Security and privacy
This repository contains public documentation only. Its MCP endpoint:
- requires no authentication;
- exposes no write tools;
- reads only build-time indexed documentation paths;
- does not fetch arbitrary URLs or filesystem paths;
- contains no product or customer data; and
- is deployed separately from the application backend and product MCP.
Requests are bounded and validated before protocol dispatch. Browser origins and request hosts are checked against explicit production, preview, development, and environment-configured allowlists.