Vulnerability Disclosure
Company details: Amaretto Software Labs ltd, registered in Bulgaria,
VAT BG208304854, Address: Bulgaria, Varna 9000, ul. Vitosha 10, ap. 9.
1. Scope
This policy covers security vulnerabilities affecting the Enclave marketing site, Enclave-hosted services, associated APIs, and supporting infrastructure that is owned or operated by Amaretto Software Labs.
2. How to report
Please report vulnerabilities privately to contactenclavehq.io.
- A concise summary of the issue and affected asset.
- Steps to reproduce, including any proof of concept or screenshots.
- The expected impact and any assumptions about exploitability.
- Relevant request, response, or environment details where safe to share.
3. No bug bounty programme
Enclave does not currently operate a paid bug bounty programme.
- We welcome responsible disclosure.
- We may acknowledge valid reports publicly if you want credit.
- We do not offer guaranteed financial rewards, payouts, or reimbursement.
4. Research guidelines
Please act in good faith and avoid:
- Accessing, modifying, or deleting data that does not belong to you.
- Denial-of-service activity, excessive traffic generation, or service disruption.
- Social engineering, phishing, or attacks against third-party systems.
- Public disclosure before we have had a reasonable opportunity to investigate and remediate.
5. Safe harbor
We will not pursue legal action against researchers who follow this policy, act in good faith, avoid harm, and report findings privately. This safe harbor applies only to legitimate security research within scope. It does not create any entitlement to payment or bounty awards.
6. Response expectations
We aim to:
- Acknowledge reports within 3 business days.
- Confirm whether the issue is in scope and reproducible.
- Keep reporters informed when a valid issue is being tracked.
7. Contact information
Amaretto Software Labs ltdSecurity Team
VAT: BG208304854
ul. Vitosha 10, ap. 9
9000 Varna, Bulgaria
Email: contactenclavehq.io
Website: enclavehq.io