Ultra is aligned with and an early contributor to AARM and the Agentic Trust Control Framework.

Trust & Security

Vulnerability Disclosure Policy

Ultra Security, Inc. · Effective July 29, 2026 · Version 1.0

Security is core to what Ultra builds. We develop AI-native security infrastructure for the Model Context Protocol (MCP), and we hold our own systems to the same standard we help our customers meet. We value the work of security researchers and welcome reports of potential vulnerabilities in our products and services.

This policy explains how to report a vulnerability to Ultra, what is in scope, and what you can expect from us in return. It is intended to give security researchers clear guidelines for conducting good-faith research and for submitting what they find.

Safe harbor. If you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Ultra will not recommend or pursue legal action against you related to your research. If legal action is initiated by a third party against you for activity conducted in accordance with this policy, we will make our authorization known.

Report a vulnerability

Ultra manages vulnerability submissions through Bugcrowd. Use the submission form at the bottom of this page to send us a report directly. Every submission goes straight to our security team for triage. You can also email security@ultra.security.

Please read the scope and rules of engagement below before testing. Submit reports in English where possible, and send one vulnerability per report unless you need to chain several issues to demonstrate impact.

What to include

A complete report lets us reproduce and assess the issue without a round trip, which is the single biggest factor in how quickly we can act. Please include:

  • The affected asset: the URL, endpoint, host, or component where you found the issue.
  • Step-by-step instructions to reproduce it, including any accounts, payloads, or preconditions required.
  • Your assessment of the impact: what an attacker could do, and to whom.
  • A proof of concept where you have one: a request and response pair, a short script, a screenshot, or a video.
  • Any suggested remediation, if you have a view on it.

Scope

This policy applies to Ultra's production services and the resources that store or process customer data, including:

  • The Ultra application and API (app.ultra.security, api.ultra.security).
  • The Ultra MCP security proxy and associated production infrastructure.
  • Other Ultra-operated subdomains and services that handle sensitive or customer data.

The scope described on this page is authoritative. If you are unsure whether a system is in scope, email security@ultra.security before testing.

Out of scope

The following are not covered by this policy. Please do not test against them:

  • Ultra's marketing website and other properties that contain no sensitive or customer data.
  • Third-party services, platforms, or vendors that Ultra uses but does not operate.
  • Systems, data, or accounts that do not belong to you and for which you do not have explicit permission.

Rules of engagement

When conducting research under this policy, we ask that you:

  • Make a good-faith effort to avoid privacy violations, data destruction, and any interruption or degradation of our services.
  • Only interact with accounts you own or for which you have explicit permission from the account holder.
  • Stop testing and notify us immediately if you encounter customer data, personal data, or other sensitive information, and do not access, store, copy, or share more of it than is necessary to demonstrate the vulnerability.
  • Give us a reasonable amount of time to investigate and remediate an issue before disclosing it publicly or to any third party.
  • Keep the details of any discovered vulnerability confidential until we have confirmed it is resolved.

Prohibited activities

To keep our services safe for all users, the following activities are not authorized under this policy:

  • Denial-of-service (DoS/DDoS) or other tests that impair the availability of our services.
  • Physical attacks against Ultra offices, staff, or infrastructure.
  • Social engineering, phishing, or pretexting of Ultra employees, contractors, customers, or vendors.
  • Automated scanning that generates excessive traffic, spam, or noise.
  • Accessing, modifying, or destroying data that does not belong to you.

What you can expect from us

When you submit a report in accordance with this policy, Ultra will:

  • Acknowledge receipt of your report within three (3) business days.
  • Validate and triage the report, and provide an initial assessment, generally within ten (10) business days.
  • Keep you informed of our progress as we work to remediate a confirmed vulnerability.
  • Coordinate disclosure with you and let you know when the issue has been resolved. We are committed to timely remediation and to coordinating any public disclosure with you.

We prioritize remediation based on severity and potential impact, and we aim to resolve critical issues as quickly as possible.

Exclusions

The following are generally not eligible under this policy unless you can demonstrate a realistic, exploitable security impact:

  • Reports based solely on theoretical vulnerabilities or automated scanner output without a working proof of concept.
  • Missing best-practice configurations, headers, or cookie flags with no demonstrated impact.
  • Reports of outdated software versions without a demonstrated, exploitable vulnerability.
  • Self-XSS, clickjacking on pages with no sensitive actions, and issues requiring unlikely user interaction.
  • Vulnerabilities affecting only unsupported or end-of-life browsers or platforms.
  • Rate-limiting, email spoofing (SPF/DKIM/DMARC), and similar issues without a demonstrated impact.

Recognition

We are grateful to the researchers who help keep Ultra and our customers safe. Eligibility for recognition or rewards, where offered, is determined through our Bugcrowd program and its terms. With your permission, we are happy to acknowledge your contribution.

Thank you for helping us keep Ultra Security and our customers safe.

Submit a report

Reports go directly to the Ultra security team. You do not need a Bugcrowd account to submit. You can also email security@ultra.security.

Questions about this policy? Contact security@ultra.security. This policy may be updated from time to time; the effective date above reflects the most recent revision.