Back to Security

Vulnerability Disclosure Policy

Last updated October 11, 2026

1. Introduction

We welcome reports from security researchers and from anyone who finds a weakness in MCPBay. This policy explains what is in scope, how to report an issue, what you can expect from us, and the protection we offer when you research in good faith. The security measures in place today are described on the Security page.

2. Scope

  • mcpbay.pro: the website, the catalog, accounts and the account area, and the OAuth sign-in that AI clients use.
  • api.mcpbay.pro: the public API.
  • Other MCPBay platform services on *.mcpbay.pro, including the sign-in and access control in front of MCP servers hosted on MCPBay.

3. Out of scope

  • The code and behavior of third-party MCP servers listed in the catalog or hosted on MCPBay. Their authors are responsible for them: please report to the author, using the source code or author link on the server’s catalog page. If a server looks malicious or its author does not respond, tell us at the address below and include the server page link.
  • Denial-of-service attacks and load or stress testing.
  • Social engineering and phishing of MCPBay staff or users.
  • Physical attacks against offices, equipment or data centers.
  • Output of automated scanners without a demonstrated, exploitable impact.

4. How to report

Email support@mcpbay.pro with “Security” in the subject. Please include:

  • a description of the issue and where it is (URL, endpoint or feature);
  • step-by-step instructions to reproduce it, with any proof-of-concept code;
  • the impact you believe it has.

Reports in English or Russian are welcome. You may report anonymously. Our contact details are also published in security.txt.

5. Guidelines

Under this policy, “research” means activities in which you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Use only accounts you own or have explicit permission to use. If you come across other people’s data, stop, do not keep or share it, and tell us.
  • Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent access, or use it as a pivot to other systems.
  • Give us a reasonable amount of time to resolve the issue before you disclose it publicly.
  • Do not submit a high volume of low-quality reports.

Once you’ve established that a vulnerability exists or encountered any sensitive data (including personal data, financial information or account credentials), you must stop your test, notify us immediately, and not disclose this data to anyone else.

6. What to expect from us

  • We acknowledge your report within 5 business days.
  • We tell you whether we can reproduce the issue, keep you informed while we work on it, and let you know when it is fixed.
  • We agree a public disclosure date with you. We aim to fix confirmed issues within 90 days; if a fix needs longer, we explain why.
  • With your permission, we credit you when the issue is resolved.

MCPBay does not run a bug bounty program and does not offer payment for reports.

7. Safe harbor

When conducting vulnerability research according to this policy, we consider this research to be:

  • Authorized in view of any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;
  • Authorized in view of any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls;
  • Exempt from restrictions in our Terms of Service that would interfere with conducting security research, and we waive those restrictions on a limited basis; and
  • Lawful, helpful to the overall security of the Internet, and conducted in good faith.

You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

If at any time you have concerns or are uncertain whether your research is consistent with this policy, please ask us at support@mcpbay.pro before going any further.

Based on the disclose.io core terms (CC0).