Rivano · Security

Security

Last updated: September 28, 2026

## Scope This page describes the shipped self-hosted **mcpgw v0.8.1** gateway. It does not describe a hosted MCP/A2A control plane, dashboard, multi-tenant database, or managed data path. ## Deployment boundary mcpgw runs in infrastructure you control. MCP request and response bodies pass through the gateway and the upstreams you configure. Rivano does not receive that traffic unless you deliberately configure a Rivano-operated destination. License verification is offline and has no phone-home call. ## Data controls - Inbound clients can use API-key authentication, OAuth 2.1 bearer tokens, TLS, and optional mutual TLS. - Policy is first-match-wins with `allow`, `deny`, `redact`, `rate_limit`, `strip_app`, and `guardrail` actions. - Guardrail webhooks receive the full matched JSON-RPC envelope. Treat every endpoint as a trusted data recipient. In v0.8.1, envelopes over the endpoint's default 1 MiB cap are not sent and take its configured fail posture. - JSONL audit records contain request metadata. Operators can ship records to S3, GCS, Kafka, or an HTTPS webhook and are responsible for destination access, encryption, and retention. - OpenTelemetry export goes only to operator-configured OTLP endpoints. A forwarded call can produce a SERVER span plus a CLIENT child span. ## Network and runtime posture The published container is multi-architecture for Linux amd64 and arm64. The shipped Helm chart uses non-root, read-only, dropped-capability defaults and provides readiness/liveness probes, PodDisruptionBudget support, anti-affinity, and graceful drain wiring. Redis can provide shared rate-limit state across replicas. Outbound guardrail, audit, OAuth metadata, Redis, upstream, and OTLP destinations remain part of the operator's trust boundary. Review private CAs, mTLS material, DNS, egress policy, and timeout/fail-open settings before production use. ## Supply chain Release automation publishes checksums, keyless cosign signatures and certificates, and SBOM artifacts when they are mirrored on the public release surface. Verify an artifact before use and pin the container by digest where reproducibility matters. Rivano does not claim SLSA Level 3 for the audited v0.8.1 workflow. ## Reporting Please send suspected vulnerabilities to **[email protected]** with affected version, reproduction steps, impact, and any suggested mitigation. Do not include production credentials, license tokens, or customer payloads in the initial report. ## Operational guidance Start with the [configuration reference](/docs/reference/configuration/), [guardrail security model](/docs/explanation/guardrail-webhook/), [HA deployment guide](/docs/how-to/run-ha-on-kubernetes/), and [compatibility and rollback notes](/docs/compatibility/upgrades/).