Responsible Disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in Agent Control Panel, please tell us privately and give us a reasonable chance to fix it. This policy explains what is in scope, how to report, what you can expect from us, and the protections we offer for good-faith research.
On this page
1. How to report
Email Founders@skaigroup.tech with the subject “Security report”. Reports go straight to the founders. Please include:
- a description of the issue and its potential impact;
- the affected URL, endpoint, SDK version, or component;
- step-by-step instructions or a proof of concept to reproduce it;
- any accounts or organization IDs you used for testing;
- how you would like to be credited, if at all.
If you want to encrypt your report, ask and we will arrange a secure channel. Our machine-readable contact details are at /.well-known/security.txt.
2. In scope
- The Agent Control Panel dashboard and API served from our production domains, including the sign-in flow.
- The ACP SDK and the integration code the Service generates, including command signature verification.
- Tenant isolation: any way to read or change another organization’s data, agents, keys, or settings.
- Authentication, authorization, API key scopes, and role checks.
- Signed control commands: forgery, replay, or scope bypass.
- Server-side request forgery through webhook or alert URLs.
- Prompt injection in ACP’s AI Features that leads to data exposure across organizations or to unauthorized actions.
- This marketing website, where an issue affects users (for example, cross-site scripting).
3. Out of scope
- Denial-of-service or load testing, and volumetric attacks of any kind.
- Social engineering, phishing, or physical attacks against our team, customers, or providers.
- Vulnerabilities in third-party services we use (such as our hosting, database, authentication, or AI providers). Report those to the provider; tell us too if ACP’s configuration makes the issue worse.
- Findings from automated scanners without a demonstrated, exploitable impact.
- Missing security headers or cookie flags without a demonstrated impact, clickjacking on pages without sensitive actions, and self-XSS.
- Rate-limit or brute-force findings that do not lead to account compromise.
- Email configuration findings (SPF, DKIM, DMARC) and reports about software versions or banners without an exploit.
- Issues that require a compromised device, a rooted or jailbroken phone, or an outdated browser.
- Vulnerabilities in customers’ own agents or applications.
4. Rules of engagement
- Test only against accounts and organizations you own or have explicit permission to use. Create your own free account for testing.
- Do not access, modify, or delete data that is not yours. If you encounter other users’ data, stop, do not keep a copy, and tell us immediately.
- Use the minimum access needed to demonstrate the issue, and do not use an exploit to move further into our systems.
- Do not degrade the Service for others, and do not send commands to agents you do not control.
- Keep the details confidential until we have fixed the issue and agreed on disclosure.
- Comply with applicable law and do not demand payment in exchange for not disclosing an issue.
5. Safe harbor
If you make a good-faith effort to follow this policy, we will consider your research authorized, will not pursue or support legal action against you for it, and will not report you to law enforcement. We consider such research exempt from the restrictions in our Acceptable Use Policy and Terms of Service that would otherwise prohibit it, to the extent needed to follow this policy. If a third party brings legal action against you for activity that followed this policy, we will make it known that your actions were authorized by us.
If you are unsure whether something is allowed, ask us first at Founders@skaigroup.tech. This safe harbor does not cover activity that violates the rules above or the law.
6. What to expect from us
| Step | Target |
|---|---|
| Acknowledge your report | Within 3 business days |
| Initial assessment and severity | Within 10 business days |
| Fix for critical and high severity issues | Aim for 30 days |
| Fix for medium and low severity issues | Aim for 90 days |
| Status updates | At least every 14 days until resolved |
We are a small team, so these are targets rather than guarantees. We will keep you informed if a fix takes longer.
7. Disclosure policy
We follow coordinated disclosure. Once a fix is released, we are happy for you to publish your findings, and we ask that you share a draft with us first so we can check it contains no customer data. If we have not fixed a valid issue within 90 days of your report, we will agree a disclosure date with you. If a vulnerability affected customer data, we will notify affected customers as required by our agreements and the law.
8. Rewards
We do not offer monetary rewards yet. Paid rewards are planned once budget allows, and we will announce them on this page. Today we offer public credit in our Hall of Fame and our sincere thanks.
9. Hall of Fame
Researchers who reported valid issues and agreed to be named:
No reports yet. Be the first.