generated: '2026-08-30' method: searched source: https://github.com/agentgateway/agentgateway/blob/main/SECURITY.md provider: AgentGateway providerId: agentgateway description: >- Agentgateway publishes a coordinated vulnerability disclosure policy in SECURITY.md. It is a real policy document, not a boilerplate stub: alongside the reporting channel it sets out how the project decides what counts as a vulnerability versus a bug, with worked classification examples on both sides. probe-security-programs.py found no security.txt and no bug-bounty program, which is accurate - the channel is GitHub private vulnerability reporting. disclosure: published: true policy_url: https://github.com/agentgateway/agentgateway/blob/main/SECURITY.md policy_status: 200 report_url: https://github.com/agentgateway/agentgateway/security/advisories/new channel: github-private-vulnerability-reporting email: null pgp_key: null security_txt: false security_txt_probe: url: https://agentgateway.dev/.well-known/security.txt status: 404 bug_bounty: false bug_bounty_note: No HackerOne, Bugcrowd or Intigriti program was found for agentgateway or the agentgateway GitHub organization. public_disclosure: GitHub Security Advisories on the agentgateway/agentgateway repository triage: Reports are reviewed privately by the agentgateway security team; maintainers determine classification. sla: null sla_note: The policy states no acknowledgement or remediation time commitment. Recorded as absent rather than assumed. policy_principles: - A vulnerability is something users reasonably need to be urgently informed about; hypothetical, highly contrived edge cases are bugs. - A vulnerability defeats a promised security boundary without the attacker already possessing equivalent authority. - User-written policy (including CEL) is the user's responsibility, but agentgateway remains responsible for enforcing who may create or modify policy. - External policy components (ext-auth, ext-proc, external rate limiting) are trusted; a malicious one is generally not an agentgateway vulnerability. - Administrative interfaces are privileged and are not designed as an untrusted security boundary - exposing them publicly is a deployment error. - Poor or ambiguous documentation is not itself a vulnerability; it may be fixed with a release-notes callout instead of a CVE. - Maintainer discretion applies, explicitly balancing real risk against CVE and scanner signal-to-noise. classified_as_vulnerability: - A request that reliably crashes the gateway. - A remotely supplied request causing resource consumption disproportionate to attacker effort under realistic deployment conditions. - Unauthorized cross-namespace Kubernetes writes that violate an intended authorization boundary. - A tenant or operator persona accessing or modifying another tenant's resources without the required authority. classified_as_bug_or_user_error: - A dangerous but documented default or behavior. - A user's CEL expression producing unintended behavior. - An administrator-supplied configuration that crashes the control plane. - A trusted ext-auth, ext-proc or external rate-limiting component acting maliciously. - A user explicitly configuring an administrative interface to listen on a publicly reachable address. - LLM guardrails not applying the way a user intended. related: code_of_conduct: https://github.com/agentgateway/agentgateway/blob/main/CODE_OF_CONDUCT.md charter: https://github.com/agentgateway/agentgateway/blob/main/CHARTER.md governance_note: >- agentgateway is "a Series of LF Projects, LLC" - contributed to the Linux Foundation by Solo.io in August 2025 and now an Agentic AI Foundation project. Project policies, trademark and website terms of use sit at https://lfprojects.org. trust_center: published: false note: >- No trust center and no named certification (SOC 2, ISO 27001, PCI, HIPAA, FedRAMP) is published for agentgateway. Expected for an Apache-2.0 project you deploy yourself - the certification boundary belongs to the deployer or to a commercial distributor. No security/agentgateway-trust-center.yml is written and no Compliance pointer is emitted. maintainers: - FN: Kin Lane email: kin@apievangelist.com