MCP Rigor logo MCP Rigor

Security and evidence retention

Production required: review this page before enabling remote data, custom extensions, or persistent CI evidence.

Implemented controls

Residual risks

DNS validation followed by the platform fetch still has a rebinding window because the current implementation does not yet pin the resolved address through a custom dispatcher. ExcelJS preflight does not fully inspect ZIP central-directory expansion ratios. Use trusted QA data endpoints and files until strict broker/container backends are available.

Worker threads are not a hard sandbox for hostile plugins.

Retention recommendation

By default, do not retain raw authorization headers, environment variables, URI queries, downloaded data files, or full sensitive MCP payloads.

Suggested policy:

Deletion procedures should cover CI artifacts, object storage, developer workstations, backups, caches, and third-party telemetry. Incident holds need an owner, reason, scope, and expiry.