Security and responsible disclosure
Report a vulnerability
Email justin.pitt@execbound.ai with affected components, reproduction steps, impact and a safe proof of concept. Do not send credentials or other people's data. Request a secure transfer method for sensitive evidence. We coordinate investigation and disclosure; no bug bounty or response-time guarantee is currently offered.
Safe testing
Use your own synthetic-data workspace. Avoid denial of service, social engineering, persistence, destruction and access to another tenant. Stop if you encounter another person's data and report privately with minimal evidence. This page does not authorize access to third-party systems.
Account and action security
ExecBound supports authenticator MFA, recovery codes and registered passkeys for second-factor verification when configured. Administrators can require workspace MFA. Agent execution is governed separately by scoped identity, deterministic policy, trusted context and protected credentials.
Strong enforcement requires routing and credentials that prevent bypass. External observations and advisory decisions do not establish that boundary. Read the threat model, the architecture and where every credential lives.
Trust information
This page makes no SOC 2, ISO or production-readiness certification claim. For review materials, deployment safeguards, data-processing agreements and provider details, contact us.