Mosaic is now liveMCP tools, 760+ targets across oncology, neuro and cardio, preprint on Zenodo.See plans →
Mosaic

Security

If you believe you've found a security vulnerability in Mosaic (the web app, API, or MCP server), please report it privately rather than filing a public issue.

Reporting a vulnerability

Email [email protected] with a description of the issue, steps to reproduce, and its potential impact. Include "SECURITY" in the subject line. We aim to acknowledge reports within a few business days and will keep you updated as we investigate and fix confirmed issues.

Scope

Out of scope: social engineering, physical access, denial-of-service testing against production, and issues in third-party services we depend on (report those to the respective provider).

Safe harbor

We won't pursue legal action against good-faith security research conducted under this policy — testing that avoids privacy violations, data destruction, and service disruption, and that gives us a reasonable opportunity to fix an issue before any public disclosure.