Responsible Disclosure Policy
Comprehensive vulnerability reporting policy, safe harbor guidelines, and technical security research scope for Legalpunkt aOS, Datapunkt aOS, and the Agentpunkt Marketplace.
Good-Faith Security Research & Safe Harbor Commitment
Agentpunkt Marketplace ("Agentpunkt", "we", "us", or "our") deeply values the contributions of security researchers and ethical hackers who help safeguard our platform ecosystem. If you conduct security research in compliance with the rules set forth in this policy, we consider your activities authorized and will NOT initiate legal action or law enforcement referrals against you.
This Responsible Disclosure Policy ("Vulnerability Policy") outlines the technical scope, safe harbor standards, vulnerability reporting procedures, and disclosure coordination protocols for identifying security vulnerabilities across our websites, application runtimes, specialized AI operating platforms—including Legalpunkt aOS and Datapunkt aOS—and the Agentpunkt Marketplace.
1. Technical Scope of In-Scope Target Infrastructure
Researchers are authorized to test internet-facing web applications, API gateways, and specialized operating environments owned and operated by Agentpunkt:
Legalpunkt aOS Infrastructure Scope
Legal Search endpoints, Legal Projects workspace APIs, Legal Contracts redlining engine, Legal Vault encryption mechanisms, Legal Skills execution runtime, Legal Playbook execution engines, and Legal Billing accounting APIs.
Datapunkt aOS Infrastructure Scope
Datapunkt Metadata services, automated code generation sandboxes, data lineage tracking APIs, schema mapping engines, and synthetic dataset generation pipelines.
Agentpunkt Marketplace Infrastructure Scope
Marketplace web storefront, merchant seller dashboard, agent listing APIs, OAuth 2.0 authentication endpoints, Stripe payment processing integrations, and agent chat widget embeds.
2. Authorized Vulnerability Testing Categories
We are particularly interested in receiving reports regarding high-impact AI, infrastructure, and application vulnerabilities:
- Indirect Prompt Injection & Legal Document Exfiltration: Vulnerabilities allowing malicious prompts embedded within uploaded legal contracts or briefs to manipulate model execution or exfiltrate cross-vault legal data.
- Automated Code Sandbox Escapes: Flaws in Datapunkt aOS code execution environments permitting arbitrary code execution on host containers.
- Cross-Tenant Vault Authorization Bypasses: Broken Object Level Authorization (BOLA/IDOR) vulnerabilities allowing access to third-party Legalpunkt aOS project files or database metadata.
- Synthetic Data Side-Channel Exfiltration: Vulnerabilities permitting reconstruction of underlying training distributions or seed parameters from synthetic dataset outputs.
- Authentication & Privilege Escalation: OAuth flow misconfigurations, JWT forgery, or session hijacking vulnerabilities.
3. Out-of-Scope Activities & Mandatory Ground Rules
To maintain safe harbor protection, researchers must adhere to strict ethical parameters:
- NEVER Access Real Client Legal Files: Do NOT view, modify, download, or exfiltrate actual client legal documents, contracts, attorney work product, or production database schemas belonging to real users. Use designated test accounts only.
- NO Denial of Service (DoS/DDoS): Do NOT perform high-volume automated rate-limit testing, network degradation attacks, or resource exhaustion exploits.
- NO Social Engineering or Physical Attacks: Phishing, spear-phishing, credential harvesting, or physical security testing against Agentpunkt personnel or data centers is strictly prohibited.
4. Vulnerability Submission Protocol & SLA Response Times
Please submit detailed vulnerability reports, including proof-of-concept (PoC) scripts and step-by-step reproduction instructions, to our Security Operations Center:
Agentpunkt Security Operations Center (SOC)
Official Security Email: info@agentpunkt.com
• First Response Acknowledgement: Within 24 business hours.
• Triage & Severity Assessment: Within 3 business days.
• Remediation Progress Updates: Weekly until resolution.