Last updated: August 5, 2026
Agent21 takes the security of our platform and our customers' data seriously. We welcome reports from security researchers and will work with you to understand and resolve issues quickly. This page describes how to report a vulnerability, what's in scope, and the protections we extend to good-faith researchers.
Email security@agent21.ai with a description of the issue, the steps to reproduce, affected URLs/endpoints, and any proof-of-concept. Please give us a reasonable time to remediate before public disclosure. Machine-readable contact: /.well-known/security.txt.
If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorized, will not initiate legal action against you, and will work with you to understand and resolve the issue quickly. This authorization does not extend to actions that harm Agent21, our customers, or third parties (e.g., data destruction, service disruption, or accessing more data than necessary to demonstrate the issue).
agent21.ai and its subdomains, and the Agent21 web application./api/v1/*) and the Agent21 Slack app.Agent21 runs a private, invitation-based bug bounty. For valid, in-scope reports we offer recognition (with your permission, a place in our security researcher acknowledgements) and, at our discretion, monetary rewards scaled to the severity and impact of the finding. Reward eligibility and amounts are determined solely by Agent21. To keep the program fair: the first researcher to report a previously unknown, reproducible issue is eligible, and duplicates or already-known issues are not.