Trust center
Security
Orrery is a hosted, public MCP catalog. Its security boundary is deliberately narrow: callers receive declared tools and signed results, not arbitrary command, filesystem, or deployment access.
What we can substantiate
Report a vulnerability
Please use private GitHub Security Advisories for vulnerabilities. Product questions and non-sensitive defects belong in the public issue tracker. Include the affected URL/tool, reproduction steps, impact, and any receipt or request identifiers that are safe to share.
Machine-readable disclosure metadata: /.well-known/security.txt.