Security

Responsible disclosure

Effective 3 June 2026 · Version 1.0

In plain English

Sigil holds the keys to your AI agents' access. If you find a flaw, please tell us before you tell anyone else. We will read your report personally within one business day, fix the issue, and credit you publicly if you want.

How to report

Email [email protected] with as much detail as you can — ideally a clear reproduction. We aim to acknowledge every report within one business day and to give you a substantive technical reply within seven days.

If the issue is severe and being actively exploited, write URGENT in the subject and we will escalate. If you want to encrypt your report, ask us for a current PGP key in your first message and we will send it back to you.

What we commit to

What's in scope

What's out of scope

We won't action reports that fall into these categories — but please tell us anyway if you think you've found something genuinely impactful that happens to match a pattern below; we'd rather hear it than miss it.

Rules of engagement

Safe harbor. If you make a good-faith effort to comply with this policy during your research, we will treat your activity as authorised. We will not initiate or support legal action against you for compliant research. Compliance includes: testing only your own accounts, never destroying or exfiltrating data, and giving us a reasonable window before disclosure.

On bug bounty

We don't currently run a paid bug-bounty programme. We're a small team in private beta. Once the user base and revenue justify it, we will — most likely on HackerOne or Intigriti — and we will honour reports submitted before that programme exists when we set the rules. Until then, we offer credit, a sincere thank-you, and the satisfaction of having protected real people's keys.

How we handle credentials

For context on what's actually at stake when you find a flaw:

If you find a flaw that breaks any of the above invariants, that is exactly the kind of report we want.

Past advisories

We have not issued any security advisories yet. When we do, they will appear here with date, severity, what was affected, what we fixed, and credit to the reporter (if they wanted it).

Hall of recognition

This section will list researchers who have responsibly disclosed issues to us. It is empty today.

Reporting: [email protected]

General questions: [email protected]

Machine-readable summary: /.well-known/security.txt (RFC 9116)