generated: '2026-08-26' method: searched probe: true source: https://github.com/Losant/losant-mcp-server/blob/main/SECURITY.md scope: repository scope_note: | IMPORTANT - read the scope. Losant publishes NO platform-wide vulnerability disclosure policy: there is no /.well-known/security.txt on any Losant host (api.losant.com answers 405, www.losant.com and mcp.losant.com answer 404, probed 2026-08-26), no /security or /responsible-disclosure page on www.losant.com (404), and no bug bounty program on HackerOne, Bugcrowd or Intigriti was found. What Losant does publish is a real, first-party SECURITY.md in its open-source MCP server repository, with a named reporting address and stated response times. That document governs the MCP server project; it is the only published disclosure channel and is recorded here as such rather than being generalised into a platform policy Losant has not written. policy: - https://github.com/Losant/losant-mcp-server/blob/main/SECURITY.md contact: - hello@losant.com channel: email public_disclosure_prohibited: 'Reporters are asked not to use public GitHub issues.' response_commitments: acknowledgement: within 48 hours update: within 5 business days coordination: 'disclosure timing coordinated with the reporter' credit: 'credited in the security advisory unless the reporter prefers anonymity' requested_report_contents: - type of vulnerability - full paths of affected source files - location of the affected code (tag/branch/commit or URL) - special configuration needed to reproduce - step-by-step reproduction - proof-of-concept or exploit code, if possible - impact and how an attacker might exploit it supported_versions: - {version: '1.0.x', supported: true} bug_bounty: null security_overview: https://docs.losant.com/references/security/ evidence: - {source: 'https://github.com/Losant/losant-mcp-server/blob/main/SECURITY.md', kind: security-policy, http_status: 200} - {source: 'https://www.losant.com/.well-known/security.txt', kind: probe, http_status: 404} - {source: 'https://api.losant.com/.well-known/security.txt', kind: probe, http_status: 405} - {source: 'https://mcp.losant.com/.well-known/security.txt', kind: probe, http_status: 404} - {source: 'https://www.losant.com/security', kind: probe, http_status: 404}