Responsible disclosure

AgentRail Security

AgentRail stores trace metadata and evidence status for agentic workflows. The current public demo is synthetic; self-hosted operators control their own database, object storage, and network exposure.

Report a vulnerability

Configure NEXT_PUBLIC_AGENTRAIL_CONTACT_URL before accepting private reports through this site.

Security policy

The repository security policy is the source of truth for supported versions and disclosure handling.

View SECURITY.md

Current controls

Raw API keys are not stored in PostgreSQL, unknown model pricing is explicit, and browser evidence access goes through backend routes. Hosted authentication, organization controls, and external audit reports are future work.