Atom Flux logoWORKFOUNDRYPilot privacy
Components meeting through an explicit checked interface

Ingress Shield // Current pilot privacy information · 7 September 2026

IDENTITY WITHOUT A NEW PASSWORD.

Plain-language information about the protected MCP platform and the closed onboarding work still required before external access.

01 // current state

Protected platform. No external pilot access yet.

The WorkFoundry MCP endpoint has active hosted protection. However, no external OAuth client, pilot invite, user account, entitlement or browser-client acceptance has been completed. An external user should not be told that they can access the MCP yet.

This page records the current data boundary for the closed onboarding work. It is not a completed external-pilot privacy notice or a substitute for separately agreed data-processing terms for a webhook route or sandbox receiver.

02 // browser sign-in design

Use an existing identity provider.

The closed-pilot onboarding design uses Auth0-brokered Google or Microsoft browser sign-in. WorkFoundry does not receive or store your Google or Microsoft password.

Auth0 and the selected social identity provider handle browser identity. Standard social sign-in creates an identity record in Auth0 from provider profile data. The intended WorkFoundry gateway record is pseudonymous rather than an email or profile record.

Public self-service access and dynamic client registration are disabled. An external identity would prove identity, but would not itself grant MCP access.

A bounded gateway separating identity from application access

03 // intended data boundary

Only the access-control minimum.

[INVITE]

Opaque lifecycle record

The intended coordinator stores an opaque invite-code digest, opaque account digest, free/preview tier, expiry, redemption and revocation state, then a digest of the authenticated subject when bound.

[AUDIT]

Redacted operational record

The bounded audit design records account digest, operation, allowed caller-owned request ID, result class and time. A caller-supplied request ID is not assumed to be anonymous.

[NOT HELD]

No gateway profile

The design excludes passwords, email/profile data, provider or access tokens, raw invite codes, raw MCP arguments/payloads, private endpoints, result bodies and client configuration.

A checked interface between services

04 // sharing, transfers and retention

Controls still required before onboarding.

Auth0 and the selected Google or Microsoft identity provider are implicated by the intended browser identity path. Auth0's development tenant reports a United States data region.

Processor roles, transfer safeguards, service-provider terms and operational retention periods have not yet been established for an external pilot. They must be agreed and published before any external-user onboarding begins.

The technical design is bounded and redacted, but a bounded design is not a completed privacy, retention or transfer control.

05 // next privacy gate

Close the governance before inviting a pilot.

Before external onboarding, WorkFoundry must establish and publish its lawful basis, privacy-request channel, retention schedule, processor/transfer arrangements and a review or appeal route for automated invitation eligibility decisions.

Until then, do not send passwords, access tokens, private keys, confidential payloads or other secrets through a public contact route. You can raise a general concern with the UK Information Commissioner's Office at ico.org.uk.