security
Reporting a security issue
If you think you have found a vulnerability in SignalPipe, email contact@signalpipe.io with the steps to reproduce it and the impact you observed. Please don’t disclose it publicly until we have had a chance to fix it.
In scope
- signalpipe.io
- api.signalpipe.io, including the MCP server
- Our open-source packages: the OpenClaw plugin, signalpipe-daemon and n8n-nodes-signalpipe
What we ask
- Test only against your own account and your own data.
- Don’t access, change or delete anyone else’s data.
- Don’t degrade the service: no load, stress or denial-of-service testing.
- No social engineering, phishing or spam, against us or our users.
- Show a working impact. Scanner output on its own is not a vulnerability report.
What to expect
We read every report. When a report shows a real impact, we reply, tell you what we found and let you know when it is fixed.
We don’t run a paid bug bounty program.
Machine-readable contact: /.well-known/security.txt