Disclosure policy

Disclosure policy.

Disclosure policy

Vendors hear first.

About 30 daysFor behaviour that differs from the vendor's documentation, privacy statement or settings, such as telemetry a privacy page says is not collected, or an opt-out that does not stop what it says.
90 daysFor security vulnerabilities: flaws that let someone other than the user read, change or take data, or run commands, beyond what the user allowed.
Time when it is neededWe extend the window when a fix is in progress, re-test fixed versions, and publish both results.
Nothing earlyUntil the date, affected results show only "Held" and the date, and no detail is published. The one exception: if users are at immediate risk or a flaw is being exploited, we may publish sooner, after telling the vendor.

We disclose by email to the vendor's published security or privacy contact. We do not resubmit through web forms or third-party platforms, including bug bounty platforms whose terms can restrict publication. An automated reply redirecting us elsewhere is treated as receipt and does not change our timeline.

Want an agent included, or want to dispute a result? Vendors can ask for a re-test after a fix.

Submit your harnessContact usRun the rig yourself

Or write to research@agenticthinking.uk.