OpenOffer Security

Layered security for human-controlled agentic business.

OpenOffer Properties is built around least privilege, fail-closed behavior, server-side authorization, bounded requests, rate limiting, replay protection, environment isolation, auditable agent access, and verified recovery controls. No internet service is breach-proof; the goal is to reduce attack surface, contain failures, and make sensitive actions require explicit authority.

Agent trust boundary

Public AI-agent guidance is informational and referral-oriented. Authenticated Agent Rail access uses per-principal credentials, timestamps, nonces, replay defenses, rate limits, verified-only discovery, PII redaction, and nonbinding defaults.

Human authority stays in control

Property acceptance remains human-confirmed. Public agent surfaces do not execute offers, payments, signatures, title/deed transfer, settlement, contact release, or final acceptance.

Report a security issue

Report suspected vulnerabilities privately to support@openofferproperties.com with the subject prefix [SECURITY]. Do not publish exploit details or unnecessary personal data.

Machine-readable disclosure contact: /.well-known/security.txt