SECURITY

Report a security issue

If you find a problem with agent-bev.ai — a key that does not verify, a record that answers wrong, a header that lies — tell the operator.

  • Machine-readable contact and policy: /.well-known/security.txt
  • Scope: agent-bev.ai and its twins (agent-bev.com, agentbev.ai, agentbev.com), the machine kit, the keyrings at bev-registry.ai and bev-x402.ai, and every door as it opens.
  • Out of scope: the makers' own sites and any third-party rail (Cloudflare, Formspree).
  • What to send: the URL, the request you made, what came back, and what you expected. Signed reports are welcome; the keyring is at bev-registry.ai/.well-known/jwks.json if you want to encrypt to it.
  • What the operator does: acknowledges within five business days, fixes on its own clock, and credits you on this page if you want credit.

No bounty. Good-faith research within scope will not be met with legal action.

Artificial intelligence makes mistakes. agent-bev is an information source, not a recommendation.