Security & responsible disclosure
We take the security of InsiderAlpha seriously and we value the work of the security research community. If you believe you have found a vulnerability, we want to hear about it, and we will not pursue or support legal action against anyone who reports in good faith.
Reporting a vulnerability
Email [email protected] with enough detail for us to reproduce the issue: affected URL or endpoint, steps, and impact. A proof of concept helps. Our machine- readable contact details are published at /.well-known/security.txt.
Safe harbour
We consider security research and vulnerability disclosure conducted under this policy to be authorised. Acting in good faith means: give us a reasonable time to respond before any public disclosure; make every effort not to access, modify, or destroy data that is not your own; do not degrade our service (no automated high-volume scanning, no denial of service); and use only your own test accounts. Stay within these bounds and we will not consider your research a violation of our terms.
Out of scope
Reports that are generally out of scope: findings from automated scanners without a demonstrated impact, missing security headers with no exploitable consequence, rate-limiting or brute-force reports without a working proof of concept, social engineering of our staff or users, and denial-of-service. When in doubt, ask.
How we respond
We aim to acknowledge a report within a few business days, keep you updated as we investigate, and let you know when a fix ships. With your permission, we are glad to credit you on the hall of fame below. We do not currently run a paid bounty program.
Hall of fame
Our thanks to the researchers who have responsibly disclosed issues and helped make InsiderAlpha safer for everyone.
- mamunwhh — August 2026 · Critical · Responsibly disclosed a vulnerability in the MCP authorization flow, since fixed.