Security at ambihome
Product security is a high priority for ambihome by JUNG. If you have discovered a vulnerability in an ambihome product, please report it to us. We work with security researchers to remediate vulnerabilities responsibly.
Report a vulnerability
The easiest way is our anonymous web form — no tracking, and anonymous reports are possible:
Alternatively, by email:
- psirt@ambihome.com — vulnerabilities in ambihome products (Panel, apps, planning and configuration tools)
- csirt@ambihome.com — security incidents in our infrastructure
We recommend encrypted transmission via OpenPGP (keys below). We handle reports in German and English alike.
OpenPGP Keys
Please encrypt sensitive reports with our public key.
PSIRT (psirt@ambihome.com)
- Download v4: /openpgp-keys/psirt-v4.asc — Fingerprint: 16E1BBDFD17B1B96A7A6C028E12F639B5BBCE8F8
- Download v6: /openpgp-keys/psirt-v6.asc — Fingerprint: 1D332DE0D0918E72BDFE16ADE8E3D6749EE12F3161213F421472BB060B8814D8
CSIRT (csirt@ambihome.com)
- Download v4: /openpgp-keys/csirt-v4.asc — Fingerprint: 04B07104F2B1C2AC834686CD41F6A88943434B2D
- Download v6: /openpgp-keys/csirt-v6.asc — Fingerprint: 9D84E711EED8B022256A2C7D4CDAE44ED889E850C97C5010CFC696F43A3FA333
How we handle reports (CVD policy)
Our Coordinated Vulnerability Disclosure Policy explains how we handle reports — including our safe harbor commitment, response times and coordinated disclosure.
Security advisories
We publish information about vulnerabilities we have already fixed here:
Machine-readable: security.txt
security.txtReport a vulnerability
Have you found a security vulnerability in an ambihome product? Report it here — anonymously if you prefer, with no tracking. The description is the only required field.
Please note: your report is forwarded to our security team as an email, without end-to-end encryption. For particularly sensitive information, please send a PGP-encrypted email to psirt@ambihome.com instead.