Security Disclosure Policy
Effective date: 1 July 2025 · Last updated: 1 July 2025
Found a security vulnerability?
Email security@sf-tether.saas-factory.ai. We will acknowledge your report within 2 business days.
1. Our Commitment
SF Tether is a token vault and API connection layer for AI agents. The security of customer credentials, OAuth tokens, and audit logs is foundational to everything we do. We take every security report seriously and are committed to working with the security research community to keep our platform safe.
We operate a responsible disclosure programme and will work with researchers who follow this policy. We do not pursue legal action against researchers who comply with this policy.
2. In Scope
- The SF Tether web application and dashboard
- The SF Tether REST API and tRPC API
- The SF Tether SDK (authentication, token handling, request signing)
- The OAuth flow implementation (authorisation, token exchange, refresh, revocation)
- The Token Vault (encryption, isolation, access control)
- Authentication and session management
- Authorisation and multi-tenancy isolation
- The MCP (Model Context Protocol) server endpoint
3. Out of Scope
- Social engineering or phishing attacks against SF Tether staff or customers
- Physical attacks against infrastructure or personnel
- Denial-of-service or brute-force attacks
- Vulnerabilities in third-party Provider APIs (report to the relevant Provider)
- Theoretical vulnerabilities without a proof of concept
- Automated scanner findings without demonstrated impact
4. How to Report
Send your report to security@sf-tether.saas-factory.ai. Please include:
- A clear description of the vulnerability and its potential impact
- Step-by-step reproduction instructions
- Proof of concept (code, screenshots, or video) for Medium severity and above
- Which components are affected
- Your contact details for follow-up
Please do not disclose the vulnerability publicly until we have resolved it and agreed a disclosure timeline with you.
5. Our Response Times
| Severity | Resolution Target |
|---|---|
| Critical (CVSS 9.0–10.0) | 7 days |
| High (CVSS 7.0–8.9) | 30 days |
| Medium (CVSS 4.0–6.9) | 90 days |
| Low (CVSS below 4.0) | Next scheduled release |
We will acknowledge your report within 2 business days and provide an initial severity assessment within 5 business days.
6. Priority Vulnerability Classes
We are particularly interested in reports involving:
- Token Vault isolation failures — access to another organisation's credentials
- OAuth token leakage — exposure of access or refresh tokens outside authorised scope
- Authentication bypass — access without valid credentials
- Privilege escalation — access to admin or cross-tenant functionality
- Audit log tampering — ability to modify or delete audit records
- Injection vulnerabilities — SQL injection, SSRF, or command injection
- MCP endpoint security — vulnerabilities in the Model Context Protocol server
- Agent authorisation bypass — an agent accessing credentials it is not authorised for
7. Rules of Engagement
- Use your own test accounts — do not access other customers' data
- Stop immediately and contact us if you encounter sensitive customer data unexpectedly
- Do not perform actions that could impact Service availability for other users
- Keep findings confidential until coordinated disclosure is agreed
- Act in good faith
8. Safe Harbour
SF Tether will not initiate legal action against researchers who follow the rules of engagement, make a good-faith effort to avoid privacy violations and disruption, and report their findings to us before any public disclosure.