Report Security Issues
We value responsible security research and welcome good-faith reports about potential security vulnerabilities affecting systems owned or controlled by ORJ COMMERCIAL LTD for AMORJ.
How to Report a Vulnerability
Email support@amorj.com with the subject line Security Vulnerability Report. Please include:
- the affected URL, feature or system;
- a clear description of the vulnerability and potential impact;
- reproducible steps or a minimal proof of concept;
- screenshots, request/response examples or technical details where useful; and
- your preferred contact details for follow-up.
We aim to acknowledge genuine security reports promptly and may contact you for additional information.
Scope
This policy applies to amorj.com and other systems that ORJ COMMERCIAL LTD explicitly owns or controls. Third-party platforms, payment providers, hosting providers, apps and services are outside scope unless we have specifically authorised testing of them.
Responsible Research Rules
When investigating or reporting a suspected issue:
- use only the minimum testing needed to demonstrate the issue;
- do not access, copy, alter, retain or disclose other people's personal data;
- do not disrupt the website, checkout, fulfilment or customer service;
- do not perform denial-of-service attacks, spam, social engineering or physical attacks;
- do not use destructive testing, malware or techniques that could damage data or systems;
- stop testing and notify us if you unexpectedly gain access to sensitive or personal information; and
- do not publicly disclose the vulnerability before we have had a reasonable opportunity to investigate and remediate it.
Bug Bounty & Recognition
We may, at our sole discretion, offer recognition or a financial reward for an eligible, previously unknown and responsibly reported vulnerability that has meaningful security impact. Submitting a report does not create an entitlement to payment.
Any bounty amount depends on factors such as severity, exploitability, quality of the report, originality and the affected system. Duplicate reports, informational findings, issues requiring unrealistic user interaction, third-party vulnerabilities and reports that breach this policy may be ineligible.
If a reward is offered, eligibility and payment details will be confirmed directly with the reporter.
Good-Faith Reporting
We aim to work constructively with researchers who act in good faith, respect privacy, avoid harm and follow this policy. Nothing on this page grants permission to access systems, accounts or data beyond what you are lawfully authorised to access.
Privacy
Information submitted in a security report will be used to investigate, remediate and communicate about the reported issue. See our Privacy Policy for information about how we handle personal data.
Company & Contact Information
-
Trading name: AMORJ
-
Legal entity: ORJ COMMERCIAL LTD
-
Company number: 07616905
-
Company type: Private limited company
-
Incorporated on: 28 April 2011
-
Registered office: 70a Bow Road, London, E3 4DH
-
Companies House: official company record
-
Email: support@amorj.com
-
Phone: +44XXXXXXXX
-
Live Chat: Available 24/7.
-
Email Support: We respond within 1 business day.
-
Time zone: Greenwich Mean Time (GMT) / British Summer Time (BST) — Europe/London.