Three things make a report useful.
Say what you found and where
For Alchemy, give the version you are running. For this website, give the page address. Describe what an attacker would need, such as a signed-in account, network access to the control center, a crafted manifest or a hostile tool server.
Show us how to reproduce it
Steps, a minimal manifest or input, and what you observed. Leave out real credentials and anyone's personal data.
Tell us the impact
What an attacker could read, change, spend or run, and how confident you are. Partial findings are welcome.
Test your own installation. Nobody else's.
Test Alchemy only on an installation you run yourself. Please do not test against anyone else's deployment, and do not access, change or keep other people's data.
For this website, ordinary requests are fine. Please do not run load, denial-of-service or high-volume automated tests.
Give us a reasonable opportunity to resolve the issue before you publish details. We will agree the timing with you.
We will respond, and keep you informed.
We will acknowledge your report and confirm whether we can reproduce it.
We will keep you informed while we investigate and resolve it, and tell you when the fix is released.
If you would like to be credited when the fix is described, tell us the name to use.
What this policy covers.
Alchemy
The runtime and control center as supplied to you under an evaluation agreement, a design partnership agreement or a licence.
This website
agiliti.ai and the files it serves.
Other providers' software and services
Claude Code, the Claude Agent SDK, tool servers, Hostinger, Google Fonts and jsDelivr are maintained by their owners. Report issues in them to those owners, and tell us too if one affects Alchemy's approvals, ceilings or run record.
Alchemy's security model is on Trust.
Trust covers sign-in and roles, encryption at rest, the hash-chained run record, and what leaves your infrastructure.
Found something? Tell us first.
contact@agiliti.ai, subject "Security disclosure".
