Security & privacy

Remote access does not mean remote authority.

MCPDO keeps capability ownership, policy, approval, verification, and activity at the runtime that executes the work.

Least privilege

Runtime-specific capabilities remain separate. Cloud relays requests but cannot silently broaden Local policy or bypass exact approval.

Secrets

Do not place account tokens, OAuth tokens, private keys, bootstrap secrets, or pairing secrets in support messages, screenshots, logs, or repositories.

WordPress privacy

Core V1 is self-hosted-first with no mandatory TopHive telemetry or cloud proxy. The site stores its own operational records and OAuth validation hashes.

Operational rules

Execution success and verification success are separate outcomes. A successful command is not treated as proof that the desired state was achieved.
Production Cloud must use a trusted HTTPS origin. Device relay sessions authenticate the paired device and Hostinger production uses outbound HTTPS polling.
Bootstrap access is only for initial account provisioning. Remove or rotate bootstrap secrets after setup or any suspected exposure.