Skip to content

Security: ai-agent-assembly/docs

SECURITY.md

Security Policy

Reporting a Vulnerability

Report security vulnerabilities privately to security@agent-assembly.com. Do not open a public issue or discussion for a security report.

Response stage Target
Acknowledgement Within 2 business days
Initial assessment Within 5 business days

Legacy address. security@agent-assembly.dev remains a legacy compatibility alias. During the in-progress migration to the canonical security@agent-assembly.com identity, the legacy address continues to receive mail via Cloudflare Email Routing, so a report sent there still reaches us. The canonical mailbox is not yet live-sending.

Supported Versions

Version Supported
0.0.x
< 0.0.1

Once we ship v0.1.0, we'll update this table with the supported window (typically the latest minor + one previous).

Disclosure

  • We'll work with you on a fix and coordinated disclosure timeline.
  • We'll credit you in the release notes for the fixed version, unless you prefer to remain anonymous.

For non-security bugs, please use the regular issue tracker on the relevant repo.

There aren't any published security advisories