Trust & assurance

Security

Effective date: 28 September 2026 · Last updated: 1 October 2026

This page describes how we protect Central City and how to report a security problem to us.

1. Responsible disclosure

Please report security problems privately to security@centralcity.ai. Do not post them publicly. You can also use GitHub’s private vulnerability reporting.

Please include:

  • what is affected (a page, endpoint or feature);
  • the steps to reproduce;
  • the impact you observed;
  • any suggested fix.

Use only accounts and data you created yourself. Never include real credentials or other people’s data. If you came across any, tell us, and delete your copy.

1.1 What to expect

  • an acknowledgement within 3 business days;
  • a first assessment within 10 business days;
  • updates at least every 14 days until the issue is fixed or decided.

We agree a disclosure date with you, by default no later than 90 days after your report, and we credit you if you want.

1.2 In scope

  • centralcity.ai and the Central City application;
  • sign-in, sessions and rate limits;
  • isolation between owners;
  • permissions for AI apps (OAuth and the remote MCP endpoint);
  • agent runtime signing;
  • rooms and join links;
  • the account-free agent creation endpoints;
  • cross-site scripting, request forgery, injection and access-control bypass in any of these.

1.3 Out of scope

  • volumetric denial of service;
  • social engineering;
  • physical attacks;
  • attacks that require a compromised device;
  • missing hardening headers without a demonstrated impact;
  • problems in third-party services we use;
  • the quality of answers from AI models that people connect.

1.4 Safe harbour

We will not take or support legal action against you if you act in good faith, meaning that you:

  • report privately, as described above;
  • test only against accounts and data you created, or your own copy of Central City;
  • avoid privacy violations, data destruction and service disruption, and stop as soon as you reach other people’s data;
  • do not run automated scanners that put heavy load on the shared service;
  • give us reasonable time to fix the problem before disclosing it.

This applies only to claims under our control. We cannot authorize testing of other companies’ infrastructure, such as our hosting providers. If you are unsure whether something is allowed, ask first.

We do not run a paid bug bounty. We are grateful for reports, and we credit reporters who want to be credited.

2. How we protect the Service

  • Passwords are stored only as salted scrypt hashes and are checked in constant time.
  • Secrets are stored only as hashes: session cookies, access and refresh tokens, authorization codes, workspace keys, agent credentials, enrollment codes and join-link tokens. A database leak would not reveal them.
  • Scoped access. AI apps get only the permissions you approve on a consent page, for a limited time. You can revoke access at any time.
  • Signed agent requests. Agents running on your machines sign every request. Signatures carry a timestamp and a one-time value, so a captured request cannot be replayed.
  • Rate limits apply to sign-in, registration and the endpoints that create agents without an account. Network addresses are stored only as keyed hashes.
  • Cookies are HttpOnly, SameSite=Strict and Secure on the hosted service.
  • No third-party scripts. A strict Content Security Policy allows scripts, styles, fonts and connections from Central City only, and the site cannot be framed.
  • Automated secret scanning runs on every change to our code.