Security and safe use

Reviewed September 30, 2026

Public educational MCP tools do not read private applications, create leads, store profiles or fetch arbitrary caller-supplied URLs. Inputs are validated, request bodies are bounded, and the deployed service uses hosting-managed OAuth.

The service uses a bounded per-runtime rate limiter; it is not a distributed global quota. No universal privacy-compliance or encryption-bit-depth certification is claimed.

Qualification uses the existing website and requires an explicit consent action before submission. Production database permissions and server-side lead controls are under review. Do not submit identity or banking documents through public educational tools.