The Bitsight Model Context Protocol (MCP) server enables AI assistants to call Bitsight's APIs on your behalf. This article explains how your data is handled, what Bitsight stores and logs, and the safeguards in place to protect your information. For Bitsight's broader AI use policy, see the Bitsight AI use policy.
At a glance
Does Bitsight train AI models on my data or API calls?
No. Nothing flowing through the MCP is used to train, fine-tune, or improve any AI or machine learning model. Your API calls, prompts, and responses are never added to any training set. This data remains on your machine only.
Does the MCP store any additional data I provide?
No. Your data is passed through per request and not persisted beyond the time required to fulfill that request.
Can the MCP see data I'm not already entitled to?
No. The MCP uses your own identity and respects your Bitsight access controls, access groups, and product subscriptions. It can only access the data you're already authorized to view.
Are my requests and responses logged?
Not by default. Bitsight logs operational metadata only — tool name, timestamps, session IDs, account identifiers, and service metrics. The contents of your requests and responses are not logged.
Is there a safeguard before an AI changes my data?
Yes. Every operation that modifies data requires explicit confirmation before it executes. An AI cannot silently change your data.
How the MCP works
The MCP operates as a stateless proxy. When your AI assistant makes a request, the MCP validates your credentials, securely forwards your authentication token to the appropriate Bitsight API, and returns the response. The MCP does not store your data beyond what is required to process the immediate request.
Because the MCP uses your credentials, it adds no new data access. You can only reach data you're already entitled to see. A small set of generic tools allows the assistant to discover and call any of Bitsight's 1,000+ API operations, with all calls routed strictly against Bitsight's official API schemas.
Data modification and confirmation
Any operation that modifies data is blocked on the first attempt and only executes after an explicit, single-use confirmation that is valid for five minutes. This prevents an AI from silently changing your data.
Service accounts and automation you provision can be allowlisted to skip this confirmation requirement for specific pre-approved operations.
Data storage and logging
What Bitsight stores permanently
Only public documentation — API schemas and help-center articles — and their search index for performance optimization.
What Bitsight never stores
Your ratings, findings, Cyber Threat Intelligence data, prompts, or credentials. Credentials are validated per request and held in memory for at most five minutes.
What Bitsight logs (operational telemetry only)
Tool name, timestamps, session and request IDs, your account identifier, upstream status and latency, usage counts, and a one-way hash of your token (never the token itself).
What Bitsight does not log by default
The contents of your requests and responses.
What Bitsight sees, and why
Bitsight's operators can see operational telemetry: that a call happened, which tool was used, which account made the call, when it occurred, and whether it succeeded. This telemetry is tied to your account and session IDs.
Bitsight uses this data only for three purposes: debugging, service monitoring, and over-utilization detection and rate limiting (60 requests per minute per user). The telemetry is not used for model training, and it does not inform data-access decisions. Those decisions are enforced entirely by your existing Bitsight entitlements.
Security and the AI boundary
Traffic between the MCP and Bitsight is encrypted using TLS 1.2 and 1.3. Databases are encrypted at rest. Secrets are managed through AWS Secrets Manager. The public MCP endpoint sits behind Cloudflare with rate limiting enabled.
Your prompts and results also pass through your chosen AI client — for example, the Anthropic API if you're using Claude, or your IDE vendor's servers if you're using an IDE extension. That boundary is outside Bitsight and governed by your AI provider's terms of service.
No model training
Bitsight does not use your API calls, prompts, or responses to train any AI or machine learning model. The MCP is a gateway, not a learning system. Its only machine learning feature is semantic search over public content: Bitsight's published API documentation and help-center articles. Your data is never embedded, indexed, or added to any training set.
- October 6, 2026: Published.
Comments
Please sign in to leave a comment.