SECURITY
MCP Verify security and disclosure
Security posture, disclosure expectations, and data-handling boundaries for MCP Verify.
Search • Governance: TrustOps / Gateway / Compare • Publishers: Claim / Badges / Profiles • Research: Trust Index / Rankings • Docs: Methodology / Security / MCP API • Pricing • Sign in
More: About • Changelog • Status • Shortlists • Digests • RSS • RSS XML • Discovery sources • Scan my server • Submit repo • GitHub Action • Docs Compiler • Agent commerce
Data boundaries
Verify stores public metadata, validation results, scoring evidence, and first-party product telemetry. It must not store real secrets.
- Detected secrets are represented as [REDACTED].
- Private/admin pages are noindex and require appropriate credentials.
- Publisher credentials and external tokens are not exposed in public reports.
Responsible disclosure
If a Verify page exposes sensitive information or a server result appears materially wrong, contact the operator with the affected URL and evidence.
- Use the server claim and maintainer annotation flows for profile corrections where possible.
- Use public evidence and policy exports for buyer review; do not treat one fresh validation as a complete security audit.