01 · Submit
Report a security concern
Email security@amazongpt.app. This channel is intended for security vulnerabilities and actual or suspected security incidents. Account support and feature requests should use the support area inside amazonGPT.
Do not send passwords, access tokens, refresh tokens, private keys, complete Amazon reports, or unnecessary personal data. We will arrange a safer transfer method if evidence is required.
02 · Describe
What to include
- Your name and a reliable contact address.
- A concise description of the vulnerability or incident.
- The affected URL, feature, account area, or integration.
- When you first observed it, including your time zone.
- Safe reproduction steps and the potential impact.
- Whether you believe access or exploitation is continuing.
03 · Respond
What happens next
- 1Recorded and acknowledged
We assign a restricted incident reference and aim to acknowledge receipt within two business days.
- 2Triaged and contained
We assess severity, affected systems and continuing risk, then take proportionate containment action.
- 3Investigated and updated
We preserve relevant evidence, investigate scope and provide material updates when appropriate.
- 4Resolved and reviewed
We validate recovery, complete required notifications and track corrective actions through closure.
04 · Escalate
Incidents involving Amazon information
amazonGPT maintains an incident-response procedure for Amazon data and credentials. When credible impact involving Amazon information, Amazon Ads data, Amazon credentials, or unauthorised Amazon API use is identified, XANON LTD will notify security@amazon.com and follow any additional route required by the applicable Amazon agreement.
We limit access to incident material on a need-to-know basis and retain Amazon data only where necessary to investigate and meet applicable contractual or legal duties.
Last updated: 3 September 2026