cMCPby IT-Labs Book a demo
Security and governance

Deny by default, enforced where the data lives

A shared memory is only useful if people trust it. This page separates plainly what is built today from what is still on the roadmap.

Built today

Controls available now

These are built and running in our live pilot.

Database-enforced isolation Available now

PostgreSQL row-level security on every table. Tenant isolation is enforced by the database, not only by application code.

Deny-by-default permissions Available now

A permission service checks every request. Search results are re-checked against permissions one by one before they are returned.

Caller rights Available now

AI apps get the smaller of the person's rights and a time-limited grant. An agent never has more rights than its user.

Audit in the same transaction Available now

Every allow and deny is recorded with who, where, which app and which model, and written in the same transaction as the change itself.

Client walls and audience labels Available now

A client's memory is never returned to another client's work. Labels mark memory internal, restricted (named people only, bots never read) or external_ok.

Data, not instructions Available now

Memory is returned labelled as data. Text that looks like instructions is flagged and cannot be bulk-approved.

Strong sign-in Available now

OAuth 2.1 sign-in. People use a password plus an authenticator code. Access tokens are short-lived.

Kill switches Available now

Suspend an AI app or bot immediately.

Versioning and backups Available now

Every update keeps the previous version. Daily backups are encrypted.

Your data

Your data stays in your infrastructure

cMCP runs where you decide. In a pilot we run it for you in your cloud, or you self-host it on your premises. Fact extraction uses a small model running on your own server, so nothing needs to leave your infrastructure.

Connectors only read, and only from the sources you choose. By design, cMCP never writes into outside systems.

Built on

  • PostgreSQL with row-level security
  • Open-source components with permissive licences
  • Docker-based deployment
On the roadmap

Not available yet

We would rather you hear this from us. These items are planned and are not part of cMCP today.

Planned controlStatus
SSO with Microsoft or Google, and SCIM provisioningRoadmap
Customer-managed encryption keys (BYOK)Roadmap
PII detection and maskingRoadmap
Hash-chained, exportable auditRoadmap
Retention policies per scopeRoadmap
Break-glass access with loggingRoadmap
Independent penetration test and SOC 2 readiness workRoadmap
Large-scale load testingRoadmap

Where we stand. cMCP is a pilot-stage product. It has not been independently audited or penetration tested, and we do not claim any compliance certification. If your security review needs more than that today, tell us what you need and we will say honestly whether the pilot can meet it.

Responsible disclosure

Found a vulnerability?

Please email sales@it-labs.in with enough detail to reproduce the issue. We will acknowledge your report, investigate it and keep you informed. Please give us reasonable time to fix a problem before sharing it publicly, and do not access data that is not yours.

Questions from your security team?

Book a session and we will walk through the architecture, the controls above and the gaps.