Security Disclosure

Last updated: August 11, 2026

1. Our Commitment

MCP Mastery takes the security of our platform and the data of our users seriously. As a course focused on MCP security, we hold ourselves to the same standards we teach. This page outlines our security practices and how to report vulnerabilities.

2. Security Measures We Implement

  • Password Security: All passwords are stored as bcrypt hashes. Plaintext passwords are never stored or logged.
  • Authentication: JWT-based session management with signed tokens. Sessions expire automatically.
  • Transport Security: All traffic is served over HTTPS/TLS. No plaintext HTTP is available.
  • Payment Security: All payments are processed by Razorpay (PCI-DSS Level 1 compliant). We never handle or store credit card data directly.
  • Input Validation: User inputs are validated and sanitized server-side to prevent injection attacks.
  • Environment Secrets: API keys and secrets are stored as environment variables and never exposed in client-side code.
  • Mock Payment Mode: In development/testing, the platform uses mock payment mode to prevent unauthorized API calls.

3. Responsible Disclosure Policy

We welcome security researchers to test our platform for vulnerabilities. If you discover a security issue, we ask that you:

  • Report the vulnerability to us promptly via our GitHub repository.
  • Provide sufficient detail to reproduce and verify the issue.
  • Give us reasonable time to fix the issue before public disclosure.
  • Avoid accessing or modifying data that does not belong to you.
  • Do not perform DoS attacks or use automated scanning tools that may disrupt service.
  • Do not exploit the vulnerability beyond what is necessary to demonstrate the issue.

4. Scope

The following are in scope for security testing:

  • The MCP Mastery web application at mcp-mastery.vercel.app
  • Authentication and session management mechanisms
  • Payment integration endpoints (API routes under /api/)

The following are out of scope:

  • Razorpay's infrastructure (report to Razorpay directly)
  • Vercel's infrastructure (report to Vercel directly)
  • Brute-force attacks on authentication endpoints
  • Social engineering attacks

5. How to Report

To report a security vulnerability, please open a private security advisory on our GitHub repository at github.com/tushar07232769/mcp-mastery. Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Suggested remediation (if any)

6. Recognition

We appreciate responsible disclosure and will acknowledge researchers who report valid vulnerabilities. With your permission, we will credit you in our security acknowledgments once the vulnerability is resolved.

7. Response Timeline

  • Acknowledgment: Within 48 hours of report
  • Initial Assessment: Within 5 business days
  • Fix Deployment: Depends on severity — critical within 7 days, high within 14 days, medium/low within 30 days
  • Public Disclosure: After fix is deployed, coordinated with reporter

8. Security Best Practices for Users

As a user of our platform, we recommend:

  • Use a strong, unique password for your MCP Mastery account.
  • Enable browser security features and keep your browser updated.
  • Never share your account credentials with anyone.
  • Log out when using shared computers.
  • Be cautious of phishing emails claiming to be from MCP Mastery — we will never ask for your password.

9. Course Security Disclaimer

The attack techniques taught in this course (tool poisoning, prompt injection, confused deputy attacks, etc.) are provided for educational purposes only. Using these techniques against systems you do not own or do not have explicit written authorization to test is illegal. We are not responsible for any misuse of the techniques taught in this course.