If you find a weakness in an AIW system, we want to hear about it before anyone else does. This policy sets out how to report one and what we commit to in return.
1. Scope
In scope
- www.agentsiw.com and its subdomains, including AIW-operated preview domains
- AIW-operated APIs and endpoints reachable from those hosts
- AIW's public-facing infrastructure configuration — DNS, email authentication, TLS
- Vulnerabilities in a client system that you discover as an authorised user of that system
Out of scope
- Client-owned systems and infrastructure where AIW is not the operator — report those to the client
- Third-party services AIW uses; report those to the provider under their own policy
- Denial-of-service, volumetric, or stress testing
- Social engineering of AIW personnel, clients, or suppliers
- Physical intrusion
- Findings from automated scanners without a demonstrated, exploitable impact
- Missing best-practice headers, absent SPF/DMARC hardening, weak TLS ciphers, and similar configuration observations with no demonstrated impact
- Self-inflicted or clickjacking issues requiring implausible user interaction
- Outdated browsers or unsupported platforms
2. Rules Of Engagement
Testing is authorised only within these limits:
- Use no more force than needed to demonstrate the issue. Stop as soon as you have proof.
- Do not access, modify, exfiltrate, or retain data belonging to anyone else. If you encounter personal data, stop, do not save it, and tell us in the report.
- Do not degrade availability, delete data, or alter system state.
- Do not use social engineering, spam, or physical access.
- Do not pivot from an initial finding deeper into the environment.
- Use your own test accounts. Do not attempt access to another party's account.
- Keep the finding confidential until we have confirmed it is resolved, or until 90 days have passed after your report.
Stay within these limits and AIW will treat your research as authorised, will not pursue civil or criminal action, and will not report you to authorities for the research itself. This is not a waiver of third-party rights: if your testing affects a client's environment or a third-party provider, their terms still apply.
3. How To Report
Email admin@agentsiw.com with subject line SECURITY. Include:
- A clear description of the vulnerability and its impact
- The affected URL, endpoint, or component
- Reproduction steps, and a proof of concept if you have one
- Your assessment of severity, and any suggested remediation
- Whether you want to be credited, and under what name
English or Dutch is fine. Do not include third-party personal data in the report.
4. What We Commit To
| Stage | Our commitment |
|---|---|
| Acknowledgement | Within 3 business days |
| Initial triage and severity assessment | Within 10 business days |
| Progress updates | Every 14 days while the issue is open |
| Remediation target — critical | 7 days |
| Remediation target — high | 30 days |
| Remediation target — medium and low | 90 days |
| Confirmation of fix | On deployment, with your report referenced |
We will tell you honestly if we decide not to fix something, and why.
5. Recognition
AIW does not currently run a paid bug bounty. We offer:
- Public credit on this page, with your permission
- A written acknowledgement suitable for a CV or portfolio
- Direct communication with the person who owns the fix, not a ticket queue
Reports are assessed on impact, not on volume.
6. AI-Specific Findings
We welcome reports on:
- Prompt injection allowing an agent to act outside its permitted tool set
- Extraction of system prompts, credentials, or configuration through model interaction
- Guardrail or oversight-checkpoint bypass in a deployed system
- Retrieval boundary failures that surface one tenant's documents to another
- Output-handling flaws — for example, generated content executed or trusted without validation
Demonstrate the boundary crossing; do not exfiltrate the data you can reach. Model behaviour that is merely undesirable — an unhelpful answer, a refusal, a stylistic failure — is not a vulnerability. Send that to admin@agentsiw.com instead.
7. Acknowledgements
Researchers who have reported valid findings will be listed here with their permission.
8. Contact
admin@agentsiw.com · fallback admin@agentsiw.com
Appendix — security.txt
Publish at https://www.agentsiw.com/.well-known/security.txt per RFC 9116.
Contact: mailto:admin@agentsiw.com
Contact: /legal/responsible-disclosure
Expires: 2027-09-12T00:00:00.000Z
Preferred-Languages: en, nl
Canonical: https://www.agentsiw.com/.well-known/security.txt
Policy: /legal/responsible-disclosure
Keep the Expires value less than 12 months ahead and refresh it on each annual review.