Security & Responsible Disclosure
Last updated: 2026-06-29
We take the security of OrgMCP and our customers' data seriously. If you believe you have found a security vulnerability, we want to hear from you and will work with you to understand and resolve it quickly.
How to report
Email security@orgmcp.io with a description of the issue, the steps to reproduce it, and any proof-of-concept material. A machine-readable contact is also published at https://orgmcp.io/.well-known/security.txt per RFC 9116.
Our commitment
- We will acknowledge your report within 3 business days.
- We will keep you informed as we investigate and remediate.
- We will not pursue legal action against researchers who follow this policy in good faith.
- With your permission, we are happy to credit you once the issue is resolved (private hall-of-fame; we do not currently run a paid bug-bounty).
Please do
- Give us a reasonable time to remediate before any public disclosure.
- Only test against your own workspace and accounts; never access, modify, or delete data belonging to other tenants.
- Use test data and avoid actions that could degrade the Service for others.
Please do not
- Run automated scans that generate denial-of-service load.
- Exfiltrate data, pivot to other systems, or use social engineering, physical, or spam/phishing techniques against our staff or customers.
Scope
In scope: app.orgmcp.io, api.orgmcp.io, and the OrgMCP MCP endpoints. Out of scope: third-party services we integrate with (report those to the respective vendor) and findings that require a compromised end-user device.
Contact
Security: security@orgmcp.io
For a broader overview of our security, privacy, and compliance posture — data residency, encryption, tenant isolation, and disaster recovery — see the Trust Center.