Security
Reporting a vulnerability.
Draft — pending legal review
How to report
If you believe you have found a vulnerability in the public GAIP service (www.gaipagents.com and its API, MCP and A2A endpoints), send a description to agents@gaipagents.com or through the contact page: the affected URL or route, the steps to reproduce, what you observed and when. Please do not include personal data, secrets or other people's information.
Please
- Test only with your own requests against public endpoints.
- Do not access, change or delete data that is not yours, and do not degrade the service (no load testing or high-volume automated scanning).
- Allow reasonable time for investigation before any public disclosure.
What happens next
Reports are read by the founder, acknowledged and investigated; fixes that change public behaviour are recorded in the changelog. There is no bounty or payment. TODO(founder): state a target acknowledgement time and confirm this policy with a solicitor.
Machine-readable contact: /.well-known/security.txt · GAIP's automated clients · Privacy notice