Security policy
Last updated 7 October 2026If you find a security problem in ClippingAlpha, tell us first so we can fix it. Momentist, Inc. operates ClippingAlpha and answers every report.
Report a vulnerability
Email dpo@clippingalpha.com with the page, endpoint or app you tested, the steps to reproduce the problem, what someone could do with it, and how to reach you. A person reads every report and replies. Please give us a reasonable time to fix a problem before you tell anyone else about it.
What is in scope
- clippingalpha.com and its subdomains, dev.clippingalpha.com included
- The MCP server at clippingalpha.com/mcp and its sign-in
- Our alert emails, push notifications and Telegram bot
- Your ClippingAlpha account, its sign-in and its connected accounts
Out of scope
- The campaign boards we link to. Each one runs its own site, so report a problem there to that board.
- Denial of service, spam, phishing or social engineering of anyone, and physical attacks
- Scanner output with no working proof of a problem
Good faith research
We will not take legal action against you, or ask anyone else to, for research done in good faith under this policy. Good faith means you avoid harm to people, their privacy and the service, you open only the data you need to show the problem and delete it afterwards, you change or destroy nothing, and you report what you find to us first.
Contact and security.txt
Security reports: dpo@clippingalpha.com
Machine readable: /.well-known/security.txt
By post: Momentist, Inc., 169 Madison Ave STE 38364, New York, NY 10016, USA
More about who we are: About ClippingAlpha