Spreedly takes security seriously and appreciates your help in keeping our products and services secure. If you discover a security vulnerability in the Spreedly MCP server, please report it to us using one of the following methods. Do not open a public GitHub issue, pull request, or discussion describing the vulnerability.
Submit a security vulnerability report through the Spreedly Help Center by submitting a request to Customer Support. This will open a support ticket for you, allowing you to securely communicate with our security team.
Email our security team directly at security@spreedly.com with details about the vulnerability you've discovered.
When reporting a security vulnerability, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any suggested fixes or mitigations (if available)
We will acknowledge receipt of your report within 48 hours and provide an initial assessment within 5 business days. We'll keep you informed of our progress as we work to address the issue.
We ask that you:
- Allow us a reasonable amount of time to address the vulnerability before public disclosure
- Act in good faith to avoid privacy violations, destruction of data, and interruption or degradation of our services
- Not access or modify data that does not belong to you
Thank you for helping keep Spreedly and our customers secure.
For security architecture details, credential management, shared responsibility, and deployment guidance, see the Security Guide.