Responsible Disclosure Policy
Last updated: July 5, 2026
We welcome good-faith security research into RunAIAgents. If you've found a vulnerability, we want to hear about it, and we will work with you to understand and resolve the issue quickly.
Safe harbour. We will not pursue legal action against researchers who test in good faith and follow this policy: avoid privacy violations and service disruption, access only the data necessary to demonstrate an issue, do not access or modify other users' data, and report the issue to us before any public disclosure.
In scope: runaiagents.io and its subdomains (including agents.runaiagents.io), the RunAIAgents application, our published MCP and A2A endpoints, and our first-party connectors.
Out of scope: infrastructure you bring and control under BYOC, your own model provider accounts under BYOK, third-party services we integrate with, denial-of-service testing, social engineering, physical attacks, and automated scanning noise with no demonstrated impact.
How to report. Reach us through the contact page with a clear description of the issue, steps to reproduce, and the potential impact.
Please give us reasonable time to investigate and remediate a reported issue before disclosing it publicly. We'll acknowledge your report and keep you updated as we work on a fix.