Vulnerability Disclosure Policy
This page was last changed on September 3, 2026.
1. Introduction
2. Systems in Scope
This policy applies to AMI products with digital elements and associated digital infrastructure. including Aptio V, MegaRAC, Tektagon, Community Editions and other AMI products.
3. Out of Scope
Products not manufactured or supplied by AMI, including third-party products used in the same system as a AMI product, are out of scope.
Vulnerabilities discovered or suspected in out-of-scope systems should be reported to the appropriate vendor or authority.
4. Our Commitments
When working with under this policy, you can expect us to:
- Respond to your report promptly, and work with you to understand and validate your report;
- Strive to keep you informed about the progress of a vulnerability as it is processed;
- Work to remediate confirmed vulnerabilities in a timely manner, within our operational constraints
5. Rules of Engagement
If you participate in our vulnerability disclosure program in good faith, we ask that you:
- Follow this policy and any other applicable agreements;
- Report suspected vulnerabilities promptly through the Official Channels identified below;
- Perform testing only on systems, hardware, software installations, and accounts that you own or are explicitly authorized to test;
- Do not perform social engineering, phishing, or physical attacks against AMI employees, contractors, offices, customers, or users;
- Do not perform denial-of-service attacks or load, stress, or resource-exhaustion testing against AMI-operated services, production infrastructure, or other live systems;
- You may report denial-of-service or availability weaknesses in AMI products. Testing of these conditions must be limited to hardware, software, and test environments that you own or are explicitly authorized to use;
- Avoid disrupting systems, degrading availability, destroying or modifying data, violating the privacy of others, or harming the user experience;
- If you obtain unintended access to a system, account, or data, stop at the point of recognition. Access only the minimum information necessary to demonstrate the issue. Do not attempt to determine what additional information may be accessible, and report the issue immediately;
- Interact only with test accounts that you own or accounts for which the account holder has provided explicit permission;
- If you encounter personal, health, payment-card, confidential, or proprietary information, stop testing and report the issue immediately;
- Use the Official Channels to communicate vulnerability information to us;
- Give AMI a reasonable opportunity to investigate and address the issue before public disclosure;
- Do not sell, trade, transfer, or use information about the vulnerability for any purpose other than reporting in to and coordinating with AMI; and
- Do not engage in extortion.
6. Official Channels
Please report security issues to [email protected], providing all relevant information. The more details you provide, the easier it will be for us to triage and fix the issue.
7. Encryption (PGP)
For sensitive reports, please encrypt your message using our PGP public key below.
—–BEGIN PGP PUBLIC KEY BLOCK—–
mDMEapiZvBYJKwYBBAHaRw8BAQdAnYLny1d/yod6GTMNeJqdrSa+j4WaElePWClj
sJ2VQ3m0PkFNSSBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50IFJlc3BvbnNlIFRl
YW0gPHNlY3VyaXR5QGFtaS5jb20+iLUEExYKAF0WIQTGdQk2SbANO3bwL1yLEDu7
zHuFLQUCapiZvBsUgAAAAAAEAA5tYW51MiwyLjUrMS4xMiwyLDECG4EFCQWkxHQF
CwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQixA7u8x7hS0qTgEA/1j3pUUu
umGJ3sEJeahwXXWtH+VkauWq0YtReeekasUA/2J7/dWaZBFOsge8Xun6TOoAEoIe
u/LJL3XFeJyXVccIuDMEapiZ3RYJKwYBBAHaRw8BAQdAm3fVyuiXrxhphpvcKPRX
LogZZ9grOFZA2+YjAfiZoZ2JAQsEGBYKADwWIQTGdQk2SbANO3bwL1yLEDu7zHuF
LQUCapiZ3RsUgAAAAAAEAA5tYW51MiwyLjUrMS4xMiwyLDECGwIAgQkQixA7u8x7
hS12IAQZFgoAHRYhBNxsdiAblZMlnOlvkfguJqKNc86jBQJqmJndAAoJEPguJqKN
c86jT1kBALzPh1tFEKCOtUOJGkEUijeYAQWYMU+Byna0BXfCyM5LAP95I2xMGDxI
PJFbOXpbEqLGJKbWBS1gF6rfCVzP+T7IDZabAPwPZRF4VF5828ptz/0thqoXoMBG
DcGwNgAk8mz7KpHfDgD+IbffMyAItVZomsyz00wVrFlNQpMdVikB6lnoQaTczww=
=dIAy
—–END PGP PUBLIC KEY BLOCK—–
8. Change History
|
Date |
Revision |
Description |
|
3 September 2026 |
1.0 |
First rev |
For additional information see the AMI Security Center at www.ami.com/security-center or email [email protected].