OpenOffer Security
Layered security for human-controlled agentic business.
OpenOffer Properties is built around least privilege, fail-closed behavior, server-side authorization, bounded requests, rate limiting, replay protection, environment isolation, auditable agent access, and verified recovery controls. No internet service is breach-proof; the goal is to reduce attack surface, contain failures, and make sensitive actions require explicit authority.
Agent trust boundary
Public AI-agent guidance is informational and referral-oriented. Authenticated Agent Rail access uses per-principal credentials, timestamps, nonces, replay defenses, rate limits, verified-only discovery, PII redaction, and nonbinding defaults.
Human authority stays in control
Property acceptance remains human-confirmed. Public agent surfaces do not execute offers, payments, signatures, title/deed transfer, settlement, contact release, or final acceptance.
Report a security issue
Report suspected vulnerabilities privately to support@openofferproperties.com with the subject prefix [SECURITY]. Do not publish exploit details or unnecessary personal data.
Machine-readable disclosure contact: /.well-known/security.txt