bg mobile
bg desktopkv desktop

Product Security

KV Mobile 2

As a leader in ultra-low power semiconductors and solutions for edge AI devices, Ambiq takes security seriously. As more intelligence moves to the edge, the attack surface for connected devices grows with it.
If you believe you have identified a potential security vulnerability affecting an Ambiq product, please submit a report using the Ambiq Product Security Intake Form.

Enabling Trusted Edge AI

Security Overview

At Ambiq, product security is a fundamental part of how we design, develop, and maintain our products. As a leader in ultra-low power semiconductors and solutions for edge AI devices, we recognize that protecting connected devices requires a proactive, lifecycle approach.

We embed security-by-design principles throughout product development, from architecture and design through validation, release, and ongoing maintenance. Our development process incorporates secure engineering practices, ongoing assessments, and continuous improvements to strengthen product resilience, helping customers build secure, reliable, connected devices.

Reporting Guidelines

Please use the Ambiq Product Security Intake Form to report potential security vulnerabilities.

The Product Security Intake Form is for reporting potential product security vulnerabilities only. For technical support, product questions, or other non-security inquiries, please visit the Ambiq Support Center.

Report a Security Vulnerability

Security Reporting Process

01

Report

Submit a potential security vulnerability using the Ambiq Product Security Intake Form.

02

Review

The Product Security Incident Response Team (PSIRT) reviews and validates the submission and begins a security investigation.

03

Assess

The PSIRT works with internal teams to determine severity, identify affected products, and assess the potential impact. We will submit required notifications in accordance with the EU Cyber Resilience Act (CRA) obligations.

04

Remediate

Ambiq develops, tests, and validates an appropriate fix or mitigation.

05

Disclose

When appropriate, Ambiq publishes a Security Advisory describing the affected products, available software updates or mitigations, and supporting technical documentation.

Security Advisories

Advisory Date

Advisory Title

Products Affected

Documentation

January 21, 2026
Ambiq Security Advisory A-SOCAPG-PSNGA01EN
Apollo3 Blue, Apollo3 Blue Plus, Apollo330B Plus, Apollo330M Plus, Apollo4 Blue Lite, Apollo4 Blue Plus,Apollo510B, Apollo510B Lite
February 17, 2026
Ambiq Security Advisory A-SOCAPG-PSNGA02EN
Apollo330 Plus, Apollo330B Plus, Apollo330M Plus, Apollo510 Lite, Apoloo510B, ApolloB Lite, Apollo510D Lite

Contact the Product Security Team

For questions related to product security or vulnerability disclosure, please contact the Ambiq Product Security Incident Response Team (PSIRT).

Email: PSIRT@ambiq.com

This contact is intended for product security and vulnerability disclosure inquiries only. For technical support, product documentation, or general product questions, please visit the Ambiq Support Center.

Frequently Asked Questions

  • Use the Vulnerability Reporting Form to report suspected security vulnerabilities affecting Ambiq products, software, development tools, SDKs, or services. For technical support, product defects that are not security-related, or feature requests, please use the appropriate customer support channels.

  • To help us investigate your report efficiently, please include:

    • The affected product, software, or service
    • Product model and firmware or software version, if applicable
    • A description of the vulnerability and its potential impact
    • Steps to reproduce the issue
    • Proof-of-concept code, screenshots, logs, or other supporting evidence, if available
    Providing complete information helps our Product Security Incident Response Team (PSIRT) validate and prioritize your report.

  • After receiving your report, Ambiq’s PSIRT will review the information, assess the potential impact, and determine whether additional details are needed. If the report describes a valid security vulnerability, we will investigate the issue, develop appropriate remediation, and coordinate any necessary communications.

  • If a reported vulnerability or security incident meets the reporting criteria established by the Cyber Resilience Act (CRA), Ambiq will submit the required regulatory notifications to the European Union Agency for Cybersecurity (ENISA) within the applicable regulatory timeframes.

  • No. Every reported vulnerability is evaluated by Ambiq’s Product Security Incident Response Team (PSIRT). Only vulnerabilities or security incidents that meet the reporting thresholds defined by the Cyber Resilience Act require notification to ENISA.

Preparing to download