generated: '2026-09-19' method: searched probe: true source: https://whisper.online/.well-known/security.txt docs: - https://whisper.online/.well-known/security.txt - https://whisper.online/.well-known/disclosure-policy.txt - https://whisper.online/.well-known/security-acknowledgments.txt - https://whisper.online/.well-known/openpgp-key.txt - https://whisper.online/trust policy: - https://whisper.online/.well-known/disclosure-policy.txt - https://as219419.net/.well-known/disclosure-policy.txt contact: - mailto:security@whisper.security - https://www.whisper.security/contact-us encryption: https://whisper.online/.well-known/openpgp-key.txt (fingerprint EFF1 663D 9925 3968 2106 A5EA D0F7 0908 CF3B 7929) acknowledgments: https://whisper.online/.well-known/security-acknowledgments.txt ("(none yet, so be the first)") program: type: coordinated vulnerability disclosure (no bug bounty platform) policy_title: Coordinated Vulnerability Disclosure Policy — Whisper Security · viaGraph b.v. · the Whisper platform last_updated: '2026-09-17' scope_in: [whisper.online and its subdomains and the agent-facing discovery documents, the control plane and graph API, the identity plane as infrastructure (allocation, registration, resolution, RDAP, certificate and DNSSEC machinery), the CLI, SDKs and MCP server and their release and signing path, the endpoint sensor and enrollment, the console and its authentication] scope_out: [individual agent /128 hosts in 2a04:2a01::/32 and their traffic, customer tenants and data, third parties and egress destinations, DoS/volumetric testing, social engineering and physical attacks, findings with no security impact] safe_harbour: 'If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research.' acknowledgement: best-effort during RIPE-region business hours ("We are not a 24x7 NOC"); abuse reports acknowledged within one business day (trust page) disclosure_timeline: typically up to 90 days, sooner for low-risk issues, longer by mutual agreement credit: with consent, via the Acknowledgments file other_contacts: {abuse: security@whisper.security (RIPE abuse-c), peering: peering@whisper.security, noc: noc@whisper.security} separate_files: - {host: whisper.online, canonical: 'https://whisper.online/.well-known/security.txt', expires: '2027-09-17', signed: PGP} - {host: www.whisper.security, canonical: 'https://www.whisper.security/.well-known/security.txt', expires: '2027-09-18', signed: PGP, note: corporate site; points at the platform policy} - {host: as219419.net, canonical: 'https://as219419.net/.well-known/security.txt', expires: '2027-06-19', signed: PGP, note: the network layer has its own policy and key} - {host: mcp.whisper.security, canonical: 'https://mcp.whisper.security/.well-known/security.txt', expires: '2027-03-03', signed: false, note: 'Policy field points at the corporate privacy policy rather than the CVD policy'} evidence: - source: https://whisper.online/.well-known/security.txt kind: security.txt (live probe) http_status: 200 fetched: '2026-09-19' - source: https://whisper.online/.well-known/disclosure-policy.txt kind: CVD policy (live probe) http_status: 200 fetched: '2026-09-19' - source: https://whisper.online/.well-known/security-acknowledgments.txt http_status: 200 fetched: '2026-09-19' - source: https://whisper.online/.well-known/openpgp-key.txt http_status: 200 fetched: '2026-09-19'