CyberMax
Security policy
How to report a vulnerability in a CyberMax website, API or MCP server, and how our hosted tools handle data.
Report a vulnerability
Email cybermax.tools@gmail.com with the subject "Security": what you found, where, and the steps to reproduce it. Please give us a reasonable time to fix it before you publish anything, and don't access other people's data, degrade a service or run automated scans that send heavy traffic. We aim to reply within 3 business days.
In scope
- cybermaxtools.com and its subdomains, and the same services on *.cybermax-tools.workers.dev
- Our remote MCP servers (list) and REST APIs
How our MCP servers and APIs handle data
- Your tool arguments are used only to answer that call. They are not saved to a database, shared, sold or used for training.
- To make repeat lookups fast, some servers keep the public answer to a lookup in Cloudflare's edge cache for up to 7 days (most for 1 hour or less). It holds the public result, not who asked.
- Free tier: a per-day counter keyed by a SHA-256 hash of your IP address and the date (in a Cloudflare Durable Object). The raw IP is not stored.
- Paid key: the key is checked with the payment provider (Stripe; Polar for older keys) and the result is cached for 10 minutes; usage is counted per key per month.
- No accounts, cookies or tracking on the MCP endpoint. Errors may appear in Cloudflare's short-lived Worker logs.
- Every tool is read-only: it looks up public data and returns it. No tool writes, deletes, sends messages or spends money.
Machine-readable contact: /.well-known/security.txt. Public MCP manifests and notes: gitlab.com/CyberMax.tools/agent-tools.