Skip to content

Security: QWED-AI/qwed-a2a

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x Yes

Reporting a Vulnerability

QWED A2A is a security-critical component — it intercepts and verifies all inter-agent communication. If you discover a vulnerability, please report it privately.

Email: rahul@qwedai.com

Do NOT open a public GitHub issue for security vulnerabilities.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Any potential mitigations you've identified

Response Timeline

  • Acknowledgment within 24 hours
  • Initial assessment within 72 hours
  • Fix timeline communicated after assessment

Coordinated Disclosure

We follow coordinated disclosure. We will work with you to understand the issue and release a fix before public disclosure. Reporter credit will be given in the release notes.

Security vs. Bug

If you're unsure whether something is a security issue or a regular bug, err on the side of caution and report it via email.

There aren't any published security advisories