Responsible disclosure
AgentRail Security
AgentRail stores trace metadata and evidence status for agentic workflows. The current public demo is synthetic; self-hosted operators control their own database, object storage, and network exposure.
Report a vulnerability
Configure NEXT_PUBLIC_AGENTRAIL_CONTACT_URL before accepting private reports through this site.
Security policy
The repository security policy is the source of truth for supported versions and disclosure handling.
View SECURITY.mdCurrent controls
Raw API keys are not stored in PostgreSQL, unknown model pricing is explicit, and browser evidence access goes through backend routes. Hosted authentication, organization controls, and external audit reports are future work.