Luthersystems Com Vulnerability Disclosure
Luther Systems publishes a vulnerability-reporting channel — security@luthersystems.com — in the SECURITY.md of each public agent-product repository, and the InsideOut MCP server exposes a submit_feedback tool that accepts category "security". probe-security-programs.py found nothing on the web hosts (no /.well-known/security.txt on any of eight hosts, no HackerOne/Bugcrowd/Intigriti program, no disclosure page on luthersystems.com), so this record is GitHub-published policy, not a security.txt or bug bounty. No safe-harbour language, response SLA or reward is stated. The InsideOut SECURITY.md also documents the data flow and trust boundaries of the hosted MCP server (what is and is not sent; credentials never transit the agent) and notes the repo runs a Snyk agent scan workflow.
Luther Systems runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.