Found a vulnerability? Tell us first.
We'd rather hear about a problem from a security researcher than from an incident report. Good-faith research into Agent Etna is welcome, and we commit to responding quickly and treating reporters fairly.
How to report
Email contact@agentetna.com with what you found, the steps to reproduce it, and its impact. Encrypt anything sensitive if you can; otherwise plain email is fine. We acknowledge good-faith reports within 72 hours and follow up with a timeline once we've confirmed the issue.
What's in scope
- The hosted product (
agentetna.comand its API) and the sandbox execution path. - Authentication, authorization, and cross-tenant isolation issues — one customer's agent or data reachable by another.
- Injection classes — command, SQL, and prompt injection.
- Secrets handling — a key or credential exposed where it shouldn't be.
What's out of scope
- Denial-of-service testing, load testing, or anything that could degrade the service for other customers — report the theoretical issue instead of demonstrating it at scale.
- Social engineering against Agent Etna staff.
- Findings that require a compromised GitHub account, stolen API key, or other credential you shouldn't have had.
- An agent under test behaving badly in a scenario Etna itself generated to probe exactly that — that's the product working, not a vulnerability in it.
Safe harbor
We won't pursue legal action against researchers who report a good-faith finding through the channel above, stay within the scope listed here, and give us a reasonable window to fix the issue before any public disclosure.
What you get back
Not money. This is a responsible-disclosure channel, not a paid bounty, and if that ever changes this page will say so plainly rather than implying a payout that isn't real. What you do get is a straight answer about whether it's a real issue, and a reply from the person who fixes it.
Found something?
No form, no triage queue — the report lands with the people who wrote the code.