Skip to content

Latest commit

 

History

History
38 lines (22 loc) · 1.79 KB

File metadata and controls

38 lines (22 loc) · 1.79 KB

Security Policy

Reporting Security Vulnerabilities

Spreedly takes security seriously and appreciates your help in keeping our products and services secure. If you discover a security vulnerability in the Spreedly MCP server, please report it to us using one of the following methods. Do not open a public GitHub issue, pull request, or discussion describing the vulnerability.

Option 1: Spreedly Help Center

Submit a security vulnerability report through the Spreedly Help Center by submitting a request to Customer Support. This will open a support ticket for you, allowing you to securely communicate with our security team.

Option 2: Spreedly Security Team

Email our security team directly at security@spreedly.com with details about the vulnerability you've discovered.

What to Include in Your Report

When reporting a security vulnerability, please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any suggested fixes or mitigations (if available)

Response Timeline

We will acknowledge receipt of your report within 48 hours and provide an initial assessment within 5 business days. We'll keep you informed of our progress as we work to address the issue.

Disclosure Policy

We ask that you:

  • Allow us a reasonable amount of time to address the vulnerability before public disclosure
  • Act in good faith to avoid privacy violations, destruction of data, and interruption or degradation of our services
  • Not access or modify data that does not belong to you

Thank you for helping keep Spreedly and our customers secure.

For security architecture details, credential management, shared responsibility, and deployment guidance, see the Security Guide.