1. Purpose and safe harbor
We welcome good-faith security research that helps protect Agentic Universe and its users. If you comply with this policy, we will treat your research as authorised for purposes of applicable computer misuse laws, will not initiate legal action against you for accidental, good-faith violations, and will work with you to understand and resolve the issue.
This safe harbor does not bind third parties or excuse violations of law. If a third party brings action and you complied with this policy, we will make reasonable efforts to clarify that your activity was conducted under our policy. If you are unsure whether a test is allowed, ask before proceeding.
2. In scope
Only publicly accessible systems and assets that are owned and operated by Qultured Media Private Limited for Agentic Universe are in scope, specifically:
agenticuniverse.aiand its public subdomains;- public web pages and APIs served under those domains; and
- authentication and demo flows directly controlled by us.
An asset is not in scope merely because it uses our name or integrates with us. If ownership is unclear, stop and ask.
3. Out of scope
- third-party systems and services, including Vercel, Google, Microsoft, Telegram, Twilio, Exotel, Ozonetel, WhatsApp and other voice, telephony, AI or infrastructure providers;
- customer, partner, employee or vendor systems and accounts;
- social media accounts, physical offices, devices and corporate email infrastructure not publicly exposed as part of the Site;
- denial of service, distributed denial of service, traffic flooding, resource exhaustion or tests that degrade availability;
- social engineering, phishing, pretexting, spam, bribery, threats or physical intrusion;
- credential attacks, password spraying, credential stuffing, brute force, MFA fatigue, OTP interception or attempts to obtain credentials;
- malware, destructive payloads, persistence, pivoting, lateral movement or changing data;
- data exfiltration, downloading bulk records, accessing another person's communications, or testing with real personal data beyond the minimum accidental proof;
- automated scanning that exceeds 2 requests per second, creates accounts at scale or triggers communications or phone calls; and
- reports consisting only of missing headers, scanner output, self-XSS, clickjacking without sensitive action, rate limits without impact, version disclosure, theoretical issues or known vulnerable libraries without a working impact demonstration.
4. Research rules
- Use your own accounts, contact details and test data.
- Use the minimum interaction needed to demonstrate impact. Do not establish persistence or move beyond the initially affected component.
- Do not access, copy, modify, retain or share data that is not yours.
- If you encounter personal data, credentials, secrets, customer content or non-public data, stop immediately, preserve only the minimum evidence, and report it. Do not continue testing that path.
- Do not disrupt service, affect other users, create costs, place calls, send messages, or generate excessive alerts.
- Keep the vulnerability confidential until we confirm remediation or agree on disclosure timing.
- Comply with law and this policy. Delete retained report data when it is no longer needed.
5. How to report
Email xerxes@agenticuniverse.ai with the subject “Security vulnerability report”. Include:
- the affected URL, endpoint and feature;
- clear reproduction steps and prerequisites;
- impact and who could be affected;
- sanitised screenshots, logs or proof of concept;
- your test IP address and testing dates, if you are comfortable sharing them; and
- how you would like to be credited, or whether you prefer anonymity.
Do not send secrets or unnecessary personal data by ordinary email. Ask for a secure transfer method if sensitive evidence is essential. For an active incident or exposed data, put “URGENT” in the subject.
6. What to expect
We aim to acknowledge a complete report within 5 business days, provide an initial assessment within 15 business days, and send progress updates when practical. These are targets, not guarantees. Resolution time depends on severity, complexity, providers and deployment constraints.
We will validate, prioritise and remediate at our discretion. We may ask for clarification or limited retesting. Please do not contact employees individually, submit duplicate reports through multiple channels, or publicly disclose while coordination is active.
7. Coordinated disclosure
Allow us a reasonable period to investigate and fix an accepted issue before publication. A typical starting point is 90 days, but we may agree to a shorter or longer period based on risk and dependencies. Coordinate the content and timing with us, protect affected users, and remove exploit details that would create ongoing harm.
8. Recognition and rewards
This is not a bug bounty program. We do not promise payment, gifts, employment, public credit or any other reward. Any recognition or discretionary reward is decided case by case and must not be assumed before testing.
9. Safe-harbor limits
Safe harbor applies only to good-faith activity on in-scope assets that follows this policy. It does not cover deliberate privacy violations, extortion, unlawful conduct, threats, repeated disruption, third-party targeting, concealment of data access, or activity after we ask you to stop. We cannot authorise research on systems we do not own.
10. Questions
Questions about scope or planned testing should be sent to xerxes@agenticuniverse.ai before testing.
This document is operational guidance, not legal advice. It should be reviewed by qualified counsel for the jurisdictions, products and customer deployments that apply.