Report a vulnerability

The security page is the home for this. The same rules are repeated here so an old link still tells the truth.

Responsible disclosure

Email security@agentics.you. That inbox is read. Tell us what you found, where it is, and how to see it again. We will acknowledge your report within 72 hours.

Scope: Bond vaults, the attestor and the claim API, and Connect at /mcp.

A bug bounty is coming. We will publish the rules before it starts.

Security page · security.txt