LedgerMCP: Responsible Disclosure Policy
LedgerMCP, LLC
Effective date: July 9, 2026
Last updated: July 9, 2026
LedgerMCP holds real financial data, and we take reports about its security
seriously. If you believe you have found a vulnerability in the Service, we
want to hear from you: privately, first.
How to report
Email support@ledgermcp.com with
"Security" in the subject line. Include:
- A description of the issue and where it lives (URL, endpoint, or MCP tool)
- Steps to reproduce it (proof-of-concept requests or screenshots help)
- What you believe the impact is
- How we can reach you for follow-up
We aim to acknowledge security reports within 2 business days and to keep
you informed as we investigate and fix.
Scope
In scope: the web application and marketing site at ledgermcp.com, the API
under `/api`, and the MCP server at `/mcp`.
Out of scope:
- Denial-of-service or volumetric testing of any kind
- Social engineering of LedgerMCP staff or users
- Findings that require a victim's device or account to already be compromised
- Reports about third-party services (our bank-connectivity, cloud database,
hosting, and email providers); please report those to the vendor directly
- Automated scanner output without a demonstrated vulnerability
Rules of engagement
- Test only against accounts you own. Never access, modify, or delete
another user's data. If you stumble into data that is not yours, stop, note
what happened, and tell us.
- Do not publicly disclose an issue before we have confirmed a fix and agreed
on timing with you.
- Do not degrade the Service for other users while testing.
Our commitment
If you follow this policy in good faith, we will not pursue legal action over
your research, we will work with you on a fix, and, with your permission,
we will credit you when the issue is resolved. We are a small company without
a formal bounty program, but we take fast fixes and honest thanks seriously.