Security

Found a vulnerability? Tell us first.

Email contact@agiliti.ai with the subject "Security disclosure". We will acknowledge your report and keep you informed until it is resolved.

This page is for reporting a security issue. For how Alchemy is governed and secured, read Trust.

contact@agiliti.aiSubject: Security disclosureCoordinated disclosure
01 / How to report

Three things make a report useful.

01

Say what you found and where

For Alchemy, give the version you are running. For this website, give the page address. Describe what an attacker would need, such as a signed-in account, network access to the control center, a crafted manifest or a hostile tool server.

02

Show us how to reproduce it

Steps, a minimal manifest or input, and what you observed. Leave out real credentials and anyone's personal data.

03

Tell us the impact

What an attacker could read, change, spend or run, and how confident you are. Partial findings are welcome.

02 / Testing guidelines

Test your own installation. Nobody else's.

Test Alchemy only on an installation you run yourself. Please do not test against anyone else's deployment, and do not access, change or keep other people's data.

For this website, ordinary requests are fine. Please do not run load, denial-of-service or high-volume automated tests.

Give us a reasonable opportunity to resolve the issue before you publish details. We will agree the timing with you.

03 / What we will do

We will respond, and keep you informed.

We will acknowledge your report and confirm whether we can reproduce it.

We will keep you informed while we investigate and resolve it, and tell you when the fix is released.

If you would like to be credited when the fix is described, tell us the name to use.

04 / Scope

What this policy covers.

In scope

Alchemy

The runtime and control center as supplied to you under an evaluation agreement, a design partnership agreement or a licence.

In scope

This website

agiliti.ai and the files it serves.

Third parties

Other providers' software and services

Claude Code, the Claude Agent SDK, tool servers, Hostinger, Google Fonts and jsDelivr are maintained by their owners. Report issues in them to those owners, and tell us too if one affects Alchemy's approvals, ceilings or run record.

05 / Where to read more

Alchemy's security model is on Trust.

Trust covers sign-in and roles, encryption at rest, the hash-chained run record, and what leaves your infrastructure.

Found something? Tell us first.

contact@agiliti.ai, subject "Security disclosure".