What AI agents you can text publish about their own security
Of 76 agents you can text, 11 publish a security document, 5 name prompt injection, 2 state a bounty. Read on one day, every page.
Of the 76 agents in this directory, 11 publish a document about their own security. 14 publish somewhere to report a hole. 5 name prompt injection, the attack that is specific to what these products are, on any page a person can read. 2 say they pay for a report. 12 say when the agent stops to ask you first. Every one of these is a count of a published sentence, read on one day across all 76, and recorded on the listing it belongs to with the date.
Every product here reads your messages. 27 say what they are given when you connect an account, which is its own piece. This one is about the rest: what a company chooses to tell you about how it protects what it holds, and how it stops the thing it built from being turned against you.
Five questions, and how many answer each
The questions are the ones a person would ask before handing over an inbox, and each is answered by a page or not.
A security document. 11 of 76 publish one: a page headed security, a trust centre, or a section of the documentation. Three of them, Lindy, Catch and Ollie, state SOC 2 Type II with an auditor named or a trust centre listing it; Lindy and Ollie add HIPAA-mapped controls and penetration testing. Town publishes a security annex, dated June 2026, as the schedule to its data processing addendum. alfred_, Allora and Flip publish a page of practices: encryption at rest, isolated containers, no password ever seen, read-only bank access. The other 65 publish nothing beyond the word "encrypt" in a privacy policy, which is a word, not a control.
A route in. 14 publish a security contact: an RFC 9116 security.txt, a disclosure page, or an address. That number was found by a script that refuses a page behind a login, and it is the one count on this page that the site has kept since the day Meta shipped Muse with a threat model and a bounty and none of the criteria here could see either.
Prompt injection, named. 5 products say the words on a page of their own. Instinct's privacy policy warns of "interactions with third parties who may include misleading instructions intended to influence autonomous agents", which is the attack described without the term. Muse's write-up names it and pays for it. Zo's disclosure page welcomes reports of it and says they are not typically eligible for a reward, because of "the inherent nature of LLMs".
OpenClaw's security page says the opposite thing in the same spirit: prompt injection "without a policy, auth, approval, sandbox, or tool-boundary bypass" is not a vulnerability by itself. Vellum's documentation makes the strongest claim of the five: its permission checks run in a separate deterministic process outside the model, so "there's no way to prompt-inject past a permission boundary". Two products that name the attack say it cannot be fully fixed; one says it has been fenced.
A bounty. 2. Muse, up to $300,000 through Meta's programme with up to $130,000 for a prompt injection affecting one user. Zo, a programme with scope and rules of engagement. OpenClaw states there is no paid programme, and then publishes what a paid programme usually hides: 1,799 reports filed since January 2026, 722 fixed and published, 39 with a CVE, 14 confirmed critical and all fixed, updated on the day this was read. It is the only ledger of its kind on any listing here and it belongs to the one open-source project in the set.
Asking first. 12 say when the agent stops. Muse: emails and purchases, approved before they happen, and a card naming the hostname and port before a new network protocol is used. Vellum: every tool carries a risk level, and a setting from Strict to Full access decides which ones prompt. Flip: nothing changes an account, contacts a person or moves money without explicit confirmation. alfred_: drafts go out only when approved. Three arrived on 12 September with the answer on their front pages: Airtap, where an action is approved with a tap in the thread and a saved routine then runs without you; Air by WZRD, where publishing and spending wait in the thread and the wallet never moves funds without approval; and Wis.ai, which asks before it ever spends your money. Two more the same weekend: asaply, where every order shows the total and waits for a tap, and Brea, where booking, buying or sending waits for a yes and a kill switch stops the agent.
Catch, Lindy and OpenClaw say approvals exist without saying for what. The other 64 say nothing, and one of them, Instinct, is the product whose defining choice is acting first.
What the documents do not say
The most detailed document in the set is Muse's, and the sharpest question anyone has put to it is about the hop it does not cover: whether the model that reads your messages runs inside the isolated machine the document describes, or outside it. The write-up describes the machine, the guard on everything leaving it, and the bounty; it does not say where inference happens.
A user put it this way: an elaborate lock on the bedroom, and the diary mailed out every 300 milliseconds. Meta could answer in a sentence and has not.
The SOC 2 claims are recorded here as the vendors state them. Nothing on this site has seen a report, and a SOC 2 Type II says an auditor checked that the controls a company described were operating; it does not say what the controls were. Lindy and Catch offer the reports on request, which is the normal arrangement and the right one to take up before connecting an inbox.
And the count at the top is a count of what companies choose to publish. A product with no security page may run one of the tighter architectures here and never have written it down; a product with a trust centre may be listing certifications its messaging path does not sit inside. What this page can say is that 65 of 76 give a person nothing to read, and that a person who wants to know is left to ask.
What to watch
The first is whether the count of security documents moves. 11 is a fact about publishing, it costs a page, and the products with the most to lose from a breach are among the ones with nothing published.
The second is whether a sixth product names prompt injection. Five have, in five different registers, from "cannot be fully fixed" to "fenced". The next one to say the words will have to pick a register, and the range is the finding.
The third is whether a third product states a paid bounty. Two do, and one of the two, in the same breath, says the attack most specific to this category does not usually qualify. A bounty that pays for prompt injection is a company saying it can be found and fixed; there is one of those here, and it is the largest company in the directory.