Opaque lifecycle record
The intended coordinator stores an opaque invite-code digest, opaque account digest, free/preview tier, expiry, redemption and revocation state, then a digest of the authenticated subject when bound.

Ingress Shield // Current pilot privacy information · 7 September 2026
Plain-language information about the protected MCP platform and the closed onboarding work still required before external access.
01 // current state
The WorkFoundry MCP endpoint has active hosted protection. However, no external OAuth client, pilot invite, user account, entitlement or browser-client acceptance has been completed. An external user should not be told that they can access the MCP yet.
This page records the current data boundary for the closed onboarding work. It is not a completed external-pilot privacy notice or a substitute for separately agreed data-processing terms for a webhook route or sandbox receiver.
02 // browser sign-in design
The closed-pilot onboarding design uses Auth0-brokered Google or Microsoft browser sign-in. WorkFoundry does not receive or store your Google or Microsoft password.
Auth0 and the selected social identity provider handle browser identity. Standard social sign-in creates an identity record in Auth0 from provider profile data. The intended WorkFoundry gateway record is pseudonymous rather than an email or profile record.
Public self-service access and dynamic client registration are disabled. An external identity would prove identity, but would not itself grant MCP access.

03 // intended data boundary
The intended coordinator stores an opaque invite-code digest, opaque account digest, free/preview tier, expiry, redemption and revocation state, then a digest of the authenticated subject when bound.
The bounded audit design records account digest, operation, allowed caller-owned request ID, result class and time. A caller-supplied request ID is not assumed to be anonymous.
The design excludes passwords, email/profile data, provider or access tokens, raw invite codes, raw MCP arguments/payloads, private endpoints, result bodies and client configuration.

04 // sharing, transfers and retention
Auth0 and the selected Google or Microsoft identity provider are implicated by the intended browser identity path. Auth0's development tenant reports a United States data region.
Processor roles, transfer safeguards, service-provider terms and operational retention periods have not yet been established for an external pilot. They must be agreed and published before any external-user onboarding begins.
The technical design is bounded and redacted, but a bounded design is not a completed privacy, retention or transfer control.
05 // next privacy gate
Before external onboarding, WorkFoundry must establish and publish its lawful basis, privacy-request channel, retention schedule, processor/transfer arrangements and a review or appeal route for automated invitation eligibility decisions.
Until then, do not send passwords, access tokens, private keys, confidential payloads or other secrets through a public contact route. You can raise a general concern with the UK Information Commissioner's Office at ico.org.uk.