Identity.Base Legal
Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities affecting identitybase.io or the Identity.Base open-source project. This policy does not create a bug bounty program or imply a hosted service commitment.
Last updated: March 12, 2026
How to report a vulnerability
Please report security issues to contactidentitybase.io.
Please include:
- A clear description of the issue.
- Steps to reproduce it.
- Any proof-of-concept or supporting material.
- Your contact information so we can follow up if needed.
Scope
This policy covers identitybase.io, the public project materials we control, and the Identity.Base source code maintained by Amaretto Software Labs. Self-hosted deployments operated by third parties are outside our operational scope.
Researcher expectations
- Act in good faith and avoid privacy violations, service disruption, or destruction of data.
- Do not access or retain more data than necessary to demonstrate the issue.
- Do not use social engineering, spam, denial-of-service, or physical attacks.
- Do not publicly disclose issues before we have had a reasonable opportunity to investigate and remediate them.
What to expect from us
- We aim to acknowledge reports within 48 hours.
- We will assess impact, validate the issue, and request clarification if needed.
- We will address confirmed issues according to severity and operational risk.
Bug bounty
Identity.Base does not currently operate a paid bug bounty program.
Contact
Security contactcontactidentitybase.io