PRIVACY

Your configuration stays in your browser.

MCP Config Guard is a static website. Scanning, parsing, scoring, redaction, copying, and report generation happen on your device.

Configuration data

The scanner does not upload, transmit, or store pasted configuration content. It does not require an account and does not use a backend scan API. Clearing the field or closing the tab removes the working input from the page.

Network requests

The site loads its HTML, CSS, JavaScript, favicon, and manifest from the same hostname. The scanner does not contact MCP servers, package registries, or credential providers. Hosting infrastructure may process ordinary HTTP metadata needed to deliver the website, such as IP address, timestamp, path, and user agent.

Reports

Copied and downloaded reports are created locally. Evidence is redacted, but you should still review a report before sharing it because server names, paths, and configuration context may be sensitive.

Security note

If a real credential has already been pasted into other websites, chat systems, logs, or repositories, rotate it. Local processing here cannot undo earlier disclosure.

Return to the private scanner

Open MCP Config Guard →