Vulnerability disclosure.
AGICOMPLY accepts good-faith reports that help protect customer evidence, package integrity, tenant boundaries, and public services.
How to report
Email support@agicomply.com with “Security Report” in the subject line. Include the affected URL or component, reproduction steps, observed impact, and a safe method for follow-up.
Do not include customer evidence, credentials, access tokens, private keys, or personal information in the initial email. We will provide a controlled route when sensitive supporting material is necessary.
Good-faith boundaries
- Avoid privacy violations, destructive testing, data exfiltration, denial of service, social engineering, and access beyond the minimum required to demonstrate the condition.
- Stop testing and report immediately if customer or cross-tenant data becomes visible.
- Do not publicly disclose an unresolved condition before AGICOMPLY has had a reasonable opportunity to investigate and correct it.
What to expect
We will acknowledge a credible report, assign a review priority, investigate the affected boundary, and communicate material remediation status when appropriate. This page does not establish a paid bug-bounty program, guaranteed response time, safe-harbor agreement, or reward commitment.
Other assurance materials
See the Security Statement, Public Assurance Register, and Procurement Vault.