Security
Last Updated: August 28, 2026
Security is foundational to OneLore. Our MCP server connects AI agents and teammates to the same shared project context, and protecting that context — your documents, tasks, and messages — is a responsibility we take seriously.
Reporting a vulnerability
If you believe you've found a security vulnerability in OneLore, please email hello@onelore.ai with a description and steps to reproduce. We read every report, we'll acknowledge yours as quickly as we can, and we'll keep you updated through to a fix.
Please give us a reasonable opportunity to investigate and remediate before disclosing an issue publicly. Our machine-readable contact details are published at /.well-known/security.txt.
Safe harbor
We support good-faith security research. If you make a good-faith effort to follow this policy, we will regard your research as authorized, we will not pursue or support legal action against you for it, and we will work with you to resolve the issue promptly. In return, please:
- Avoid privacy violations, data destruction, and disruption of our service.
- Only access or modify accounts and data that you own or have explicit permission to test.
- Give us reasonable time to remediate before any public disclosure.
Acknowledgments
We are grateful to the researchers who have responsibly disclosed security issues to OneLore:
- A security researcher — Reported a
redirect_urivalidation flaw in the MCP OAuth server that enabled authorization-code interception. Fixed August 2026.