Skip to content
MCP Security Lab

Privacy notice (draft)

What MCP Security Lab stores about you, what it never stores, and how to delete it.

Draft, pre-launch, not legal advice. This is a working draft dated 9 October 2026. It will change before launch.

Who this covers

This notice covers the MCP Security Lab website, the security demo, user accounts and the waitlist. The operator’s legal name and address will be added before launch. Until then, reach us through the contact form.

What we store

  • Account: your email address and a hash of your password made with scrypt. The password itself is never stored.
  • Session: a random token kept in a cookie. We store only a SHA-256 hash of it.
  • Workspace data: the servers you add and their endpoint URLs, the policies you write, and your assessment runs, findings, evidence and reports.
  • Discovered MCP metadata: what your server returned during read-only discovery, such as its name and version, tool names, descriptions and schemas, resource and prompt metadata, and a list of the protocol methods exchanged.
  • Audit events: records of security-relevant actions, such as sign-ups, sign-ins, failed sign-in attempts with the email address entered, discovery attempts, report exports and waitlist sign-ups. Some include the IP address the request came from.
  • Waitlist entries: your email address and, if you give them, your role and note.

What we do not store

Bearer tokens you supply for discovery. A token is held in memory for that discovery only, scrubbed from error messages, and never stored.

Cookies

The only cookie is a session cookie that keeps you signed in. It is marked httpOnly, so scripts on the page cannot read it. There are no tracking, analytics or advertising cookies.

How we use data

  • To run the discovery, assessments and reports you ask for.
  • To keep accounts secure and to limit abuse, using the audit events above.
  • To reply to your messages and to tell waitlist members about early access.

We do not sell personal data, and we do not use it for advertising.

Who processes it

The service runs on cloud hosting and managed Postgres providers, which store and process data so that the service can run.

“Ask Claude” builds a redacted prompt in your browser for you to paste into your own Claude account; we send nothing to Anthropic. On deployments where in-app explanations are switched on, clicking “Explain with Claude” sends the redacted context of that one finding to Anthropic’s API. Nothing is sent unless you ask. In-app explanations are switched off on this deployment.

Deleting your data

You can delete your account from Settings. This removes your account and sessions and, for a workspace you own, its servers, discovered metadata, policies, runs, findings, evidence, reports and the audit events linked to your account or workspace. Failed sign-in records keep only the email address entered and are used for rate limiting.

To remove a waitlist entry, or for any other request about your data, use the contact form.

Not decided yet

  • The operator’s legal name and address.
  • The legal bases for processing, and the rights that apply where you live.
  • How long audit events and waitlist entries are kept.

Changes

This is a draft. The final notice will be published before launch.