New ReleaseIntroducing EnterpriseACP — The Enterprise Agent Control Plane.See the platform →
EnterpriseACP
Cyber Security Response Team

Responsible Disclosure Policy

At EnterpriseACP, security is our foundational mandate. We welcome reports from security researchers and industry partners who help protect our control plane architecture.

Vulnerability Response Commitment SLA

< 2 HoursFirst Triage Acknowledgement
< 24 HoursInitial Assessment & Reproduction
< 7 DaysRemediation Patch Deployment

1. Safe Harbor Policy

When conducting research in good faith and in alignment with this policy, EnterpriseACP considers your research authorized. We will not initiate legal action or law enforcement complaints against researchers who abide by responsible disclosure principles.

2. Scope & Target Inclusions

In Scope:

  • EnterpriseACP Sidecar Proxy & MCP Interception Engines
  • Agent Passport Cryptographic Verification Routines
  • Runtime Lease Token Minting & Revocation Handlers
  • Console Authorization & Role-Based Access Control Boundaries

3. Reporting Procedure

Please transmit encrypted vulnerability reports including reproduction steps, proof of concept code, and impacted component specs to:

security@enterpriseacp.comPGP Key ID: 0x4E9A28B1

4. Guidelines for Testing

  • Do not attempt to access customer telemetry, live agent passports, or tenant data.
  • Do not perform Denial of Service (DoS/DDoS) testing against production control plane gateways.
  • Give EnterpriseACP reasonable time to deploy remediation patches before public disclosure.