Privacy
Written by the operator in plain language; not yet reviewed by a lawyer.
What we collect and why
- Public server metadata. When we scan a public MCP endpoint we record what it returns to read-only requests: server name and version, tool names and schemas, headers, TLS details. We keep the scan output as evidence for the report it produced.
- Contact details for outreach. Maintainer or owner contact details from public sources (registries, repositories, websites). Each outreach email says where we got your address and how to stop further email. Opt-outs are honoured within ten business days, usually the same day, and kept on a suppression list so you are not contacted again.
- Customer records. Names, billing details handled by our payment provider, correspondence, signed scopes, reports and evidence. Kept for the retention periods in our records policy, which follow tax and evidence requirements.
- This website. Static pages with no analytics scripts and no tracking pixels. The host may keep standard server logs.
What we do not do
We do not sell or share contact data. We do not run automated phone or voice contact. We do not accept health data, privileged legal material or regulated datasets.
Your choices
Email the address on the opt-out page to stop outreach, to ask what we hold about you or your organisation, or to request deletion. Deletion requests are answered within 30 days with a statement of what was deleted and what was retained and why (evidence hashes and manifests for delivered work are retained).