# Security policy

## Supported versions

Security fixes are provided for the current Marketplace pre-release or stable
version and, when rollback requires it, the immediately preceding version.

## Reporting a vulnerability

Send a concise report to `charles@one-agent.ai` with the subject
`OneAgent security report`. Do not include live credentials, customer data, or
unredacted source archives. Include affected versions, impact, reproduction
steps using synthetic data, and a safe contact method.

OneAgent will acknowledge P0 reports within four hours and other credible
reports within one business day. Please allow time to investigate and prepare
a signed release before public disclosure.

## Product security boundary

- Production requires the release-manifest-pinned OneAgent Host. The invited
  Ampacs `0.5.x` Marketplace pre-release accepts only its exact version- and
  SHA-256-pinned unsigned Host and discloses the missing Windows publisher
  identity. All other production channels, including `0.6.0` stable, require an
  allowlisted Authenticode signer. Arbitrary unsigned fallback remains
  development-only and is not packaged in the VSIX.
- OneAgent Identity uses OAuth Authorization Code with PKCE, rotating refresh
  sessions, RS256 access tokens, and JWKS verification.
- Tenant Profiles and Agent Bundles are signed and verified locally before the
  Host starts the agent runtime.
- Gateway credentials are resolved server-side and are not stored in the VSIX,
  Agent Home, thread, settings, or logs.
- Service audit is metadata-only and tenant-bound.
