Security

Security controls without security theatre

MCXAI uses restrictive browser headers, server-side validation, private-by-default job data and isolated processing interfaces. Provider-backed paths remain disabled until their dependencies are configured.

01

Web controls

Requests are validated by type and size. Sensitive server configuration is not exposed to the browser, and private routes send noindex and no-store directives.

02

Files and URLs

The production design requires signed private storage, MIME and signature checks, malware scanning, timeout limits and private-network blocking for URL ingestion.

03

Report a vulnerability

Send reproducible details to security@mcxai.com. Do not retain, alter or disclose data that is not yours.