To report a vulnerability, privacy, or security concern, email amir@amoreg.com with "Security report" in the subject. Please include the affected URL or component, the steps to reproduce, impact, and any safe proof of concept.
General commercial enquiries can still be sent to hello@amoreg.com.
Safe reporting
Do not access, modify, delete, exfiltrate, or disclose customer data. Avoid denial-of-service testing, social engineering, spam, physical attacks, and testing against accounts or workspaces you are not authorized to use.
Current safeguards
- Organization-scoped authorization checks on Amoreg domain API routes.
- Session and role checks before customer workspace reads or writes.
- Encryption in transit on public HTTPS surfaces.
- Secret scanning and push protection on the GitHub repository.
- Dependency alerting and security update monitoring.
- Operational logging for reliability, abuse prevention, and incident review.
Scope of this page
This public page is not a certification statement. Amoreg does not claim SOC 2 certification, completion of row-level security, or an independent penetration test unless those controls are separately documented in an executed agreement or current security report.