Skip to content
Agentic Universe
AboutExperience CentreCustomer StoriesBlogsContact usBook a demo
Security

Vulnerability Disclosure Policy

A clear path for good-faith researchers to report security issues affecting public systems owned by Agentic Universe.

Effective 5 October 2026Last updated 5 October 2026
On this page
1. Purpose and safe harbor2. In scope3. Out of scope4. Research rules5. How to report6. What to expect7. Coordinated disclosure8. Recognition and rewards9. Safe-harbor limits10. Questions

1. Purpose and safe harbor

We welcome good-faith security research that helps protect Agentic Universe and its users. If you comply with this policy, we will treat your research as authorised for purposes of applicable computer misuse laws, will not initiate legal action against you for accidental, good-faith violations, and will work with you to understand and resolve the issue.

This safe harbor does not bind third parties or excuse violations of law. If a third party brings action and you complied with this policy, we will make reasonable efforts to clarify that your activity was conducted under our policy. If you are unsure whether a test is allowed, ask before proceeding.

2. In scope

Only publicly accessible systems and assets that are owned and operated by Qultured Media Private Limited for Agentic Universe are in scope, specifically:

  • agenticuniverse.ai and its public subdomains;
  • public web pages and APIs served under those domains; and
  • authentication and demo flows directly controlled by us.

An asset is not in scope merely because it uses our name or integrates with us. If ownership is unclear, stop and ask.

3. Out of scope

  • third-party systems and services, including Vercel, Google, Microsoft, Telegram, Twilio, Exotel, Ozonetel, WhatsApp and other voice, telephony, AI or infrastructure providers;
  • customer, partner, employee or vendor systems and accounts;
  • social media accounts, physical offices, devices and corporate email infrastructure not publicly exposed as part of the Site;
  • denial of service, distributed denial of service, traffic flooding, resource exhaustion or tests that degrade availability;
  • social engineering, phishing, pretexting, spam, bribery, threats or physical intrusion;
  • credential attacks, password spraying, credential stuffing, brute force, MFA fatigue, OTP interception or attempts to obtain credentials;
  • malware, destructive payloads, persistence, pivoting, lateral movement or changing data;
  • data exfiltration, downloading bulk records, accessing another person's communications, or testing with real personal data beyond the minimum accidental proof;
  • automated scanning that exceeds 2 requests per second, creates accounts at scale or triggers communications or phone calls; and
  • reports consisting only of missing headers, scanner output, self-XSS, clickjacking without sensitive action, rate limits without impact, version disclosure, theoretical issues or known vulnerable libraries without a working impact demonstration.

4. Research rules

  1. Use your own accounts, contact details and test data.
  2. Use the minimum interaction needed to demonstrate impact. Do not establish persistence or move beyond the initially affected component.
  3. Do not access, copy, modify, retain or share data that is not yours.
  4. If you encounter personal data, credentials, secrets, customer content or non-public data, stop immediately, preserve only the minimum evidence, and report it. Do not continue testing that path.
  5. Do not disrupt service, affect other users, create costs, place calls, send messages, or generate excessive alerts.
  6. Keep the vulnerability confidential until we confirm remediation or agree on disclosure timing.
  7. Comply with law and this policy. Delete retained report data when it is no longer needed.

5. How to report

Email xerxes@agenticuniverse.ai with the subject “Security vulnerability report”. Include:

  • the affected URL, endpoint and feature;
  • clear reproduction steps and prerequisites;
  • impact and who could be affected;
  • sanitised screenshots, logs or proof of concept;
  • your test IP address and testing dates, if you are comfortable sharing them; and
  • how you would like to be credited, or whether you prefer anonymity.

Do not send secrets or unnecessary personal data by ordinary email. Ask for a secure transfer method if sensitive evidence is essential. For an active incident or exposed data, put “URGENT” in the subject.

6. What to expect

We aim to acknowledge a complete report within 5 business days, provide an initial assessment within 15 business days, and send progress updates when practical. These are targets, not guarantees. Resolution time depends on severity, complexity, providers and deployment constraints.

We will validate, prioritise and remediate at our discretion. We may ask for clarification or limited retesting. Please do not contact employees individually, submit duplicate reports through multiple channels, or publicly disclose while coordination is active.

7. Coordinated disclosure

Allow us a reasonable period to investigate and fix an accepted issue before publication. A typical starting point is 90 days, but we may agree to a shorter or longer period based on risk and dependencies. Coordinate the content and timing with us, protect affected users, and remove exploit details that would create ongoing harm.

8. Recognition and rewards

This is not a bug bounty program. We do not promise payment, gifts, employment, public credit or any other reward. Any recognition or discretionary reward is decided case by case and must not be assumed before testing.

9. Safe-harbor limits

Safe harbor applies only to good-faith activity on in-scope assets that follows this policy. It does not cover deliberate privacy violations, extortion, unlawful conduct, threats, repeated disruption, third-party targeting, concealment of data access, or activity after we ask you to stop. We cannot authorise research on systems we do not own.

10. Questions

Questions about scope or planned testing should be sent to xerxes@agenticuniverse.ai before testing.

Counsel review notice

This document is operational guidance, not legal advice. It should be reviewed by qualified counsel for the jurisdictions, products and customer deployments that apply.

Agentic Universe
TermsPrivacyCookiesVulnerability disclosure
Operator
Qultured Media Private Limited
trading as Agentic Universe
Legal and privacy contact
xerxes@agenticuniverse.ai
© 2026 Agentic Universe. Legal documents effective 5 October 2026.

Cookie settings

Choose whether this browser may use optional analytics technologies on pages that honor this setting. Essential storage remains available for security, access and your preferences.

EssentialRequired for access sessions, security and remembering this choice.

See the Cookie Policy. Some existing site integrations may require a reload or additional consent controls to apply a changed preference.