generated: '2026-09-19' method: searched probe: true source: well-known/optionsahoy-com-security.txt docs: - https://github.com/AlvisoOculus/optionsahoy-mcp/blob/main/SECURITY.md policy: - https://github.com/AlvisoOculus/optionsahoy-mcp/blob/main/SECURITY.md contact: - mailto:security@optionsahoy.com acknowledgement_sla: 'We aim to acknowledge reports within three business days.' disclosure_terms: 'Please do not open a public issue for security reports, and please allow a reasonable window to fix before any public disclosure.' scope: - The hosted MCP server at https://optionsahoy.com/mcp - The REST API under https://optionsahoy.com/api/v1/ - The code in the optionsahoy-mcp repository out_of_scope: 'Questions about a calculation result or an unexpected number are not security reports (SECURITY.md); those go to a GitHub issue.' bug_bounty: null evidence: - source: well-known/optionsahoy-com-security.txt kind: security.txt (RFC 9116) on the apex host fetched: '2026-09-19' fields: {Contact: 'mailto:security@optionsahoy.com', Preferred-Languages: en, Canonical: 'https://optionsahoy.com/.well-known/security.txt', Expires: '2027-05-16T00:00:00Z'} note: No Policy field on the apex file. - source: well-known/optionsahoy-com-api-security.txt kind: security.txt (RFC 9116) on api.optionsahoy.com fetched: '2026-09-19' fields: {Contact: 'mailto:security@optionsahoy.com', Policy: 'https://optionsahoy.com/security-policy', Expires: 'generated per request'} note: The Policy URL it names returns HTTP 404 (probed 2026-09-19). The published policy that does resolve is SECURITY.md in the source repository. - source: https://github.com/AlvisoOculus/optionsahoy-mcp/blob/main/SECURITY.md kind: published security policy fetched: '2026-09-19' quote: 'Email security@optionsahoy.com with details and steps to reproduce. ... We aim to acknowledge reports within three business days. This matches the disclosure contact published at https://optionsahoy.com/.well-known/security.txt.' probed_absent: - {url: 'https://optionsahoy.com/security-policy', status: 404, note: 'The Policy target named by the api-host security.txt.'} - {url: 'https://optionsahoy.com/security', status: 404} - {url: 'https://optionsahoy.com/trust', status: 404} - {url: 'https://hackerone.com/optionsahoy', status: 404} - {url: 'https://bugcrowd.com/optionsahoy', status: 404} third_party_scans_claimed: - {name: MCPSafe, claim: 'Grade A, zero findings (five-model-consensus AIVSS scan)', source: https://optionsahoy.com/for-agents} - {name: MDN HTTP Observatory, claim: 'A+ (125/100)', source: https://optionsahoy.com/for-agents, note: 'Consistent with the HSTS-preload/CSP/COOP headers observed on /openapi.json.'} data_posture: 'SECURITY.md: no accounts, no authentication, no stored user data; inputs are not retained; telemetry records only tool name, success/error, client name and country; computation runs offline from compiled tax tables.'