Give your AI agents access to accurate, real-time customer profiles with FullContact MCP | No complex setups.

Overview of Security Practices

Information for Security Researchers

If you are a Security Researcher, please let us know about any security issue and we’ll make every effort to quickly correct it. However, you must follow our responsible disclosure policy:

 

  • Disclose the vulnerability and all known details promptly.

  • Give us a reasonable time to respond to the issue before making any information about it public in order to protect our users from a possible malicious attack in response to your disclosure. You’re more than welcome to post a write-up after the issue has been fixed and public disclosure has been agreed upon.

  • Act in good faith not to degrade the performance of our services (including denial of service). We understand accidents may happen.

  • Strive not to access or modify information in users’ accounts should you find a vulnerability. If necessary, please create a second account to demonstrate the issue. If you cannot, you may report using real accounts.

  • Limit the scope of your activities to FullContact properties, not those belonging to other services we may use such as analytics providers or support helpdesks. Those issues should be reported to the providers directly. If you’re unsure how to proceed, or have questions, please contact us!

 

We will not take legal action or engage with law enforcement for security activities provided you comply with this policy. Please read about our eligibility guidelines and report security issues using our Bugcrowd page. If you need to speak with the security team, open a Bugcrowd ticket, or send an email to the security@fullcontact.com mailing list.

 

If you believe your own account may have been compromised for any reason, please contact support@fullcontact.com with as many details as you can provide.