Privacy Policy
Effective October 9, 2026
Agent Trust provides MCP discovery, historical selection evidence, task-specific provider review, and optional metadata analysis. This policy describes the hosted service at https://mcp-selection-lab-production.up.railway.app.
Product evidence and catalog data
- The Explore catalog displays locally imported public metadata from the Official MCP Registry. Browsing the catalog does not contact the listed provider endpoints.
- Registry data quality grades describe fields in those catalog records. They are not safety ratings, and they are not used as Trust Live recommendations.
- Evidence Lab displays bounded historical benchmark measurements. Trust Live presents recorded provider evidence and task-specific review results; the page does not call provider business tools.
- The optional metadata scan is separate: when submitted, it makes the public MCP discovery requests described below and creates a public-by-link report.
What the service processes
- A public MCP URL that you submit.
- Public MCP discovery metadata returned by that server, including tool names, descriptions, and schemas needed for routing-readiness evaluation.
- For the caller-supplied holdout endpoint, natural-language test prompts, expected tool names, optional candidate descriptions, and the caller's freeze attestation needed to calculate the requested receipt.
- Operational scan metadata such as creation time, normalized target URL, referral/source bucket, scan classification, prior-report linkage, status, and aggregate routing metrics.
- Basic network and request metadata may be processed by our hosting infrastructure as necessary to deliver, secure, and troubleshoot the service. We do not intentionally include client IP addresses or authentication secrets in public scan reports.
What the hosted service does not do
- It does not call the target MCP server's business tools.
- The free generated-readiness scan and caller-supplied deterministic holdout endpoint do not require or invoke a model-provider API.
- It rejects MCP URLs containing URL credentials, query strings, fragments, and local/private-network targets.
- It does not intentionally request personal data. Do not submit secrets, credentials, personal data, private endpoints, or sensitive real-world content in holdout prompts.
Reports and retention
Successful standard scans create public-by-link reports using unguessable report IDs. A report may contain the submitted public MCP URL, discovered public tool metadata, routing metrics, and candidate description-only routing fixes. Standard reports may be retained until operational cleanup; the service currently does not promise an automatic deletion period.
The /api/holdout endpoint is different: Selection Lab does not write caller-supplied holdout prompts or its receipt into the standard public-report database. The request and response are still processed by the application and hosting infrastructure to serve the request, so callers should not submit secrets or personal data.
Third-party processing
The hosted service runs on Railway infrastructure. When you request a scan or holdout evaluation, the target public MCP server receives the discovery requests required for initialize and tools/list. The deterministic hosted evaluations do not send target metadata or caller-supplied holdout prompts to a model provider.
Use of information
Processed information is used to operate evaluations, generate and retrieve reports or receipts, measure service reliability and usage, prevent abuse, and improve routing-readiness analysis. We do not sell scan or holdout data to advertisers.
Your choices
Submit only public MCP metadata and non-sensitive test prompts. Standard scan reports are public-by-link; caller-supplied holdout receipts are returned to the caller without being inserted into the standard public-report database.
Changes
We may update this policy when the service changes. The effective date above identifies the current version.