Skip to content

Security: synpareia/trust-mcp

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in synpareia-trust-mcp, please report it responsibly. Do not open a public issue.

Send your report to security@synpareia.com with:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if you have one)

We will acknowledge your report within 48 hours and aim to provide a resolution timeline within 5 business days.

Disclosure Timeline

We follow a 90-day disclosure timeline. After reporting:

  1. We acknowledge receipt within 48 hours
  2. We investigate and develop a fix
  3. We coordinate a release and public disclosure
  4. If 90 days pass without a fix, the reporter may disclose publicly

We may request a reasonable extension if a fix requires more time, but we will communicate openly about progress.

Safe Harbor

We will not pursue legal action against researchers who:

  • Act in good faith to discover and report vulnerabilities
  • Avoid accessing or modifying other users' data
  • Do not degrade the service for others
  • Report findings privately before any public disclosure

Scope

The following are in scope for security reports:

  • The synpareia-trust-mcp MCP server
  • Trust toolkit tools (identity, chains, anchors, verification)
  • Cryptographic primitives used by the toolkit
  • Dependencies where the vulnerability is exploitable through this project

Out of Scope

  • Social engineering attacks against contributors or maintainers
  • Denial of service attacks
  • Vulnerabilities in third-party services or infrastructure not controlled by this project
  • Issues in software not maintained by this project

Credit

We are happy to credit security researchers in our release notes and CHANGELOG unless you prefer to remain anonymous. Let us know your preference when reporting.

There aren't any published security advisories