Security

Effective: August 2, 2026

ProductIndex operates an agentic marketplace surface (MCP server, OAuth 2.1 clients, A2A endpoints, and an RFQ system) in addition to the public site. If you've found a security vulnerability affecting any of it, we want to hear about it before anyone else does.

How to report

Email security@productindex.ai with a description of the issue, the steps to reproduce it, and its potential impact. Please include enough detail (request/response examples, affected endpoint or page) for us to reproduce the issue without extensive back-and-forth.

This address is also published at /.well-known/security.txt per RFC 9116 for automated tooling.

What we ask

Safe harbor

We will not pursue legal action against anyone who reports a vulnerability in good faith, follows the guidelines above, and gives us a reasonable opportunity to fix the issue before disclosing it publicly.

What's in scope

Anything served from productindex.ai and its subdomains, including the MCP server, OAuth/A2A endpoints, and the producer dashboard. Third-party services we depend on (payment processors, cloud infrastructure providers) are out of scope — report those directly to the vendor.

Not a support channel

This address is for security reports only. For general questions, profile corrections, or account help, see our Contact page.