost our customers real money.
  • Give us reasonable time to fix an issue before disclosing it publicly. We suggest 90 days, and we will agree an earlier date with you where a fix lands sooner.

Safe harbour

If you follow this policy in good faith, we will not pursue or support legal action against you for your research, and we will treat your activity as authorised under applicable computer misuse laws. If a third party brings action against you for research conducted under this policy, we will make it known that your activity was authorised.

This safe harbour does not extend to accessing, exfiltrating or retaining other people’s data, to extortion, or to activity that damages the service.

Rewards

We do not currently run a paid bug bounty programme. We do publicly credit researchers who want it, and we answer every legitimate report.

Incidents involving Amazon data

Reports concerning the actual or suspected misuse of data obtained from Amazon Ads are logged, tracked and escalated under our incident response process, and are reported to Amazon where their policies require it.

Questions about this document: legal@advigator.com. All Advigator legal documents are listed at advigator.com/legal.