Responsible Disclosure
Effective 25 July 2026 · Version 0.1.0
If you've found a security issue in AccMCP — the website, the MCP server, the API, or the BI application — we want to hear about it directly, before it's disclosed publicly.
How to report
Email [security contact pending confirmation] with:
- A description of the issue and its potential impact.
- Steps to reproduce it (a proof-of-concept is welcome, exploit code is not required).
- Any accounts or data involved — please use test data, not another customer's real accounting data.
What we ask
- Give us a reasonable time to investigate and fix an issue before any public disclosure.
- Don't access, modify, or delete data that isn't yours, including test accounts belonging to others.
- Don't run automated scanning that could degrade service for other customers — the platform serves real accounting workflows.
- Don't attempt social engineering against our staff or customers.
What you can expect from us
- An acknowledgment of your report within [response time pending confirmation].
- Honest updates as we investigate and remediate.
- Credit in our disclosure notes, if you'd like it, once a fix ships.
Scope
In scope: accmcp.com, the MCP server and API at api.accmcp.com, the BI application at app.accmcp.com, and the data-sync service at upload.accmcp.com.
Out of scope: denial-of-service testing, physical security, and social engineering against staff or customers.
Legal safe harbor
[Safe-harbor language for good-faith security research pending legal review.]