Skip to content

Security: ipinfo/mcp

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest released version of ipinfo-mcp-server receives security updates.

Reporting a Vulnerability

Please report security vulnerabilities by email to support@ipinfo.io. Do not open a public GitHub issue for security reports.

If you want to encrypt your report, use our PGP key: https://ipinfo.io/.well-known/pgp-key.txt

Include as much detail as you can: affected version, reproduction steps, and potential impact.

What to Expect

  • We acknowledge reports within 2 business days.
  • We aim to provide an assessment within 5 business days.
  • We aim to ship a fix for confirmed vulnerabilities within 30 days, and we follow a 90-day coordinated disclosure window.

We will credit reporters in the release notes unless asked otherwise.

There aren't any published security advisories