Security controls without security theatre
MCXAI uses restrictive browser headers, server-side validation, private-by-default job data and isolated processing interfaces. Provider-backed paths remain disabled until their dependencies are configured.
Web controls
Requests are validated by type and size. Sensitive server configuration is not exposed to the browser, and private routes send noindex and no-store directives.
Files and URLs
The production design requires signed private storage, MIME and signature checks, malware scanning, timeout limits and private-network blocking for URL ingestion.
Report a vulnerability
Send reproducible details to security@mcxai.com. Do not retain, alter or disclose data that is not yours.