Agent Control Panel
HomePricingDocsTrust
Request early access
Legal
  • All documents
  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum
  • Acceptable Use Policy
  • Cookie Policy
  • Responsible Disclosure
  • Enterprise Agreement (on request)
Legal/Responsible Disclosure
Legal

Responsible Disclosure

Last updated: September 29, 2026

We welcome reports from security researchers. If you believe you have found a vulnerability in Agent Control Panel, please tell us privately and give us a reasonable chance to fix it. This policy explains what is in scope, how to report, what you can expect from us, and the protections we offer for good-faith research.

On this page
  1. 1. How to report
  2. 2. In scope
  3. 3. Out of scope
  4. 4. Rules of engagement
  5. 5. Safe harbor
  6. 6. What to expect from us
  7. 7. Disclosure policy
  8. 8. Rewards
  9. 9. Hall of Fame

1. How to report

Email Founders@skaigroup.tech with the subject “Security report”. Reports go straight to the founders. Please include:

  • a description of the issue and its potential impact;
  • the affected URL, endpoint, SDK version, or component;
  • step-by-step instructions or a proof of concept to reproduce it;
  • any accounts or organization IDs you used for testing;
  • how you would like to be credited, if at all.

If you want to encrypt your report, ask and we will arrange a secure channel. Our machine-readable contact details are at /.well-known/security.txt.

2. In scope

  • The Agent Control Panel dashboard and API served from our production domains, including the sign-in flow.
  • The ACP SDK and the integration code the Service generates, including command signature verification.
  • Tenant isolation: any way to read or change another organization’s data, agents, keys, or settings.
  • Authentication, authorization, API key scopes, and role checks.
  • Signed control commands: forgery, replay, or scope bypass.
  • Server-side request forgery through webhook or alert URLs.
  • Prompt injection in ACP’s AI Features that leads to data exposure across organizations or to unauthorized actions.
  • This marketing website, where an issue affects users (for example, cross-site scripting).

3. Out of scope

  • Denial-of-service or load testing, and volumetric attacks of any kind.
  • Social engineering, phishing, or physical attacks against our team, customers, or providers.
  • Vulnerabilities in third-party services we use (such as our hosting, database, authentication, or AI providers). Report those to the provider; tell us too if ACP’s configuration makes the issue worse.
  • Findings from automated scanners without a demonstrated, exploitable impact.
  • Missing security headers or cookie flags without a demonstrated impact, clickjacking on pages without sensitive actions, and self-XSS.
  • Rate-limit or brute-force findings that do not lead to account compromise.
  • Email configuration findings (SPF, DKIM, DMARC) and reports about software versions or banners without an exploit.
  • Issues that require a compromised device, a rooted or jailbroken phone, or an outdated browser.
  • Vulnerabilities in customers’ own agents or applications.

4. Rules of engagement

  • Test only against accounts and organizations you own or have explicit permission to use. Create your own free account for testing.
  • Do not access, modify, or delete data that is not yours. If you encounter other users’ data, stop, do not keep a copy, and tell us immediately.
  • Use the minimum access needed to demonstrate the issue, and do not use an exploit to move further into our systems.
  • Do not degrade the Service for others, and do not send commands to agents you do not control.
  • Keep the details confidential until we have fixed the issue and agreed on disclosure.
  • Comply with applicable law and do not demand payment in exchange for not disclosing an issue.

5. Safe harbor

If you make a good-faith effort to follow this policy, we will consider your research authorized, will not pursue or support legal action against you for it, and will not report you to law enforcement. We consider such research exempt from the restrictions in our Acceptable Use Policy and Terms of Service that would otherwise prohibit it, to the extent needed to follow this policy. If a third party brings legal action against you for activity that followed this policy, we will make it known that your actions were authorized by us.

If you are unsure whether something is allowed, ask us first at Founders@skaigroup.tech. This safe harbor does not cover activity that violates the rules above or the law.

6. What to expect from us

StepTarget
Acknowledge your reportWithin 3 business days
Initial assessment and severityWithin 10 business days
Fix for critical and high severity issuesAim for 30 days
Fix for medium and low severity issuesAim for 90 days
Status updatesAt least every 14 days until resolved

We are a small team, so these are targets rather than guarantees. We will keep you informed if a fix takes longer.

7. Disclosure policy

We follow coordinated disclosure. Once a fix is released, we are happy for you to publish your findings, and we ask that you share a draft with us first so we can check it contains no customer data. If we have not fixed a valid issue within 90 days of your report, we will agree a disclosure date with you. If a vulnerability affected customer data, we will notify affected customers as required by our agreements and the law.

8. Rewards

We do not offer monetary rewards yet. Paid rewards are planned once budget allows, and we will announce them on this page. Today we offer public credit in our Hall of Fame and our sincere thanks.

9. Hall of Fame

Researchers who reported valid issues and agreed to be named:

No reports yet. Be the first.

Questions about this document? Email Founders@skaigroup.tech. Other policies: Legal hub · Security & Trust.

© 2026 Agent Control Panel
OverviewDocumentationPricingSecurity & TrustTermsPrivacyGuidesLegalContactSign in