LedgerMCP: Responsible Disclosure Policy

LedgerMCP, LLC

Effective date: July 9, 2026

Last updated: July 9, 2026

LedgerMCP holds real financial data, and we take reports about its security

seriously. If you believe you have found a vulnerability in the Service, we

want to hear from you: privately, first.

How to report

Email support@ledgermcp.com with

"Security" in the subject line. Include:

We aim to acknowledge security reports within 2 business days and to keep

you informed as we investigate and fix.

Scope

In scope: the web application and marketing site at ledgermcp.com, the API

under `/api`, and the MCP server at `/mcp`.

Out of scope:

hosting, and email providers); please report those to the vendor directly

Rules of engagement

another user's data. If you stumble into data that is not yours, stop, note

what happened, and tell us.

on timing with you.

Our commitment

If you follow this policy in good faith, we will not pursue legal action over

your research, we will work with you on a fix, and, with your permission,

we will credit you when the issue is resolved. We are a small company without

a formal bounty program, but we take fast fixes and honest thanks seriously.

Related