Skip to content

Security: Nomploy/mcp

Security

SECURITY.md

Security Policy

Security is a priority across every Nomploy project. We appreciate the help of security researchers and the community in finding and reporting vulnerabilities.

Reporting a vulnerability

Email contact@nomploy.com. Please do not open a public issue for a suspected vulnerability.

Include as much as you can:

  • a description of the issue and the component or repository it affects,
  • steps to reproduce it,
  • sample code, screenshots or a short recording if they help,
  • the impact you think it has, and the version or commit you tested.

We will acknowledge your report as quickly as we can and keep you updated while we investigate. Time to a fix depends on complexity and severity.

What we ask of you

  • Do not access user data or systems beyond what is needed to demonstrate the issue.
  • Do not run denial-of-service tests, spam or social engineering.
  • Do not modify or destroy data that is not yours.
  • Give us a reasonable window to ship a fix before disclosing publicly.

Supported versions

Fixes land on the latest release of the affected project. If you are running a self-hosted instance, upgrade to the current version before reporting — the issue may already be fixed.

There aren't any published security advisories