Specification and documentation
Use the public VCP-Spec issue tracker for errors, unclear protocol wording, broken or missing examples, and proposed amendments.
Open a specification issueFeedback and support
Include the page URL, any version shown on the page or in the footer, your browser or runtime, and the steps that reproduce the problem. Do not place credentials, private context, personal data, or undisclosed vulnerability details in a public report.
Use the public VCP-Spec issue tracker for errors, unclear protocol wording, broken or missing examples, and proposed amendments.
Open a specification issueUse the public VCP-SDK issue forms for reproducible implementation, package, CLI, WebMCP, and conformance defects.
Choose an SDK issue formEmail a description and the affected page to security@creedspace.com, the one address the site uses for private reports. Your name and other details are optional.
Email the site teamKeep suspected vulnerabilities private. Email security@creedspace.com; the security policy explains what to include, what not to send, and the response targets.
Read the security policyPublic reports are triaged by repository maintainers. Security reports follow the interim acknowledgment and severity targets in the security policy; a critical issue, for example, should be acknowledged within 4 hours. The current releases come with no paid support, service-level agreement, or promise of continuous staffing.
Applies to the VCP 3.1 source baseline and the published SDK 4.2.0. Last updated 26 September 2026.