Trust

Security at OpenAgent

Verifiable website controls and current security boundaries for sessions, billing, and agent calls.

Last updated:

Website controls

  • Browser policy. Production configuration includes HSTS, CSP, frame, content-type, referrer, and permissions headers.
  • Private routes. Account, login, authorization, internal API, preview, and health routes are excluded from public indexing.
  • Session boundary. The navigation snapshot cannot authenticate a user or replace server validation.

Agent boundaries

A selected Service Agent can receive required task context and may run outside this website. Minimize shared data and review output before use.

Authentication and billing

Configured identity-provider flows handle sign-in. Stripe checkout and verified webhooks support billing; OpenAgent stores identifiers needed for plan and credit fulfillment.

Security reporting

No verified public vulnerability inbox or bug-bounty program is published. Do not post credentials, personal data, or exploit details in public channels.

Shared responsibility

Users, Client Agent operators, and Service Agent providers must protect credentials, minimize data, validate output, and secure their own systems.