Security & disclosure

Quickstart, authentication, streaming, routing and error handling for the AgentsRouter API. OpenAI-compatible: change the base URL and the key.

If you believe you have found a vulnerability in AgentsRouter, we want to hear about it. This page is the disclosure policy that /.well-known/security.txt points to.

How to report

  • Email security@isync.ai. Write in English or French.
  • Encrypt anything sensitive to our OpenPGP key at https://isync.ai/.well-known/pgp-key.asc. Its fingerprint is 4F38 59BD 4156 DC42 CE7D C727 9C20 3178 F95C D43F; check it before you encrypt.
  • Include what you found, the steps or a request that reproduces it, what an attacker could do with it, and how you would like to be credited.

In scope

  • The API at api.isync.ai and isync.ai/v1, including authentication, key handling, routing, metering and billing.
  • The dashboard at isync.ai, including sign-in, invitations, roles and workspaces.
  • Anything that lets one organisation read or change another organisation’s data, keys or spend.

Out of scope

  • Denial of service, load testing or anything that degrades the service for others.
  • Social engineering of our staff or customers, and physical attacks.
  • Vulnerabilities in the model providers themselves; report those to the provider.
  • Findings that need a compromised device, or only affect an out-of-date browser.

Testing rules

  • Use only accounts, keys and organisations you created yourself.
  • If you reach another customer’s data, stop, do not keep or share it, and tell us what you saw.
  • Keep request volume low; every endpoint is rate limited and you will be throttled.
  • Give us a reasonable time to fix an issue before you disclose it publicly.

Safe harbour

Research done in good faith and within these rules is authorised. We will not pursue legal action or ask anyone else to, and if a third party does, we will make it known that you acted with our authorisation.

What happens next

We acknowledge every report, tell you whether we can reproduce it, and keep you updated until it is fixed. We credit reporters who want to be named once the fix is live. We do not run a paid bug bounty.