Security and safe use
Reviewed September 30, 2026
Public educational MCP tools do not read private applications, create leads, store profiles or fetch arbitrary caller-supplied URLs. Inputs are validated, request bodies are bounded, and the deployed service uses hosting-managed OAuth.
The service uses a bounded per-runtime rate limiter; it is not a distributed global quota. No universal privacy-compliance or encryption-bit-depth certification is claimed.
Qualification uses the existing website and requires an explicit consent action before submission. Production database permissions and server-side lead controls are under review. Do not submit identity or banking documents through public educational tools.