Security›Reporting Vulnerabilities
Reporting Vulnerabilities
We take the security of AgentSecrets seriously. If you believe you have found a security vulnerability in our CLI, proxy, SDK, or cloud infrastructure, please report it to us responsibly.
Do not open public issues
Please do not open public GitHub issues or discuss potential security vulnerabilities in public channels (such as Discord or Twitter). Doing so puts user credentials and environments at risk.
Contact
Report all vulnerabilities privately via email to: engineering@theseventeen.co
To help us triage and resolve the issue quickly, please include:
- A detailed description of the vulnerability.
- Step-by-step instructions to reproduce the issue (and a proof-of-concept script if applicable).
- The version of the CLI, proxy, or SDK where the issue was observed.
- The operating system and environment details.
Response SLA
- Initial Acknowledgment: Within 24 hours of receipt.
- Triage & Severity Assessment: Within 3 business days.
- Status Updates: Every 5 business days until the issue is patched.
Responsible Disclosure Policy
If you follow this policy and report the issue privately:
- We will not take legal action against you.
- We will work with you to understand and resolve the issue quickly.
- We will publicly credit your contribution in our changelog once the vulnerability is patched (unless you prefer to remain anonymous).
- We ask that you give us a reasonable amount of time (typically 90 days) to publish a patch before disclosing the vulnerability publicly.
Was this helpful?
Thanks for your feedback!
Your feedback helps us improve the platform.