Skip to main content
Back to Home
Security

Vulnerability Disclosure Policy

Last updated: August 31, 2026

1. Scope

This policy covers security issues in:

  • attestedintelligence.com and its subpages
  • The demo verification gateway at aga-mcp-gateway.attested-intelligence.workers.dev
  • The published @attested-intelligence/aga-mcp-server and aga-verify npm packages
  • The published aga-governance PyPI package

Out of scope: the third-party services we integrate (Formspree, Vercel, Cloudflare, ImprovMX) have their own security teams and disclosure channels; report issues in their infrastructure to them directly, not to us.

2. How to Report

Email admin@attestedintelligence.com with:

  • A description of the issue and the component or URL affected
  • Steps to reproduce it
  • What an attacker could do with it, to the best of your assessment
  • Whether you want credit and, if so, the name to use

3. What to Expect

We are a small team, not a security operations center. We aim to acknowledge new reports within a few business days and to give you a rough sense of timeline once we understand the issue; for a straightforward fix, expect it shipped in days to a few weeks, not months. If a report turns out to be out of scope or not a vulnerability, we will tell you why.

4. Safe Harbor

If your research stays within this policy’s scope, is conducted in good faith, avoids privacy violations and service disruption, and you report the issue to us promptly and do not disclose it publicly before we have had a reasonable chance to address it (see Section 5), we consider that research authorized. We will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue.

5. Coordinated Disclosure

Please give us 90 days from your report before any public disclosure, so we have time to ship a fix. We will work with you on timing if a fix needs longer, and we are glad to credit researchers who want credit once an issue is resolved.

6. Please Don’t

  • Run automated scanning that degrades service for other visitors
  • Access, modify, or delete data that is not yours, beyond what is needed to demonstrate the issue
  • Attempt social engineering against us, our contractors, or our service providers
  • Test for physical security or attempt to access accounts that are not yours (this site has no user accounts; see our Privacy Policy)

7. Contact

admin@attestedintelligence.com. For what we do and do not claim about the cryptography itself, see Trust and Scope.