LOCATION
Hong Kong

  • Exchange
  • Services
  • Technical
  • About

Responsible Disclosure Policy

AMS-IX considers the security of our infrastructure a top priority. Although we try to do our best to mitigate vulnerabilities, they may still occur in our systems, especially in dynamic environments such as ours.

If you discover a vulnerability, let us know about it so we can take the necessary steps to address the issue as quickly as possible. Please help us better protect our clients and infrastructure.

It would be greatly appreciated if you:

  • Emailed your findings to ir@ams-ix.net. Please encrypt your findings using our PGP key (see below or download here) to prevent this critical information from falling into the wrong hands.
  • Do not take advantage of the vulnerability or problem you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability or by deleting or modifying other people's data.
  • Do not reveal the problem to others until it has been resolved.
  • Do not use attacks on physical security, social engineering, distributed denial of service, spam or applications of third parties, and
  • Do provide sufficient information to reproduce the problem, so we will be able to resolve it as quickly as possible. Usually, the IP address or the URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation.

Responsible disclosure should focus on issues of:

  • Breaches of Privacy of our customers, suppliers and/or staff in any meaningful way (example: gaining unauthorised access to customer email addresses pointing to people).
  • Breaches of Confidentiality or Integrity of our customer, supplier and/or staff data in any meaningful way (example: obtaining valid AMS-IX staff credentials).
  • Disrupting the Availability of AMS-IX services or processes, in any meaningful way (example: Software or Hardware exploits which can be provably used against our infrastructure).

We commit to:

  • Respond to your report within 3 business days with our evaluation of the report and an expected resolution date.
  • If you have followed the instructions above, we will not take any legal action against you in regards to the report.
  • We will handle your report with strict confidentiality, and we will not pass on your personal details to third parties without your permission.
  • We will keep you informed of the progress towards resolving the problem.
    In the public information concerning the problem reported, we will give proper attribution (unless otherwise desired).
  • As a token of our gratitude for your assistance, we may offer a small monetary reward for every verifiable report of a security problem that was not yet known to us and which meets the conditions described in this policy. The amount of the reward will be determined based on the severity of the issue, and the quality of the report, and will only be transferred via Paypal. No other forms of payment are supported. Lastly, note that only the first person/entity reporting an issue may be eligible for such a reward.

---

We strive to resolve all problems as quickly as possible, and we would like to play an active role in the ultimate publication on the problem after it is resolved.

