Coordinated disclosure
Reporting a security issue.
If you have found a vulnerability in this website, in the secure login, or in anything else Ameristar operates on the public internet, we would rather hear about it from you than read about it later.
What we ask
Give us the detail
A description of the issue, the URL or component affected, and enough of a reproduction that an engineer can confirm it. A screenshot or a request log helps.
Give us time
We acknowledge reports within two working days and aim to have a fix or a written position within thirty days. We will tell you when it is resolved.
Stay inside the line
No denial of service, no social engineering of our people, no physical access attempts, and no testing that degrades service for a client. Do not access, alter or retain data that is not yours.
Hold the report
Please do not publish until the issue is fixed or thirty days have passed, whichever is sooner. We will not take legal action against research conducted in good faith and within these limits.
How to reach us
Ameristar does not publish direct addresses on this site. Reports are accepted through the secure login by any account holder, and through the operator or contracting party you already deal with if you have one. If you have neither, a report left with any Ameristar counterparty will reach the same desk.
The machine-readable version of this policy is published at
/.well-known/security.txt.
In scope
- This website and every page served from it
- The secure login and both workspaces behind it
- Published documents and the media library
Out of scope
- Missing security headers with no demonstrated impact
- Reports produced solely by an automated scanner, with no working proof
- Rate limiting on public, unauthenticated, read-only pages
- Anything requiring a compromised device or a browser we do not support
What is already known
Two things on this site are deliberate and do not need reporting. The workspace login is a front-end demonstration gate rather than an authentication system, and it says so in the source. The operations and client workspaces run on generated data and are not connected to live SCADA, WITSML, AIS or ADS-B feeds. Both are stated on the pages themselves.
How we take work.
Ameristar does not tender publicly and does not accept unsolicited enquiries. Programmes come to us through operators we already work for.