generated: '2026-07-18' method: searched probe: true source: https://github.com/butlrtechnologies/butlr-mcp/blob/main/SECURITY.md policy: - https://github.com/butlrtechnologies/butlr-mcp/blob/main/SECURITY.md contact: - security@butlr.com acknowledgement_sla: 48 hours notes: >- Butlr publishes a responsible-disclosure security policy in its official first-party MCP server repository. Reporters are asked to email security@butlr.com (not open a public issue); Butlr acknowledges within 48 hours and provides an estimated fix timeline. No public bug-bounty program (HackerOne/Bugcrowd/Intigriti) or standalone /.well-known/security.txt was found; api.butlr.io returns HTTP 403 to /.well-known/ probes. evidence: - source: https://github.com/butlrtechnologies/butlr-mcp/blob/main/SECURITY.md kind: security-policy contact: security@butlr.com