Note
: This policy is currently on version 37, published on Tuesday, August 13 2019, and may be amended in the future.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBFzeoXoBEACwUiK+ffedXzG3Z2hcCe93Bv75GMjz0btgvv83WxLP9wnC11om
LZQhqjjWXjW1+NPN+VTK5jHy/11myXMQ/u+ED1MyauDa/yZ0YmiFP7BL4uRVnfge
Fx1D5gWXaNhFyLnpKV0LgUHnZknvMJ+OsLwfQ6i6wsryUB+glZYdRDea1cu15geB
VFCJ975oySB1fWWKcxwG2G8JRP0Xdmew0/4YsbQOthPZ7TskC4euxuJyE3AGBC41
6I4C/V8YfI4z9myGOKfZFOtznx6si6pt+LxXVlI4bD/Uwcpkn5oTj90Hxx0C8n0t
UZBrAvl/YRT0QO8FS9jZ/bUNwFEeBc1tKV8kE5/8lLCtsDjxS4qiZ7omKZnaxdIN
TFpNwtpoHEm86/XAgLfe9WmdH/Nwcn3XAEXs39MYKFt0auOSjAnE04C+GaqqrDgD
rGLr8oPhyWpXaweS11H2b/++XfxW4x+E/hLcHkskV8vTQi2n2tWyS+6UNNku//Vn
WfS1gvWf0PA/BEWn6nfUowGDviVXEaHiMsI+CpHLjesUT020LpIalG8geIEMfjhu
1Qya37Ymbtgxe05tMCKPA7xvO+nVZUfq0ZQn0jhL0toXkTScy9nFmCAgRqwQ4Ez8
zt0Zh6PmYTlQ6jjurYxscPwdIo2nlV+z8ECJXqZBzBmxBTQQmMT2iy29qQARAQAB
tChBTVMtSVggSW5jaWRlbnQgUmVzcG9uc2UgPGlyQGFtcy1peC5uZXQ+iQJOBBMB
CAA4FiEEg140av/SSloSH/FbNYgBlf+q3+IFAlzeoZsCGwMFCwkIBwIGFQoJCAsC
BBYCAwECHgECF4AACgkQNYgBlf+q3+LtqBAAgLNUI48bZt4Clj3j/nGOhDWZ3RC1
9h1Q7Nl2N0mj8Ri/wyqgXjw7C0bD74z3U/jYjQRfvyRoHuGPSNDH2P1VDnDUcfIz
kflDqtbkipmEV8aHq000vrW/AcKc0kwJNY1QD+HoB5cP8uYrTkK8QdUpAFVCwdHP
29Nzbr3C2XrvqU2IMa9nrTGaH8KiHYVkjwjiQMRfdm+Hof8GO+cIAvZbARIXkTEn
lsjfYFEF98KMomGN+PZvhZrlpSqTeClrIamdAwAdk9IPtRHJ87SGhy/jEHUJZbQR
bVtTfuiN49MWozhivFGBUSKxpr/IfeQJqVlS5OOwIY6+Tf5x4gu0cjqVh7pljIwF
igk39aUcAaYYyyOLxsBkW2CymgkWufoVyx572xOpmqctNXKlX9UWL7Svf9VLJcgH
aOMj01BbUoSBC5iid8PHKOX9HBai5qqF35MmpJc+/JrZ5Gy8I06pzIltcxXq+sZx
8zhwFadbrqemJWIeTrIciF4gC3Bksqbn4/ykrYcDMpyKKDuNj0ksrGLT1vHdvguS
qR2EIJcYTJgeqhVL8FDqDdTpFhgxJcjR0FzkGLDIHZgxPBkRpFAvYOalBJDkgf0V
EiOUE0LJsemMz6y7OkHzC/wu47/KevTSmB9SdMPTmnwP27Y7Si/o5sZuDTQqxmwK
5mHMvci0jKWEmr+0I0FNUy1JWCBJbmZvc2VjIDxpbmZvc2VjQGFtcy1peC5uZXQ+
iQJRBBMBCAA7AhsDBQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAFiEEg140av/SSloS
H/FbNYgBlf+q3+IFAlzeobgCGQEACgkQNYgBlf+q3+KVFBAAjp4hzUjv0T+Vk3c1
UzvMAZb3UtSqk/hSTRs5TuEFPjQhzg5CpGF1AMCYKU6ITnb5h+/a30kchn9Jetus
3NwtRhB4Ygxj4tfcSMKYgy6orwoQ2mQLWY/4pxSamZ4z8G1NLdGzT2jrZWQN+hJU
oBWYhpoZBz2wAbnMOt+jjvb03z6Tp9ybaIBCcNscetrtrTKJyteo5Tv6OhI/p3LZ
