← PQSafe AgentPay

Security

Responsible disclosure, bug bounty, and vulnerability policy.

Report a Vulnerability

For sensitive disclosures, use GitHub Security Advisories — this provides an encrypted, private channel directly to the team.

For general security questions: [email protected]

We prefer responsible disclosure. Please give us a reasonable window to investigate and patch before any public disclosure.

Vulnerability Policy

Scope, disclosure timeline, and out-of-scope items are documented in the full policy.

Read the full security policy →

Bug Bounty

Launching May 2026

An Immunefi bug bounty program is planned for May 2026, covering the AP2-PQ Worker, SpendEnvelopeRegistry contract, and core SDK packages.

Until then, we acknowledge all valid critical reports in our Hall of Fame.

Machine-Readable Disclosure File

/.well-known/security.txt — RFC 9116 compliant disclosure policy.