# Sightspool — security contact # Format: RFC 9116 (https://www.rfc-editor.org/rfc/rfc9116) # # If you have found a vulnerability in Sightspool, the @sightspool/sdk package, # or the MCP connector, please tell us at the address below before disclosing it # publicly. We will acknowledge your report and keep you updated. We do not run a # paid bounty, and we will not pursue action against good-faith research that # respects user privacy and avoids service disruption or data destruction. # # In scope: www.sightspool.com, its research invitation/interview surfaces and public APIs, # and the published @sightspool/sdk and @sightspool/react packages. # Out of scope: findings against a customer's own connected services. # # NOTE: Expires is a required field and must stay under a year out. Renew it — # an expired security.txt is treated as unmaintained. Contact: mailto:security@sightspool.com Expires: 2027-07-01T00:00:00.000Z Preferred-Languages: en Canonical: https://www.sightspool.com/.well-known/security.txt