Yy4hSMcVe10EsJ9X3CnGn3GCWvKhbzFJ3U1/BjHmQAT81LHmCXR/+0dNMG22r0/V
+e7COC5+eCBWI7sPp108YR3MciY5xv2Ba5OBiTSb0F7eeohM4kXkNBoFCFUi6G7g
hP1nOX8+6F4heDGklQk/SeHpTomKg8Px628C/yS+icze4OuhJ96vDOiHLMGLD3Ta
72R4jSD+low227qre9i69jlvSLlNkR75gcKS+RLrM4IaA3MGyIXYMNFhRK3Q2UHq
dD/NGOMqO22/GI1ej1jyQy6Nh14MxDrbGHsqbrNSZbWNiOqWgf8HQNV/KF//LW3+
qDF4VZupz71SxPgmHFyUD0zf+rphbzhxAIuPCAUG4FOIvlCzqvxSIwHHWxh77kY1
+3gV/mayInFcKbDO5biG5Crma37JafDtPALUHSS12YEhNuT+RaHykRKTa0HKmlD/
J1P58fIpMgXwAWJHFMhaiWG8tqm5Ag0EXN6hegEQAMhnCrzUTyghqK6ZGjItUIBC
FKBy3Lr9Ga6FENWQs4mtt6SE9trXt9Bg+qe3NI6Egws5o0948f/swCyE7WlHzGft
yU2HtKZhs3TCXJTeGpF5mpm0zjEij8Xr2XVICLIdIcSczjjSVqv33w8fo6wR17pp
bUVhEk21is02mm5f389cgkEeVTDSqie9tbveIcX44eNra6Kz65vzgeoBAFmwPlYL
4gYRKshFSLTQA/JHApVf/FITVyn1ABT1RFgD0PEEfBCEGfRIYrzAGTLnhWOjP6ob
yEFTLTKMKqMVhdMlarrMk5+iv2kSKFJenZmBVVAtlzSGTjjrZ96XPqV/0Lg+ndg2
ch7uFH2U9pt8RwWrwzuo8kDBno1dlFjX0W2D18q7T1dRWQ1P336wxtQ7P2IbEg4Z
lZkZjaZYEhyGy4dPDBNQ3WDl4Fn/JGilNpjScRnEcBsbK7rXn54Kmamn6XlcAGbt
RD0H1pv7Y5nmVGWuj3JoYIQoXZ9TxRORedCXJn5FpFlptZ/V3/SOUpUzssqZdHvf
SRaDspSFjrHpg3M5Fq7rjIZvuBLDw1oRQDi6gkZLFr7uOolRQj7//AyPlktH/2dU
FoEGa6425L+Ebze9pClGKI72VaneWMwl5pIKCz/zm2CnjcyiZBJUUrNiMDEY/Hz3
vcmKQwFIJqRal2QcuOXdABEBAAGJAjYEGAEIACAWIQSDXjRq/9JKWhIf8Vs1iAGV
/6rf4gUCXN6hegIbDAAKCRA1iAGV/6rf4g0yD/9aHsHsPAcDeyIttYmMwDWwktgC
0a/AdC1TmVjYEPG+fY2H1PMVsjE5NUafOgdQVsUe3u85zqiHd3YBf+DPHemrhIUx
2rpYw1I73RsettTthwxqoCWs7+NJsNk1Vwxec+vWVMxdbyFNugYzR2xon1qVFSla
fdbSHke1urgWgt7r273FZLkczRjTG68dn4GYAgJrjDe+PUZc78I5A9TjZQRvFE9K
tlMqGItvGMMiq6XyvH5HhMIFF8KyvMakwTWRtQtUrRxD9/ErZNvZt57pHJDzKvcT
Jm8fizq542VPqYJ0259rY4g5xOyTHjTujD0zN10HWEwGmutnLpW8uRRt8LfxBSca
YJwzuAu6wTZyClnTgLHLXDCwqzYT0v97SkuhSCe3vKToXIn65gbi+KJqqZ8qhUUq
SoUyPgy+VaS8gOqyNPyALPEn2pf4/5oetD9Y9l3VFv3BGMSOgci88w/c5oZ65YCA
S1NWCdyYUXprSQ6CKLlK0AaPTxyDMZfBoW4BDzglRaDaNSk1/Vja8dItop4wtPCu
jyYcUHU6VSxnOKTX8ld4NuKM6uh5kZArDfs+gmmfPxOBFvksyzrUYHBJWnsAq8zj
Evs29wFKxu8rhJjk8qK1Hqsw/BShTcVv8pK7ysmJUOhtBXgJw8qP97jdgrPi9w7s
gSZxRuVK2fTU37M5Uw==
=8LiZ

-----END PGP PUBLIC KEY BLOCK-----

You might also be interested in

Subscribe to our newsletter

Got a question?