Procurement summary · Reviewed July 2026

Trust, with the gaps included.

A compact, factual view of Passport's data flow, implemented controls, recovery evidence, and current assurance status. This is not a certification, audit report, penetration-test report, or contractual SLA.

Need this in your review workflow?

Use the agent-readable Markdown summary or contact us for procurement and signature questions.

Open MarkdownContact
Credentials stay at the gatewayProtected upstream and identity secrets are encrypted at rest.
Operational telemetry excludes contentNo MCP inputs, outputs, prompts, files, cookies, auth headers, or bodies.
Assurance gaps are explicitNo SOC 2, independent penetration-test report, or contractual SLA yet.
Evidence room

Open the category your review needs.

Everything here describes the product as deployed today. What we have not earned yet is tagged, not hidden.

Data handling
What Passport stores and excludesThe governed-call trail records who, client, MCP, tool, outcome, and timing. It excludes MCP inputs and outputs, prompts, files, cookies, authorization headers, query strings, and response bodies. Read the privacy policy.
Credentials stay at the gatewayUpstream and identity-provider secrets are AES-256-GCM encrypted. Long-lived session validation records, bridge credentials, and agent keys are retained only as one-way SHA-256 digests. Desktop device-flow approval uses a 10-minute encrypted delivery handoff.
Legal
DPA and SCC termsThe standard DPA and SCC terms are public. Enterprise support, residency, recovery, and service commitments beyond those terms must be agreed explicitly with hello@passportmcp.com.
Terms of serviceRead the terms.
Subprocessors
Who we rely onThe current infrastructure providers and their roles are listed on the Subprocessors page.
Infrastructure
Self-hostingRun Passport as one container plus Postgres in your own VPC, with your own keys and the identical gateway, catalog, and controls. See the self-host guide.
Live statusThe status page is a live, self-reported component view. Five-minute external probes cover health, database readiness, status, and a read-only product contract.
ChangelogDated product changes ship in the public changelog.
Recovery is exercisedA recurring synthetic drill restores a logical Postgres backup and decrypts protected data. Separate drills exercise two replicas and bounded gateway load. Synthetic restore evidence does not prove a hosting provider's production backup/PITR toggle or retention setting; operators verify those separately.
Access controls
Gateway enforcementServer-side passes, per-tool controls, member approvals, secret and injection guardrails, client selection, append-only user activity, and a separate admin audit trail. Full detail on the security page.
Identity, tenancy, and egressOAuth 2.1/PKCE with rotation, client/resource binding, and inactivity expiry; version-guarded tenant writes; SSRF and redirect-hop validation; and production configuration that refuses unsafe startup.
Dated MCP handshakes, pinned open toolsetsCommitted catalog evidence distinguishes a point-in-time protocol check from uptime, endorsement, or a security guarantee.
Vulnerability reporting
How to reportEmail security@passportmcp.com with what you found and how to reproduce it. The machine-readable policy is at /.well-known/security.txt. We acknowledge within 2 business days.
Independent assurance
SOC 2In progress — not yet earnedNo SOC 2 report yet.
External penetration testIn progress — not yet earnedNo independent third-party penetration-test report yet.
Uptime history and SLAIn progress — not yet earnedNo independent third-party uptime history or contractual SLA yet. The status page is a live, self-reported component view.