Vulnerability Disclosure

Company details: Amaretto Software Labs ltd, registered in Bulgaria, VAT BG208304854, Address: Bulgaria, Varna 9000, ul. Vitosha 10, ap. 9.

We welcome responsible disclosure of security vulnerabilities that may affect Dawn. If you believe you have found a security issue, report it to us and we will investigate it.

How To Report

Send reports to contactdawnhq.ai.

Please include:

  • A clear description of the issue and affected surface
  • Steps to reproduce the problem
  • Any proof-of-concept material or screenshots that help verify the issue
  • Your contact details so we can follow up if needed

What We Ask From Researchers

  • Act in good faith and avoid privacy violations, data destruction, or service disruption
  • Do not access, modify, or retain customer data beyond what is strictly necessary to demonstrate the issue
  • Do not use social engineering, physical attacks, spam, or denial-of-service techniques
  • Do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate it

Scope

This policy applies to Dawn-operated properties and services, including the marketing site, application surfaces, APIs, and supporting infrastructure that we control.

Third-party services, customer-managed integrations, and provider platforms are outside the scope of this policy and should be reported through their respective disclosure channels.

What To Expect

  • We aim to acknowledge receipt within 48 hours
  • We will review the report, assess impact, and request clarification if needed
  • We will work to remediate validated issues within a timeframe appropriate to the severity and operational risk
  • We may notify affected customers or users where required by law, contract, or incident handling policy

Bug Bounty

Dawn does not currently operate a paid bug bounty program.

Contact

Dawn Security Team
Amaretto Software Labs ltd
Email: contactdawnhq.ai

© 2026 Amaretto Software Labs ltd. All rights reserved.

Last updated: March 12, 2026