Advigator welcomes reports from security researchers, customers and anyone else who finds a weakness in our systems. This is also the publicly accessible process for submitting, tracking, responding to and resolving data privacy and security vulnerability notifications, and incidents involving the actual or suspected misuse of Amazon data, as required by the Amazon Ads Partner Network Policies.
How to report
Email: security@advigator.com
Machine-readable contact details are published at advigator.com/.well-known/security.txt.
Please include: what you found, where (URL, endpoint, parameter), how to reproduce it step by step, what impact you believe it has, and how we can contact you. Screenshots or a short recording help. If you have a PGP key preference, say so and we will arrange an encrypted channel.
If you believe customer data or Amazon data has actually been accessed or misused, say so in the subject line — those reports are escalated immediately.
What we commit to
| Step | Our commitment |
|---|---|
| Acknowledgement | Within 2 business days |
| Initial assessment and severity triage | Within 5 business days |
| Status updates | At least every 10 business days while the report is open |
| Remediation of critical issues | Immediately on confirmation, with a fix or mitigation as fast as we can safely deploy one |
| Resolution notice | When the fix is live, with credit to you if you want it |
We will tell you honestly if we decide not to fix something, and why.
Scope
In scope: advigator.com and dashboard.advigator.com.
Out of scope: third-party services we use but do not control (report those to the provider); findings that require physical access to a user’s device; social engineering of our staff or customers; denial-of-service and volumetric testing; reports generated solely by an automated scanner with no demonstrated impact; missing best-practice headers with no exploitable consequence; and issues in Amazon’s own services, which should go to Amazon.
Rules of engagement
To keep testing safe for our customers:
- Use only your own account and your own test data.
- Do not access, modify, download or retain another customer’s data. If you encounter it accidentally, stop, do not save it, and tell us in your report.
- Do not degrade the service: no denial-of-service, no load testing, no mass automated scanning.
- Do not make changes to live advertising accounts — they cost our customers real money.
- Give us reasonable time to fix an issue before disclosing it publicly. We suggest 90 days, and we will agree an earlier date with you where a fix lands sooner.
Safe harbour
If you follow this policy in good faith, we will not pursue or support legal action against you for your research, and we will treat your activity as authorised under applicable computer misuse laws. If a third party brings action against you for research conducted under this policy, we will make it known that your activity was authorised.
This safe harbour does not extend to accessing, exfiltrating or retaining other people’s data, to extortion, or to activity that damages the service.
Rewards
We do not currently run a paid bug bounty programme. We do publicly credit researchers who want it, and we answer every legitimate report.
Incidents involving Amazon data
Reports concerning the actual or suspected misuse of data obtained from Amazon Ads are logged, tracked and escalated under our incident response process, and are reported to Amazon where their policies require it.