Apache 2.0Pre-1.0 · managed cloud and self-hosted previewsRead the open-source commitment

Security and trust

Treat every MCP server as a trust boundary.

LiteMCP Composer is designed around least privilege, explicit identity, policy at discovery and execution, credential isolation, request correlation, and portable audit evidence.

Enforcement boundaries

Defense is repeated, not implied.

01

Tenant boundary · Available now

Every management request resolves a tenant on the server; tenant-scoped repositories enforce it again.

02

Identity boundary · Preview

Gateway sessions bind the authenticated subject, organization, composition, environment, expiry, and revocation state. Client hints are not yet a cryptographic binding.

03

Discovery boundary · Available now

Policy removes capabilities the current principal is not allowed to discover.

04

Execution boundary · Preview

The gateway re-evaluates policy and approval state before every upstream invocation.

05

Credential boundary · Planned

The planned broker will issue short-lived execution material without exposing durable provider secrets. Connected accounts and the credential vault are not implemented.

06

Network boundary · Preview

The Node executor pins validated public addresses and bounds HTTP behavior. Equivalent managed cloud egress proof and isolated stdio execution remain outstanding.

Responsible disclosure

Report privately. Patch publicly.

Use GitHub private vulnerability reporting. Include affected versions, reproduction detail, impact, and a safe contact channel.

Acknowledgement
A response target has not yet been contractually published.
Coordination
Reports should remain private until a fix and advisory can be coordinated.
Advisories
Confirmed issues will use public security advisories and affected-version guidance.
Certifications
No certification, audit completion, or compliance attestation is claimed at this stage.