Notify. Wait. Publish. The same way, every time.
Conformant's value is telling the truth about which agent tools are safe to connect. Hiding every failure would falsify that by omission. So failures are not suppressed and they are not published the day we find them: they run through one mechanical process, applied identically to every vendor, with no human discretion over who is named.
1. We grade only what an MCP client can already see
Every grade is produced by the public-subset battery performing the standard MCP client handshake (initialize, notifications/initialized, tools/list) against a publicly reachable endpoint. The scanner never invokes a tool: it cannot call tools/call, so nothing is exploited, nothing is changed, and no access control is circumvented. A grade is an automated observation of a publicly reachable endpoint at a timestamp. It is not a certification.
2. Failing grades are held, then the vendor is notified
When a server grades D or F, it is withheld from the public registry and the vendor's security contact (RFC 9116 security.txt, or a documented good-faith path to a real security or abuse address) is notified with the full report, its content hash, and its Sigstore/Rekor anchor URL. The notification itself is anchored, so coordination is provable, not merely asserted.
3. A fixed disclosure window, identical for everyone
45 calendar days for domestic and first-party-reachable vendors; 90 days for non-responsive or first-contact foreign entities. The window is fixed in this policy. No vendor receives a longer or shorter window by request, relationship, or discretion.
4. At window expiry, the grade publishes automatically
When the window closes, the grade publishes by mechanism, not by a person, unless a re-scan shows the endpoint now requires authentication and has remediated to an A or B, in which case we publish the dated remediation timeline instead. A person never decides which vendor publishes.
5. Only directly-observed findings auto-publish
A grade auto-publishes only when it rests on directly-observed, independently reproducible failing checks (an unauthenticated session that completed, a credential pattern in disclosed metadata, plaintext transport). Any grade resting on inference or a low-confidence signal stays held for human and counsel review and never rides the automatic clock.
6. The registry never lies by omission
While a finding is held, the registry shows an honest count of findings under coordinated disclosure with names pending. A clean registry is never the result of hiding a failure.
7. Right of reply
The vendor's response, or a note that no response was received by the published date, is shown alongside the grade. A specific, demonstrated factual error is corrected before publication, not after.
8. Every grade is reproducible and anchored
Each published report carries its content hash and Sigstore/Rekor log URL. Anyone can re-run the identical, non-invasive handshake and reproduce the observation. The grade is Conformant's labeled conclusion drawn from the disclosed CFM-01 through CFM-08 criteria, never an assertion about a vendor's competence or intent.
9. Remediation is the better story
A vendor-triggered re-scan re-grades a fixed endpoint on the next cycle. A server that moves from a failing grade to a passing one publishes its dated before-and-after. Fixing the problem is the outcome this policy exists to produce.
10. If we are wrong, we correct within 48 hours
Any demonstrated false positive (a transient error misread, a server gated at call time, a staging endpoint mistaken for production) is corrected within 48 hours with an anchored retraction. A grade nobody can fake includes us.
This policy is versioned and anchored. It is modeled on the established practice of coordinated vulnerability disclosure (ISO/IEC 29147, CERT/CC, and the public security research community). Vendors: to dispute a finding, trigger a re-scan, or reach the security team, contact security@conformant.io.