Security & Vulnerability Disclosure
Last updated: 29 July 2026.
1. Reporting a vulnerability
If you believe you’ve found a security vulnerability in Amplify, we want to hear about it. Please email hello@amplifymymusic.co.uk with a description of the issue, the steps to reproduce it, and any proof-of-concept material. We aim to acknowledge reports within 3 business days.
Please report privately, by email, rather than through a public issue tracker, social media, or any other public channel, until we’ve had a chance to address the issue.
2. Safe harbour
We will not pursue legal action against you for security research conducted in good faith and in accordance with this policy. Specifically, we consider your research authorised if you:
- Report findings to us before disclosing them publicly, and give us reasonable time to address them before disclosure;
- Make a good-faith effort to avoid privacy violations, degradation of service, and destruction of data during your research;
- Only interact with accounts and data you own or have explicit permission to test — never a real venue, band, or musician account that isn’t yours;
- Do not exploit a vulnerability beyond what’s necessary to confirm it exists (for example, stop after confirming access rather than exfiltrating further data).
3. Scope
In scope:
- amplifymymusic.co.uk and its subdomains
- Authorisation/access-control issues (one account reaching another’s data)
- Injection (SQL, XSS, command injection)
- Authentication and session handling
- Payment-flow logic issues
Out of scope:
- Denial-of-service or load/stress testing of any kind
- Social engineering or phishing against our staff or users
- Physical access attempts
- Automated scanning that generates high-volume traffic — a handful of test requests is fine; a sustained scan is not
- Reports concerning third-party services we integrate with (Stripe, Supabase, Resend, Firebase) — please report those directly to the provider
- Missing security headers, SPF/DMARC misconfigurations, or other best-practice suggestions without a demonstrated exploit
4. What to expect
We’ll acknowledge your report, investigate, and let you know our assessment and, where applicable, a rough timeline for a fix. We don’t currently run a paid bug bounty programme, but we’re happy to publicly credit researchers (with permission) once an issue is resolved.
5. Machine-readable policy
A security.txt file (RFC 9116) is published at the standard location for automated tooling.