Last updated: August 31, 2026
Contact
Report a vulnerability to contact@agentmaurice.ai using the subject “Security vulnerability”.
In your first message, include the affected product and version, observed impact, minimal reproduction steps, and a way to contact you. Do not send personal data, secrets, or customer data until an appropriate transfer channel has been agreed.
Our commitment
- target acknowledgement within three business days;
- target triage and status update within seven business days;
- regular updates until remediation or documented risk acceptance;
- public credit if requested and if disclosure is coordinated.
These are response targets, not a guarantee of resolution.
Responsible research rules
Limit testing to accounts and data you control. Do not perform denial of service, social engineering, physical attacks, spam, data exfiltration, or modification of third-party data. Stop testing as soon as unauthorized data becomes accessible, report it, and do not retain it.
We will not pursue research conducted in good faith, within these rules, for the purpose of helping us remediate a vulnerability. This statement does not cover unlawful, destructive, or third-party harmful activity.
Disclosure
Coordinate publication with us. We will propose a timeline based on severity, patch availability, and user risk. AgentMaurice currently has no bug bounty program and does not promise automatic rewards.