In scope
Systems we operate and want you to test:
- The AgentTask web application and its API, including the developer API and the hosted MCP endpoint.
- The marketing site.
- The AgentTask desktop application (macOS and Windows) as distributed by us.
- Vulnerabilities that let one organization read or modify another organization’s data, escalate a member’s role beyond what was granted, or bypass authentication.
Out of scope
Please do not test the following. Reports in these categories are usually closed as informational:
- Denial of service, volumetric, brute-force, or load testing of any kind.
- Social engineering, phishing, or physical attacks against our staff, users, or offices.
- Findings that only affect third-party services we consume (report those to the vendor directly).
- Missing hardening headers, cookie flags, or TLS configuration preferences with no demonstrated impact.
- Output from automated scanners submitted without a working proof of concept or a described impact.
- Issues requiring a rooted, jailbroken, or otherwise compromised device, or a physically present attacker.
- Self-XSS, clickjacking on pages with no sensitive state change, and version-disclosure banners.
Rules of engagement
While testing, we ask that you:
- Use only accounts and organizations you own or have explicit permission to test.
- Stop as soon as you have confirmed a vulnerability — do not pivot further into our systems.
- Never access, modify, exfiltrate, or retain another person’s or organization’s data. If you encounter it accidentally, stop, tell us, and delete your copy.
- Do not degrade the service for other users, and do not run destructive tests against production.
- Give us a reasonable opportunity to remediate before disclosing publicly, and coordinate the timing with us.
Safe harbour
If you make a good-faith effort to follow this policy, we will treat your research as authorised conduct. We will not initiate or support legal action against you, we will not report you to law enforcement for the research, and we will not ask your internet provider to act against you. If a third party brings action against you for activity that this policy authorised, we will make it known that your testing was conducted with our permission. Good faith means following the rules of engagement above; testing that damages our systems, exposes other customers’ data, or attempts extortion is outside this policy and outside its protection. This is our commitment to you, not legal advice, and it does not waive any rights of a third party.
What to expect from us
These are the targets we hold ourselves to. They are aims rather than a contractual service level, and we will tell you if a report is going to take longer:
- Acknowledgement that we received your report within 5 business days.
- An initial assessment — whether we consider it a vulnerability, and a rough severity — within 10 business days.
- A status update at least every 30 days while the issue is open, until it is resolved or we explain why we will not act on it.
- Notice to you when the fix ships, so you can verify it and plan any disclosure.
Recognition
We do not run a paid bug bounty, and this policy is not an offer of payment or a reward. What we do offer: with your permission we will credit you by name (or handle) when we describe the fix, and we will provide written confirmation of your report and its resolution if you need it for your own disclosure records or CVE process.
Machine-readable contact
The same contact details are published as an RFC 9116 file at /.well-known/security.txt. That file expires on 2027-08-22; if you are reading it after that date, this page remains the authoritative policy.