Back to homeCorporate

Responsible Disclosure

Effective: 1 May 2026 | Last Updated: 30 April 2026

1. Purpose & Scope

Attribute Global Ventures Pte. Ltd. takes the security of its digital infrastructure, data systems, and investor-facing platforms seriously. This Responsible Disclosure Policy establishes a structured, good-faith process for security researchers, third parties, and members of the public to report potential security vulnerabilities they discover in AGV's systems. This policy applies to all internet-accessible systems, web applications, APIs, and digital services owned and operated by AGV, including the AGV corporate website and the AGV Investor Portal.

2. Our Commitment

When you engage with AGV under this policy in good faith, AGV commits to: Acknowledging your report within three (3) business days of receipt; Conducting a thorough and timely investigation of all credible reports; Providing you with updates on the status of your report at reasonable intervals; Notifying you when the reported vulnerability has been remediated; Not pursuing legal action against researchers acting in good faith within this policy's scope; Treating your personal information confidentially and using it only to respond to your report

3. Scope of Eligible Vulnerabilities

3.1 In Scope AGV welcomes reports of the following vulnerability types: Authentication and authorization flaws (e.g., broken access control, privilege escalation); Injection vulnerabilities (SQL, command, LDAP, etc.); Cross-site scripting (XSS) and cross-site request forgery (CSRF); Sensitive data exposure or unintended data leakage; erver-side request forgery (SSRF) and remote code execution; Insecure direct object references or misconfigured access permissions Security misconfigurations on AGV-operated infrastructure; 3.2 Out of Scope The following are explicitly excluded from this policy: Denial-of-service (DoS/DDoS) attacks or volumetric testing; Social engineering, phishing, or physical security attacks against AGV personnel; Vulnerabilities in third-party software or services not controlled by AGV; Reports generated by automated scanning tools without manual validation; Reports that include accessing, exfiltrating, or modifying actual investor data

4. How to Report

Submit your report securely and in writing to legal@attributegv.com with the subject line "Security Disclosure." Your report should include: A clear description of the vulnerability and the affected system or URL; Step-by-step reproduction instructions, including any tools or scripts used; Screenshots, HTTP request/response captures, or proof-of-concept code where applicable; Your assessment of the potential impact and severity; Your contact details for follow-up correspondence

5. Researcher Responsibilities

To qualify for good-faith protection under this policy, you must: Make every effort to avoid accessing, copying, modifying, or destroying investor or proprietary data; Not disclose the vulnerability to any third party before AGV has confirmed remediation; Cease testing upon discovery of a vulnerability and report immediately; Not use the vulnerability to conduct unauthorised transactions or take advantage of data; Operate within Singapore law and applicable international legal standards at all times

6. No Bug Bounty

AGV does not currently operate a monetary bug bounty programme. AGV reserves the right to introduce such a programme in the future. Researchers who submit valid, in-scope reports may be acknowledged on the AGV Security Hall of Fame at AGV's sole discretion.