Legal
Security
Draft pending legal review. This document has not yet been reviewed by counsel for The Schoeller Group LLC and may change before it takes effect. Questions: legal@sourcefinch.com.
If you think you have found a security problem in SourceFinch, the API, the MCP server, the CLI or the SDK, email security@sourcefinch.com. We read every report and reply within two business days.
What helps
- What you found, where (URL, endpoint or tool), and the steps to reproduce it.
- What an attacker could do with it, as you understand it.
- How to reach you, and whether you would like to be credited.
Testing in good faith
- Use your own workspace and data. Do not access, change or delete other customers’ data.
- Do not run denial-of-service, spam or social-engineering tests, or test physical security.
- Give us a reasonable time to fix the problem before you disclose it publicly.
We will not pursue or support legal action against research that follows these rules. Our machine-readable contact details are in security.txt.