AGENT OBSERVATORYPUBLIC BETA LIVE CAPTURE

PRIVACY & RETENTION

Signal without surveillance.

The public canary is designed to observe MCP behavior while minimizing what it collects and publishes.

Stored

  • Timestamp, MCP method, requested canary tool, inferred risk, and policy decision.
  • A self-declared client name/version, if supplied by the MCP client.
  • Otherwise, a pseudonymous behavioral identifier derived from the client header.
  • A one-way hash of the source address. Raw source IP addresses are not stored.

Not stored

  • Tool arguments, secrets, credentials, customer data, or content returned by an upstream system.
  • Raw IP addresses or a raw user-agent string for unattributed clients.

Public dashboard

Only public-eligible MCP telemetry is shown. Operational health checks and requests marked as Observatory checks are excluded. The dashboard intentionally presents pseudonymous, behavior-level signals—not a list of people.

Retention

Telemetry, decisions, alerts, identities, and session records expire after 30 days and are purged on a daily schedule.

Do not send sensitive information to a public research canary. The tools are intentionally synthetic and cannot access real systems.