Credentials protected. Access under control.
Passport puts one governed gateway between the AI clients people use and the MCP servers they connect. Members connect once and go, while every call stays scoped, attributed, and revocable.
Our security posture, DPA and SCCs, subprocessors, live status, and current assurance gaps are public.
The AI client never needs the upstream credential.
Passport evaluates access before presenting a provider credential to the MCP server on the user's behalf.
Go deeper where your review needs it.
The important outcomes come first. Implementation details remain available for security and procurement teams.
Credentials
Isolation
Catalog and gateway controls
Accountability
Deployment choices
Reporting a vulnerability
No SOC 2 report, independent third-party penetration-test report, independent uptime history, or contractual SLA/RTO/RPO is published during early access. The Trust summary keeps those boundaries explicit.
The standard DPA and SCC terms are public. Full data-handling details: Privacy. Who we rely on: Subprocessors.