generated: '2026-08-09' method: searched source: https://github.com/mcp360/mTarsier/blob/HEAD/SECURITY.md policy: - https://github.com/mcp360/mTarsier/blob/HEAD/SECURITY.md contact: - support@mcp360.ai channel: email public_disclosure_forbidden: true sla: acknowledgement: 48 hours fix_target: 14 days depending on severity bug_bounty: null scope: covered: - mTarsier desktop application - the bundled tsr CLI binary not_covered: - third-party MCP servers listed in the Marketplace caveat: IMPORTANT — this policy is scoped to the mTarsier desktop app, NOT to the MCP360 gateway (connect.mcp360.ai) or the REST/MCP API. There is no vulnerability disclosure policy covering the hosted gateway itself, and no /.well-known/security.txt on any MCP360 host. Recorded here because it is the only published disclosure channel the provider operates, and the contact address is the company-wide one. evidence: - source: https://raw.githubusercontent.com/mcp360/mTarsier/HEAD/SECURITY.md kind: security-policy status: 200 fetched: '2026-08-09' - source: https://mcp360.ai/.well-known/security.txt kind: security.txt status: 404 fetched: '2026-08-09' - source: https://mcp360.ai/security kind: disclosure-page status: 404 fetched: '2026-08-09' gaps: - No security.txt (RFC 9116). - No disclosure policy covering the hosted gateway or API. - No bug bounty program.