Terms of use (draft)
The rules for using MCP Security Lab during early access.
Draft, pre-launch, not legal advice. This is a working draft dated 9 October 2026. It will change before launch.
Early access
MCP Security Lab is in early access. Features may change, break or be removed. No billing is enabled.
Authorized use only
Connect only targets you own or are authorized to test. When you connect a target, you confirm that you have that authorization. We may refuse or remove a target if we have reason to believe you do not.
No attacks on third parties
- Do not use the lab to probe, scan or attack systems you are not authorized to test, or to help anyone else do so.
- Do not try to get around the read-only boundary. Against a remote target, the lab reads metadata and refuses to call tools. Do not try to make it do more, or to reach private networks or other blocked addresses through it.
- Do not use findings, scenarios or reports to attack anyone.
Results are indicators, not certifications
Scores, readiness labels and reports describe a tested configuration at a point in time: one server version, one policy version and a defined set of scenarios. They are not certifications, audits or penetration tests. A passing result does not mean that an agent connected to your server cannot cause harm.
No warranty
The lab is provided as is, without warranties of any kind, to the extent the law allows. You are responsible for the decisions you make based on its results.
Your data
How personal data is handled is described in the privacy draft.
Not decided yet
- The operator’s legal name and address.
- Governing law, liability, and how disputes are resolved.
- Terms for paid plans, if any are introduced.
Contact
Questions about these terms: use the contact form.