// SECURITY_DISCLOSURE
Responsible Disclosure
If you discover a security vulnerability in MakeYourMCP, we want to hear from you. This page defines our scope, contact method, and safe harbour commitments.
How to Report
Send your findings to connect@makeyourmcp.com with a clear description of the issue, reproduction steps, and any proof-of-concept material. PGP-encrypted communication is available on request — reply to our initial acknowledgement to request our public key.
Response SLAs
- Acknowledgement: Within 4 hours of receipt (24/7).
- Triage confirmation: Within 24 hours during business days (UTC+0, Mon–Fri).
- Critical vulnerability resolution: Target 14 days from confirmed reproduction.
- Coordinated disclosure: We will work with reporters on public disclosure timing once the issue is resolved.
In-Scope Targets
- MakeYourMCP gateway API (api.makeyourmcp.com)
- Policy engine and rule evaluation logic
- Credential vault interfaces
- Web application (makeyourmcp.com)
- Authentication and session management
Out-of-Scope
- Third-party services and infrastructure we do not control
- Social engineering attacks against MakeYourMCP employees
- Physical access attacks
- Denial-of-service testing without prior written authorisation
- Automated scanning tools that generate noise without targeted investigation
Safe Harbour
MakeYourMCP will not pursue legal action against researchers who discover and responsibly disclose security vulnerabilities following this policy, provided that the researcher:
- Does not access, modify, or delete data beyond what is strictly necessary to demonstrate the vulnerability.
- Does not exploit the vulnerability beyond initial proof-of-concept reproduction.
- Does not publicly disclose the vulnerability before we have had a reasonable opportunity to address it.
- Reports findings through the official channel (connect@makeyourmcp.com) before sharing with any third party.
Recognition
We maintain a private thank-you list for researchers who responsibly disclose vulnerabilities. Public acknowledgement on a Hall of Fame page is in development and will be available before GA launch.
Additional Security Resources
Contact
connect@makeyourmcp.com — 4-hour acknowledgement SLA · PGP available on request