AccMCP

Responsible Disclosure

Effective 25 July 2026 · Version 0.1.0

If you've found a security issue in AccMCP — the website, the MCP server, the API, or the BI application — we want to hear about it directly, before it's disclosed publicly.

How to report

Email [security contact pending confirmation] with:

  • A description of the issue and its potential impact.
  • Steps to reproduce it (a proof-of-concept is welcome, exploit code is not required).
  • Any accounts or data involved — please use test data, not another customer's real accounting data.

What we ask

  • Give us a reasonable time to investigate and fix an issue before any public disclosure.
  • Don't access, modify, or delete data that isn't yours, including test accounts belonging to others.
  • Don't run automated scanning that could degrade service for other customers — the platform serves real accounting workflows.
  • Don't attempt social engineering against our staff or customers.

What you can expect from us

  • An acknowledgment of your report within [response time pending confirmation].
  • Honest updates as we investigate and remediate.
  • Credit in our disclosure notes, if you'd like it, once a fix ships.

Scope

In scope: accmcp.com, the MCP server and API at api.accmcp.com, the BI application at app.accmcp.com, and the data-sync service at upload.accmcp.com.

Out of scope: denial-of-service testing, physical security, and social engineering against staff or customers.

[Safe-harbor language for good-faith security research pending legal review.]