Trust
Security at OpenAgent
Verifiable website controls and current security boundaries for sessions, billing, and agent calls.
Last updated:
Website controls
- Browser policy. Production configuration includes HSTS, CSP, frame, content-type, referrer, and permissions headers.
- Private routes. Account, login, authorization, internal API, preview, and health routes are excluded from public indexing.
- Session boundary. The navigation snapshot cannot authenticate a user or replace server validation.
Agent boundaries
A selected Service Agent can receive required task context and may run outside this website. Minimize shared data and review output before use.
Authentication and billing
Configured identity-provider flows handle sign-in. Stripe checkout and verified webhooks support billing; OpenAgent stores identifiers needed for plan and credit fulfillment.
Security reporting
No verified public vulnerability inbox or bug-bounty program is published. Do not post credentials, personal data, or exploit details in public channels.