Trust / Responsible disclosure

Found something? Tell us, safely.

Agent Etna handles agents and the code that powers them. We take that seriously, and we want anyone who finds a security issue to be able to tell us without worrying about how we'll respond. This page is what to expect when you do.

How to report

Email security@agentetna.com with:

If you'd prefer encrypted reports, ask for our PGP key in the first message and we'll send it back.

What we commit to

Safe harbour

We will not pursue legal action against researchers who act in good faith and follow this policy. Specifically, we won't pursue a researcher who:

If you're unsure whether a research approach is OK, ask us first at the same email — we'd rather scope something safely than find out after.

In scope

Out of scope

To keep our triage focused on what matters, the following are not eligible for safe-harbour treatment:

Coordinated disclosure

We default to coordinated disclosure: we ship a fix, then you and we publish together. We aim for a 90-day window for most issues, shorter for actively exploited ones, longer when a fix is genuinely complex — we'll always tell you the reasoning.

Ready to report?

One short email is enough to start — we'll take it from there.

security@agentetna.com