Security

Responsible Disclosure
& Bug Bounty Program

AMILLIPAY takes security seriously. We welcome security researchers who responsibly disclose vulnerabilities. If you find a security issue we want to hear from you.

Report a vulnerability

Send your findings to our security team. Include a clear description of the vulnerability, steps to reproduce, and the potential impact.

security@amillipay.com

We respond to all valid reports within 48 hours.

In scope

The following systems are authorized for security testing:

AMILLIPAY REST API (api.amillipay.com and www.amillipay.com/api)

Agent authentication and API key system

Payment processing and credit transfer logic

Agent wallet balance system

Webhook delivery system

Rate limiting and fraud detection

Out of scope

The following are explicitly prohibited:

Direct database access or Supabase dashboard

Denial of service attacks of any kind

Social engineering of AMILLIPAY staff or users

Physical security attacks

Attacks against other users accounts or data

Spam or mass account creation

Third party services or infrastructure

Rewards

We reward researchers who find and responsibly disclose valid security vulnerabilities.

SeverityDescriptionReward
CriticalAuthentication bypass, funds theft, mass data exposure$500 USD or 500,000 credits
HighPrivilege escalation, significant data leak, payment manipulation$250 USD or 250,000 credits
MediumLimited data exposure, rate limit bypass, logic errors$100 USD or 100,000 credits
LowMinor information disclosure, non-critical misconfigurationsPublic acknowledgment

Rules

01

Only test against your own accounts and agents — never against other users data

02

Do not access, modify, or delete data that does not belong to you

03

Do not perform denial of service attacks or automated scanning at scale

04

Do not publicly disclose vulnerabilities before we have had 30 days to address them

05

Act in good faith — your goal should be to improve security not to cause harm

Safe harbor

AMILLI AI, CORP will not pursue legal action against security researchers who discover and responsibly report vulnerabilities in accordance with this policy. We consider security research conducted under these guidelines to be authorized activity.

If you follow these rules and report in good faith we will work with you to understand and address the issue quickly. We consider you a partner in keeping AMILLIPAY secure.

Hall of fame

Security researchers who discover and responsibly disclose valid vulnerabilities will be acknowledged here. Be the first.

Report a vulnerabilityRead the docs