createmcps.com

Security & disclosure policy

Validation reports are public by default, with a per-run opt-out that makes a report unlisted rather than indexed. Every finding carries a dispute link, acknowledged within 2 business days. To report a vulnerability in createmcps.com itself, email security@createmcps.com.

Are validation reports public?

Yes, by default — though you can opt out per run. Each report gets a permanent URL showing the target's hostname, its grade and every finding; that permanence is what makes a report citable. Ticking "keep this report out of search engines" on the validator makes it unlisted instead: still reachable at its URL, but carrying noindex and never entering the sitemap. There is no ownership verification yet, so anyone can validate any server: only validate servers you own or have permission to test. If a report about your server should not exist at all, contact us and we will remove it.

How are security-relevant findings handled?

They are published in the report alongside everything else today. The embargo workflow described in our disclosure policy — notify the operator, hold the detail for 90 days — is not built yet. If you operate a server and need a security finding held back, contact us and we will remove the report while we sort it out.

How do I dispute a finding?

Every finding on every report carries a dispute link. We acknowledge within 2 business days and resolve within 10. Ambiguous checks ship as warnings rather than failures precisely so that a disputed call is rarely the difference between passing and failing.

Accuracy and permanence

Two policies worth stating plainly, because they are what makes a report worth trusting and worth citing.

When is a check a failure rather than a warning?

Only when it can be proven deterministically. A check that infers a problem — rather than observing it directly — ships as a warning, never a failure, no matter how confident the inference. A wrong “non-compliant” verdict destroys trust instantly and permanently, and a false warning costs a reader thirty seconds. Those are not symmetric, so the line sits well inside the safe side. Separately, if a failure was detected only heuristically, the overall letter grade is bumped up one level to compensate.

Who decides a disputed finding?

A human, not an automated re-run. Every dispute is reviewed by the maintainer against the specific spec sentence the rule cites — which is why every rule carries one. If the sentence does not support the finding, the rule is wrong and gets fixed for everyone, not just for the report that raised it. Acknowledged within 2 business days, resolved within 10.

How long do public reports last?

Permanently. A report URL, once public, is never recycled, never renumbered, and never expires — permanence is the entire reason a report is worth citing, and a citation that rots takes the citing page's trust with it. The two exceptions are both deliberate and both requested: a report can be made unlisted at validation time, or removed on request afterwards, in which case its URL returns 410 Gone rather than 404 so that crawlers know the removal was intentional.

How do I report a vulnerability in createmcps.com?

Email security@createmcps.com or see /.well-known/security.txt.

Full policy: /05-REPORT-DISCLOSURE-POLICY.md. This page needs a legal review pass before launch — see that doc's §10.