What this preview does
The downloadable prototype is a static content site with fictional workspace data. It does not accept credentials, process payment, send forms, access the ad database, or operate an MCP server.
Production controls to verify
Before publishing security claims, verify transport protection, credential and token handling, workspace authorization, least-privilege access, logging, backups, deletion behavior, dependency management, and an incident-response process. A checklist is not proof that these controls exist.
MCP authorization boundaries
The production design should restrict each connection to its authorized workspace and approved tools, validate tokens, support revocation, and avoid exposing secrets to an AI client. Research retrieval must not silently grant access to billing, user administration, or private advertising accounts.
Retrieved content is untrusted
Ads and landing-page text may contain instructions or misleading content. The application should preserve the boundary between data and executable instructions. No retrieved ad should cause a secret to be shared or a privileged action to run.
Certifications and claims
No SOC 2, ISO certification, penetration-test result, data-residency guarantee, zero-retention promise, or service-level agreement is asserted in this draft. Publish only evidence-backed statements when the relevant control or assessment exists.
Reporting a security issue
Establish [VERIFIED_SECURITY_CONTACT] and a vulnerability-handling process before launch. Request a concise description and reproduction details without encouraging access to other users’ data. No bug bounty or guaranteed response window has been approved.