If you discover a security vulnerability in synpareia-trust-mcp, please report it responsibly. Do not open a public issue.
Send your report to security@synpareia.com with:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
We will acknowledge your report within 48 hours and aim to provide a resolution timeline within 5 business days.
We follow a 90-day disclosure timeline. After reporting:
- We acknowledge receipt within 48 hours
- We investigate and develop a fix
- We coordinate a release and public disclosure
- If 90 days pass without a fix, the reporter may disclose publicly
We may request a reasonable extension if a fix requires more time, but we will communicate openly about progress.
We will not pursue legal action against researchers who:
- Act in good faith to discover and report vulnerabilities
- Avoid accessing or modifying other users' data
- Do not degrade the service for others
- Report findings privately before any public disclosure
The following are in scope for security reports:
- The synpareia-trust-mcp MCP server
- Trust toolkit tools (identity, chains, anchors, verification)
- Cryptographic primitives used by the toolkit
- Dependencies where the vulnerability is exploitable through this project
- Social engineering attacks against contributors or maintainers
- Denial of service attacks
- Vulnerabilities in third-party services or infrastructure not controlled by this project
- Issues in software not maintained by this project
We are happy to credit security researchers in our release notes and CHANGELOG unless you prefer to remain anonymous. Let us know your preference when reporting.