Security & Responsible Disclosure Policy
Effective 2026-10-01 · Version 2026-10-01
What changed in this version
- First published Security & Responsible Disclosure Policy.
- Explains how to report a vulnerability, what is in scope, and the safe harbor for good-faith research.
- We acknowledge reports within 2 business days; coordinated disclosure after 90 days.
- Lists the security measures in place today and what we ask of you.
Capitalised words have the meanings given in the Valuein Terms of Service (the "Terms"). "Valuein" means Valuein (as identified in the Terms). Machine-readable contact details are in /.well-known/security.txt.
In short: if you find a security vulnerability in Valuein, email security@valuein.biz. Test only within the scope below, use your own accounts, do not touch other people's data, and give us time to fix the problem before you tell anyone else. If you do that in good faith, we will not pursue legal action against you for your research. We do not run a paid bug bounty. Below is also an accurate list of what we do to protect your data — and what we ask of you. This summary helps you read the policy; it is not a substitute for it.
1.How to report
Email security@valuein.biz. Please include:
- the affected hostname, URL, endpoint, MCP tool, or SDK version;
- the type of issue (for example, broken access control, injection, credential exposure, prompt injection that crosses an account boundary);
- step-by-step reproduction, with requests and responses or a short proof of concept;
- what an attacker could achieve, in your assessment;
- any account identifiers or Credentials you used (never another person's);
- how you would like to be credited, if at all.
Do not include other people's personal data in your report beyond what is needed to show the issue. We do not publish a PGP key. If you need to send something sensitive, say so and we will agree a method.
2.Scope
In scope
valuein.bizand its pages, including the Workspace and account settings;- the Bulk API at
data.valuein.biz; - the MCP Server at
mcp.valuein.biz, including its OAuth flow; - the
valuein-sdkPython package (current release on PyPI) and its public source repository; - vulnerabilities in Valuein's own code that let one account read, change or act on another account's data, bypass Plan limits or payment, or make Valuein's Agents act without the user's approval.
Out of scope (do not test)
- denial-of-service, load or volumetric testing, and anything that degrades the Service for others;
- social engineering of Valuein personnel or users, phishing, and physical attacks;
- third-party services Valuein uses (for example Cloudflare, Stripe, Resend, Anthropic, OpenAI, OpenRouter, Google, LinkedIn): report issues in their products to them;
- staging, preview and
*.workers.devhostnames; - spam or mass account creation;
- reports from automated scanners without a demonstrated, exploitable impact (for example, a missing header with no attack, a version banner, or TLS cipher preferences);
- the content of SEC filings or Valuein Data (report a data error through the correction process in the Terms, not here);
- a language model saying something wrong or rude in your own session, with no security impact beyond your account (report it as Feedback).
3.Rules of engagement
- Use only accounts and Credentials you own or have explicit permission to use. Create test accounts on the free Benchmark Plan where possible.
- Do not access, copy, modify or delete data that is not yours. If you reach another person's data by accident, stop, do not keep a copy, and tell us in your report.
- Use the minimum testing needed to confirm the issue. Keep automated requests within your Plan's published rate limits.
- Do not run Agents or make purchases in a way that charges anyone other than you.
- Do not use an issue to persist access, pivot to other systems, or exfiltrate data.
- Keep the details confidential until we have fixed the issue, or until 90 days after your report, whichever is sooner — and coordinate the date with us.
4.Safe harbor
If you make a good-faith effort to comply with this policy, Valuein considers your research authorised and:
- will not bring, or support, a civil claim or a criminal complaint against you for it, including under the Computer Fraud and Abuse Act, state computer-crime laws, or the anti-circumvention provisions of the DMCA (17 U.S.C. §1201);
- waives, for that research only, the parts of the Terms and Acceptable Use Policy that would otherwise forbid it (security testing, automated access within your Plan's limits, and reverse engineering needed to demonstrate the issue);
- will, if a third party brings a claim against you over research that complied with this policy, make it known that your research was authorised.
This safe harbor does not cover conduct outside the scope or rules above, does not authorise testing of third parties' systems, and cannot bind a government authority. If you are unsure whether something is in scope, ask us first at security@valuein.biz.
5.What happens after you report
| Step | Target |
|---|---|
| Acknowledge your report | Within 2 business days |
| Tell you when it is fixed | when the fix ships |
These are targets, not contractual commitments. We will keep you informed and, with your permission, may credit you publicly once the issue is fixed.
No bounty. Valuein does not offer payment or rewards for reports. Do not make a report conditional on payment.
6.What we do
These are the protections in place today. We describe them precisely so you can judge them; we do not claim any certification or that the Service is free of vulnerabilities.
- Encryption in transit. The website, Bulk API and MCP Server are served over HTTPS (TLS) through Cloudflare. The website sends HTTP Strict Transport Security for two years, including subdomains.
- Encryption at rest. Account and Workspace data is stored in Cloudflare D1, KV, R2 and Durable Objects, which Cloudflare encrypts at rest (AES-256) with keys Cloudflare manages.
- API tokens. Each token is 256 bits of cryptographically secure randomness. You can rotate your token in account settings; rotation issues a new token and revokes the old one immediately.
- Sign-in without passwords. You sign in with Google, LinkedIn, or a one-time code we email you. We store only a peppered hash of the code; it expires after 10 minutes and allows a limited number of attempts.
- Your model keys. A model API key you connect is sealed with AES-GCM; the secret needed to open it is held in the server environment, not in the database. The sealed key is kept in a cookie that expires within 24 hours and, unless you untick the option, in an encrypted vault so your scheduled Agents can run. It is decrypted only in memory, only to call the provider you chose. It is not end-to-end encrypted: Valuein's servers decrypt it to make that call.
- Rate limiting and abuse controls. The Bulk API, MCP Server and website apply rate limits and quotas, and public sign-up forms use Cloudflare Turnstile. Our rate limiters are designed to let traffic through if the limiter itself fails, so they are a control, not a guarantee.
- Agent guardrails. Agent actions are classified by risk; higher-impact actions are staged for your approval and recorded in an audit log. Agents cannot place trades or move money. Third-party text that Valuein's tools return, such as filing content, is marked as untrusted for the model.
- Website hardening. A Content Security Policy restricts what the website can load and forbids embedding it in other sites.
- Payments. Card payments are handled by Stripe. Valuein does not receive or store your full card number.
- SDK. The SDK validates every SQL statement it runs against local data, scrubs tokens and signed URLs from its logs, and checks downloaded files before caching them.
- Deletion. You can delete your Account yourself in account settings; deletion removes your token, subscriptions and stored Workspace data as described in the Privacy Policy.
7.What we ask of you
- Keep Credentials secret. Do not put API or MCP tokens in source code, notebooks, shared documents, screenshots or prompts you share. Use environment variables or a secrets manager. Your token is emailed to you when it is issued; delete that email or store it securely.
- One Seat, one person. Do not share Credentials (see the Acceptable Use Policy).
- Protect your email and sign-in accounts. Anyone who controls your email or your Google/LinkedIn account can sign in as you. Use strong authentication on them.
- Give Agents only what they need. Connect Agents and MCP clients only to the tools and Credentials they need, and review staged actions before approving them.
- Tell us about a compromise. If you believe a Credential, model key or your Account has been exposed or misused, rotate the token in account settings immediately and email security@valuein.biz (or support@valuein.biz for account help). You are responsible for use of your Credentials until you rotate them, as set out in Terms §5.