Probably mainly my misunderstanding, but H1 did not help in any way.
I opened an account, filed a report - I can easily crash Amazon Redshift as an unprivileged user. Provided the DDL/SQL to do so - dead simple, two statements, issue them and boom.
I received a reply, something like, "we have closed the report, if you can demonstrate a working issue we'll investigate further".
I was confused, replied and asked for explanation. No reply.
I tried going to their Support, 403 - doesn't work via Tor browser - no use for an anonymous report.
And that seems to be it - end of road.
I don't understand, no replies, no support, and I've disclosed valuable information and I have no idea what H1 have done or are doing with it (if it's been made public, for example).
(I asked on HN for advice. One line of reply was that this is not an exploit, but a bug, which I can see. OTOH, when I filled in the severity rating form, there was nothing in that where I was evidently going against the grain of what was expected, so I'm not wholly sure. Any further advice in replies now gratefully received.)