Security
If you believe you've found a security vulnerability in Mosaic (the web app, API, or MCP server), please report it privately rather than filing a public issue.
Reporting a vulnerability
Email [email protected] with a description of the issue, steps to reproduce, and its potential impact. Include "SECURITY" in the subject line. We aim to acknowledge reports within a few business days and will keep you updated as we investigate and fix confirmed issues.
Scope
- getmosaic.dev and its subdomains (including mcp.getmosaic.dev)
- The public
mosaic-mcppackage and its source repository - The OAuth 2.1 / MCP connector authorization flow (DCR, PKCE, token issuance and refresh)
Out of scope: social engineering, physical access, denial-of-service testing against production, and issues in third-party services we depend on (report those to the respective provider).
Safe harbor
We won't pursue legal action against good-faith security research conducted under this policy — testing that avoids privacy violations, data destruction, and service disruption, and that gives us a reasonable opportunity to fix an issue before any public disclosure.