Security Policy
Last updated: June 7, 2026
Our Commitment
Security is fundamental to how we build and operate DigitalPipe. We are committed to protecting your data and MCP connection information.
1. Infrastructure Security
- All data transmitted through our service is encrypted in transit using TLS 1.2+
- We use industry-standard cloud infrastructure with SOC 2 Type II: in progress
- Network isolation protects our backend systems from unauthorized access
- Regular security patches and updates are applied to all systems
- Firewall rules restrict access to necessary ports only
2. Data Protection
DigitalPipe offers configurable inspection modes so you choose how much visibility you need:
Metadata-only(default)
Timing, sizes, tool names, and status only. No payload content stored.
Sampled inspection
Payloads scanned in-memory for flags (PII, injection patterns). Only flagged excerpts retained, with redaction.
Full payload
Complete request/response retention for audit. Documented retention period and redaction options apply.
On payload integrity: DigitalPipe never modifies payloads in transit. We can terminate sessions on your instruction or your configured policy, but we do not alter request or response content.
- Read-Only Monitoring: We observe traffic but never modify your MCP connections
- Data Retention: Telemetry is retained for 30 days; audit logs for 12 months
- Access Controls: Role-based access limits who can view or manage data
- No Third-Party Data Sharing: Your data is never sold or shared with advertisers
3. Connection Security
- All MCP proxy connections use encrypted channels
- Connection kill-switch works in real-time to terminate any session
- PII detection flags potentially sensitive data in connections
- Injection detection identifies potentially malicious content
- Audit trail records all connection events for compliance
- Configurable fail-open/fail-closed behavior — see Availability docs
4. Network Isolation
Our gateway infrastructure operates in isolated network segments. Egress traffic is controlled through proxy servers to prevent unauthorized data exfiltration.
5. Monitoring & Detection
- 24/7 monitoring of service availability and performance
- Automated alerting for anomalous connection patterns
- Real-time dashboards show connection status and throughput
- Packet loss monitoring ensures reliable connections
6. Authentication & Access
- Secure authentication required for all user accounts
- Password requirements enforce minimum complexity
- Session tokens expire after reasonable inactivity periods
- API keys provide programmatic access with scoped permissions
7. Incident Response
In the event of a security incident:
- We will notify affected users within 72 hours of discovery
- We will investigate the scope and cause of the incident
- We will take immediate steps to contain and remediate the issue
- We will provide regular updates until resolution
- We will conduct a post-incident review to prevent recurrence
8. Responsible Disclosure
We welcome responsible security research. If you discover a vulnerability, please:
- Email us at [email protected]
- Include detailed description of the vulnerability
- Do NOT exploit vulnerabilities beyond what is necessary for verification
- Give us reasonable time to address the issue before public disclosure
9. Compliance
We are working toward the following certifications:
- SOC 2 Type II (in progress)
- GDPR compliance for EU customers
- CCPA compliance for California residents
10. Your Responsibilities
While we implement robust security measures, you also play a role:
- Use strong, unique passwords for your account
- Rotate API keys regularly
- Review connected MCP servers periodically
- Report suspicious activity immediately
- Keep your contact information up to date
11. Security Updates
For critical security updates, we may contact you via email. Please ensure your account email is current and monitored.
12. Contact Security Team
For security concerns, vulnerability reports, or questions about our security practices:
Email: [email protected]
Response Time: We aim to respond within 48 hours
