AGILICRYPT™ Security

Vulnerability disclosure

Version 1.0 · 17 August 2026.

Found a security problem in something we made? Tell us: security@agilicrypt.com. We will acknowledge within 3–5 business days and give you a substantive response within 10.

What we promise you

What we ask of you

What is in scope

In scopeNot in scope
The assessment tool and collectors in any bundle we issued
agilicrypt.com and its subdomains
The data files we ship — snapshot, module map, identity map
Anything that makes a report say something untrue
Findings against NIST, Stripe, Microsoft or any third party — report those to them
Missing hardening headers with no demonstrated impact
Volumetric denial of service
Social engineering of us or our customers
Anything requiring physical access to a machine

The category we care about most

A defect that makes a report wrong is a security defect here, and we treat it as one.

Our product is evidence. A parsing flaw that causes an affected certificate to be missed, a version comparison that silently matches the wrong module, or anything that turns "we could not determine this" into a clean result — those do more damage than most conventional vulnerabilities, because a customer may carry the answer into a contract action. Report them here and we will treat them with the same urgency as a code execution bug.

Cryptographic vulnerabilities

Reports concerning cryptographic implementation, algorithm selection, certificate handling or validation logic are explicitly welcome and are handled under this policy.

Executive Order 14412 §6(d) directs the FAR Council to publish a proposed rule requiring covered contractors to disclose cryptographic vulnerabilities. This policy is in force now rather than when that rule arrives.

Safe harbour

Activity conducted in good faith under this policy is authorized access as far as we are concerned, and we will say so in writing if anyone asks. If a third party brings action against you for work done within this policy, tell us and we will make our authorization clear to them.

We cannot authorize access to systems we do not own. If your testing would reach a customer's environment or a third party's service, it is outside this policy and outside our gift to permit.

If you would rather encrypt it

Email security@agilicrypt.com and ask, and we will arrange a channel before you send anything sensitive. Do not send exploit detail or customer data in plain email until we have.

No bounty

We do not run a paid bounty program, and saying so plainly is fairer than letting anyone assume otherwise. What you get is a fast answer, credit if you want it, and a fix.