Security & Responsible Disclosure

Last updated: 2026-06-29

We take the security of OrgMCP and our customers' data seriously. If you believe you have found a security vulnerability, we want to hear from you and will work with you to understand and resolve it quickly.

How to report

Email security@orgmcp.io with a description of the issue, the steps to reproduce it, and any proof-of-concept material. A machine-readable contact is also published at https://orgmcp.io/.well-known/security.txt per RFC 9116.

Our commitment

  • We will acknowledge your report within 3 business days.
  • We will keep you informed as we investigate and remediate.
  • We will not pursue legal action against researchers who follow this policy in good faith.
  • With your permission, we are happy to credit you once the issue is resolved (private hall-of-fame; we do not currently run a paid bug-bounty).

Please do

  • Give us a reasonable time to remediate before any public disclosure.
  • Only test against your own workspace and accounts; never access, modify, or delete data belonging to other tenants.
  • Use test data and avoid actions that could degrade the Service for others.

Please do not

  • Run automated scans that generate denial-of-service load.
  • Exfiltrate data, pivot to other systems, or use social engineering, physical, or spam/phishing techniques against our staff or customers.

Scope

In scope: app.orgmcp.io, api.orgmcp.io, and the OrgMCP MCP endpoints. Out of scope: third-party services we integrate with (report those to the respective vendor) and findings that require a compromised end-user device.

Contact

Security: security@orgmcp.io

For a broader overview of our security, privacy, and compliance posture — data residency, encryption, tenant isolation, and disaster recovery — see the Trust Center.