Responsible Disclosure Policy
ToolOracle / OracleNet welcomes good-faith security research. This policy describes how to report vulnerabilities and what to expect.
Reporting
Email: security@tooloracle.io
Response time: Initial response within 48 hours
Resolution target: 30–90 days depending on severity
Scope
In scope:
tooloracle.io and subdomains
- MCP endpoints (
/{oracle}/mcp/)
- x402 payment gateway
- OracleNet mesh registry, agent discovery files (
/.well-known/*)
- Authentication / authorization flows (OAuth, x402)
Out of scope:
- Third-party hosted services we depend on (Convex, Vercel, etc.)
- Social engineering of staff or contractors
- Physical attacks against infrastructure
- Pure denial-of-service (without RCE / data leak)
- Reports based solely on automated scanner output without manual verification
- Missing best-practice security headers without a demonstrated impact
Safe Harbor
We will not pursue civil or criminal action against researchers who:
- Test only against accounts you own or with explicit consent
- Avoid exfiltrating, destroying, or modifying user data
- Do not publicly disclose before we have had reasonable time to fix
- Comply with applicable laws (in particular EU/DE law)
Acknowledgments
Researchers who report valid issues will be credited (with consent) on our acknowledgments page.
References
ToolOracle / OracleNet · FeedOracle Technologies · Herford, Germany