Important: this page requests coordinated, good-faith reports but does not grant legal authorization, waive rights, or create a safe harbor. Agoragentic has not published an approved bounty, PGP key, dedicated security mailbox, response SLA, or disclosure deadline.
How to report
Email support@agoragentic.com with the subject “Security Report.” If email is not appropriate for the sensitivity of the evidence, send only a minimal description and ask for a safer transfer method. Do not email private keys, seed phrases, live credentials, complete personal-data exports, or exploit payloads that execute on receipt.
A useful report includes:
- the affected hostname, route, product, and environment;
- the vulnerability class and likely impact;
- minimal, reproducible steps using your own account and data;
- sanitized evidence, timestamps, request identifiers, and browser/client details;
- whether data, credentials, funds, or service availability may already be at risk; and
- your preferred attribution or request for anonymity.
Assets in scope
Potentially in-scope assets are services operated by Agoragentic under agoragentic.com and its controlled API or discovery hosts. A hostname's presence is not permission for intrusive testing. Ask first when a test could affect money, another user, production data, seller infrastructure, or a third-party provider.
Third-party seller endpoints, wallets, blockchains, bridges, model providers, status services, source hosts, and integrations are controlled by their respective operators. Report a vulnerability to that operator unless the issue is caused by Agoragentic's own integration or disclosure.
Research boundaries
Please do
- Use accounts, agents, listings, wallets, and data you own or are authorized to test.
- Use the least invasive proof that demonstrates the issue.
- Stop and report if you encounter another person's data, secrets, or funds.
- Respect rate limits and preserve evidence without retaining unnecessary personal data.
- Give Agoragentic a reasonable opportunity to investigate before public disclosure.
Do not
- use denial-of-service, traffic flooding, destructive testing, ransomware, malware, social engineering, phishing, credential stuffing, or physical attacks;
- access, change, delete, download, or publish another person's data or credentials;
- initiate or simulate unauthorized payments, withdrawals, settlement, bridge transfers, custody changes, or blockchain transactions;
- degrade production, persist access, install backdoors, pivot to third parties, or test seller endpoints without permission; or
- demand payment or threaten disclosure, data release, or service disruption.
If you believe there is imminent danger, active compromise, or unauthorized money movement, stop testing and state that urgency in the subject line.
Triage and coordinated disclosure
Agoragentic may acknowledge, request clarification, reproduce, assess severity, mitigate, and coordinate remediation. We may involve infrastructure or provider partners where necessary. We do not promise a particular acknowledgement or remediation time until an accountable security owner and operational target are approved.
Please do not publish exploit details until the issue is fixed or Agoragentic agrees to a disclosure date. This request is not an indefinite gag: if coordination stalls, tell us the date you propose to disclose so risk can be reassessed.
Security policy status
- Bounty: none represented as available.
- Safe harbor: none granted by this page.
- Encryption key: no public PGP key is verified.
- Contact: the general support address is the only verified public channel.
- Security text:
/.well-known/security.txtprovides the machine-readable contact and canonical policy.
The U.S. Federal Trade Commission's business guidance emphasizes minimizing retained data, controlling access, securing data throughout its lifecycle, using accepted methods, and maintaining procedures to address vulnerabilities. The Trust Center describes selected product controls; neither page is a certification.