| Version | Supported |
|---|---|
| 0.x | Yes |
QWED A2A is a security-critical component — it intercepts and verifies all inter-agent communication. If you discover a vulnerability, please report it privately.
Email: rahul@qwedai.com
Do NOT open a public GitHub issue for security vulnerabilities.
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Any potential mitigations you've identified
- Acknowledgment within 24 hours
- Initial assessment within 72 hours
- Fix timeline communicated after assessment
We follow coordinated disclosure. We will work with you to understand the issue and release a fix before public disclosure. Reporter credit will be given in the release notes.
If you're unsure whether something is a security issue or a regular bug, err on the side of caution and report it via email.