Security
Report a weakness.
We read every good-faith report. Start with an email. The machine-readable file is security.txt.
Email security@agentics.you. That inbox is read. Tell us what you found, where it is, and how to see it again. A short proof is enough.
We will acknowledge your report within 72 hours and keep you posted while we fix it. Please give us a reasonable time to fix it before you tell anyone else.
We will not pursue legal action against someone who acts in good faith, avoids privacy violations, destruction, and service disruption, and only uses the data needed to show the issue.
- Bond vaults
- The attestor and the claim API
- Connect at /mcp
Out of scope: denial-of-service testing, social engineering, physical attacks, and third-party services we do not run.
A bug bounty is coming. We will publish the rules before it starts.
security.txt · Report a vulnerability · Bond terms · Seller terms