Agent Vulnerability Disclosure (AVD) Policy
How AlgoVoi reports findings from the Agent Trust Bench.
AlgoVoi is not a security research firm.
The bench is a public-good research instrument operated by a payment-infrastructure
company. AVD reports describe observed failure patterns at a disclosed research
endpoint under its stated challenge conditions — they are not security
advisories with CVE-equivalent authority, and they make no claim that observed
failures are exploitable in production systems.
Publication threshold
An agent stack becomes eligible for an AVD report only when all of the following hold:
- ≥ 50 distinct sessions from an identifiable header-set fingerprint
- Failure rate ≥ 65% on injection / exfil / orchestrator-auth profiles
- Sessions show production-pattern timing (sub-second inter-arrival, not researcher-pace gaps)
Process
- 30-day private notice to the operator (if identifiable via UA, canary correlation, or direct contact) before any public publication.
- If the operator is uncontactable, the report is published with the stack fingerprint anonymised to a generic class (e.g.
Framework Class A / orchestration layer B).
- Findings are numbered
AVD-YYYY-NNN (AlgoVoi-internal, not CVE).
What gets published
- Aggregate failure rates by profile category
- Timing-class distribution (scraper / production-agent / researcher)
- Header-set fingerprint class (anonymised where possible)
- Methodology used to derive findings
What does NOT get published
- Individual session records
- IP addresses (raw or hashed)
- Payment amounts or transaction IDs
- X-PAYMENT signature material
- User-Agent strings beyond truncated 80-char prefixes
Methodology transparency
Every AVD report includes the full methodology in-line: the profile definitions, the
header-set hashing approach, the timing classification thresholds, the salt-rotation
schedule, and the data-retention policy. Findings are reproducible against the bench
landing page and stats endpoint.
Defamation, scope, intent
AlgoVoi commits to:
- Not characterising any failure as a production-system vulnerability without independent verification by the operator.
- Not publishing reports targeted at specific named products without 30-day private notice and right-of-reply.
- Withdrawing or revising any report on credible methodology challenge.
Contact
Operator contact for private notice or methodology challenge: [email protected]