# Security Policy

`delx-mcp-server` is a thin local stdio bridge to the hosted Delx MCP endpoint.
It does not contain Delx backend code, databases, reward accounting, server
credentials or private infrastructure.

Do not open public issues or pull requests that contain:

- API keys, OAuth tokens or bearer tokens.
- Local MCP client config files with private values.
- Private Delx endpoint overrides.
- Hosted response payloads that include personal or account data.

For private reports, contact:

```text
support@delx.ai
```
