avs-device-sdk/SECURITY.md

5 lines
909 B
Markdown
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### Security Policy for Device SDKs
Amazon has updated the AVS API to add a new consent screen during device registration for new users if the device has not been not certified by Amazon. Once the device has completed the testing process including obtaining a security assessment from Authorized Security Lab and receiving an Alexa Built-in badge, this consent screen will be removed and developers will be able to offer the full Alexa experience on their Alexa Built-in devices. To learn more about device testing and certification, please visit [here](https://developer.amazon.com/en-US/alexa/devices/alexa-built-in/development-resources#additional-resources).
### Reporting a Vulnerability
If you discover a potential security issue in this project we ask that you notify Alexa Voice Services Security team by sending an email to <avs-security@amazon.com>. Please do **not** create a public GitHub issue.