Trust boundary
By default, nothing crosses the boundary to mcpindex.
Read Fig. 03 as text
+- YOUR HOST ---------------------------------------+
| |
| [ agent ] <-> [ mcpindex gate ] <-> [ pin store ]|
| local disk |
+-----------+---------------------------+-----------+
| |
DEFAULT | nothing crosses to | tools/call + your credentials
| mcpindex. the tier-0 +-------------> [ MCP server ]
| contract-diff runs here. | passed through untouched.
| | the gate holds no keys.
OPT-IN | contract hash ------------------------> [ mcpindex edge - US ]
| a deterministic hash of the public tool contract
OPT-IN | salted HMAC fingerprint --------------> [ drift network ]
| + change type, safety flag, hour-rounded time. fail-open.
|
NEVER X tokens - arguments - schema bodies - descriptions
X URLs - server names - tool names - your call dataInside your host sit the agent, the mcpindex gate and a local pin store. By default nothing crosses to mcpindex because the tier-0 contract diff runs locally. The tool call and your credentials pass through untouched to the MCP server and the gate holds no keys. Two optional opt-in crossings exist: a contract hash to the mcpindex US edge, and a salted HMAC fingerprint to the drift network. Tokens, arguments, schema bodies, descriptions, URLs, server names, tool names and your call data never cross.
Licensed CC BY 4.0. Use it anywhere, including commercially. Keep the credit.
Paste under the figure. That is the whole licence obligation.
<a href="https://mcpindex.ai/diagrams/trust-boundary">Trust boundary - mcpindex.ai</a> (CC BY 4.0)Standalone image/svg+xml. Vector, editable, no stylesheet needed.
https://mcpindex.ai/diagrams/trust-boundary/svgLast reviewed 2026-07-27
mcp security architecture · mcp trust boundary · does mcpindex phone home · mcp gate data flow