Security
Effective: August 2, 2026
ProductIndex operates an agentic marketplace surface (MCP server, OAuth 2.1 clients, A2A endpoints, and an RFQ system) in addition to the public site. If you've found a security vulnerability affecting any of it, we want to hear about it before anyone else does.
How to report
Email security@productindex.ai with a description of the issue, the steps to reproduce it, and its potential impact. Please include enough detail (request/response examples, affected endpoint or page) for us to reproduce the issue without extensive back-and-forth.
This address is also published at /.well-known/security.txt per RFC 9116 for automated tooling.
What we ask
- Give us a reasonable time to investigate and address a report before any public disclosure.
- Avoid actions that could degrade the service for other users, including automated scanning at volume, denial-of-service testing, or attempts to access or modify data belonging to other accounts beyond what's needed to demonstrate the issue.
- Don't use a finding to access, retain, or exfiltrate real user or producer data beyond the minimum needed to prove impact.
Safe harbor
We will not pursue legal action against anyone who reports a vulnerability in good faith, follows the guidelines above, and gives us a reasonable opportunity to fix the issue before disclosing it publicly.
What's in scope
Anything served from productindex.ai and its subdomains, including the MCP
server, OAuth/A2A endpoints, and the producer dashboard. Third-party services we depend on
(payment processors, cloud infrastructure providers) are out of scope — report those directly
to the vendor.
Not a support channel
This address is for security reports only. For general questions, profile corrections, or account help, see our Contact page.
ProductIndex