Vulnerability disclosure
Version 1.0 · 17 August 2026.
What we promise you
- We will not pursue you. If you act in good faith under this policy, we will not bring legal action, will not report you, and will not ask your employer to. Finding a problem and telling us is a favor, and we will treat it as one.
- We will tell you what we did. Whether we fix it, mitigate it, or decide it is not a vulnerability, you get a reasoned answer rather than silence.
- We will credit you if you want the credit, and stay quiet about you if you do not. Your choice, not ours.
- We will tell affected customers. If a problem reaches anyone who holds our software or a report we produced, they hear it from us.
What we ask of you
- Report privately first, and give us a reasonable chance to fix it before publishing. We are not going to bargain over what "reasonable" means; tell us your intended timeline and we will work to it.
- Do not access, alter or destroy data that is not yours, and do not degrade any service. Stop as soon as you have proved the point.
- Give us enough to reproduce it — the version, the input, and what you expected instead.
What is in scope
| In scope | Not in scope |
|---|---|
The assessment tool and collectors in any bundle we issuedagilicrypt.com and its subdomainsThe data files we ship — snapshot, module map, identity map Anything that makes a report say something untrue |
Findings against NIST, Stripe, Microsoft or any third party —
report those to them Missing hardening headers with no demonstrated impact Volumetric denial of service Social engineering of us or our customers Anything requiring physical access to a machine |
The category we care about most
Our product is evidence. A parsing flaw that causes an affected certificate to be missed, a version comparison that silently matches the wrong module, or anything that turns "we could not determine this" into a clean result — those do more damage than most conventional vulnerabilities, because a customer may carry the answer into a contract action. Report them here and we will treat them with the same urgency as a code execution bug.
Cryptographic vulnerabilities
Reports concerning cryptographic implementation, algorithm selection, certificate handling or validation logic are explicitly welcome and are handled under this policy.
Executive Order 14412 §6(d) directs the FAR Council to publish a proposed rule requiring covered contractors to disclose cryptographic vulnerabilities. This policy is in force now rather than when that rule arrives.
Safe harbour
Activity conducted in good faith under this policy is authorized access as far as we are concerned, and we will say so in writing if anyone asks. If a third party brings action against you for work done within this policy, tell us and we will make our authorization clear to them.
We cannot authorize access to systems we do not own. If your testing would reach a customer's environment or a third party's service, it is outside this policy and outside our gift to permit.
If you would rather encrypt it
Email security@agilicrypt.com and ask, and we will arrange a channel before you send anything sensitive. Do not send exploit detail or customer data in plain email until we have.
No bounty
We do not run a paid bounty program, and saying so plainly is fairer than letting anyone assume otherwise. What you get is a fast answer, credit if you want it, and a fix.