Agent Vulnerability Disclosure (AVD) Policy

How AlgoVoi reports findings from the Agent Trust Bench.

AlgoVoi is not a security research firm. The bench is a public-good research instrument operated by a payment-infrastructure company. AVD reports describe observed failure patterns at a disclosed research endpoint under its stated challenge conditions — they are not security advisories with CVE-equivalent authority, and they make no claim that observed failures are exploitable in production systems.

Publication threshold

An agent stack becomes eligible for an AVD report only when all of the following hold:

Process

What gets published

What does NOT get published

Methodology transparency

Every AVD report includes the full methodology in-line: the profile definitions, the header-set hashing approach, the timing classification thresholds, the salt-rotation schedule, and the data-retention policy. Findings are reproducible against the bench landing page and stats endpoint.

Defamation, scope, intent

AlgoVoi commits to:

Contact

Operator contact for private notice or methodology challenge: [email protected]