PRIVACY & RETENTION
Signal without surveillance.
The public canary is designed to observe MCP behavior while minimizing what it collects and publishes.
Stored
- Timestamp, MCP method, requested canary tool, inferred risk, and policy decision.
- A self-declared client name/version, if supplied by the MCP client.
- Otherwise, a pseudonymous behavioral identifier derived from the client header.
- A one-way hash of the source address. Raw source IP addresses are not stored.
Not stored
- Tool arguments, secrets, credentials, customer data, or content returned by an upstream system.
- Raw IP addresses or a raw user-agent string for unattributed clients.
Public dashboard
Only public-eligible MCP telemetry is shown. Operational health checks and requests marked as Observatory checks are excluded. The dashboard intentionally presents pseudonymous, behavior-level signals—not a list of people.
Retention
Telemetry, decisions, alerts, identities, and session records expire after 30 days and are purged on a daily schedule.
Do not send sensitive information to a public research canary. The tools are intentionally synthetic and cannot access real systems.