SECURITY
Report a security issue
If you find a problem with agent-bev.ai — a key that does not verify, a record that answers wrong, a header that lies — tell the operator.
- Machine-readable contact and policy: /.well-known/security.txt
- Scope: agent-bev.ai and its twins (agent-bev.com, agentbev.ai, agentbev.com), the machine kit, the keyrings at bev-registry.ai and bev-x402.ai, and every door as it opens.
- Out of scope: the makers' own sites and any third-party rail (Cloudflare, Formspree).
- What to send: the URL, the request you made, what came back, and what you expected. Signed reports are welcome; the keyring is at bev-registry.ai/.well-known/jwks.json if you want to encrypt to it.
- What the operator does: acknowledges within five business days, fixes on its own clock, and credits you on this page if you want credit.
No bounty. Good-faith research within scope will not be met with legal action.