# Zactonz MCP Server: Security & limits

> A Model Context Protocol server that gives AI assistants the Zactonz APIs as tools: screenshots, page to Markdown, link previews, DNS, SSL, WHOIS, email checks, QR codes, barcodes, social images, image conversion and translation.

Page: https://developers.zactonz.com/tools/zactonz-mcp/security/

Complete documentation for this product: https://developers.zactonz.com/tools/zactonz-mcp.md

## What is sent and kept

- **Tool arguments go to `api.zactonz.com` and nowhere else.** The server keeps no logs and stores nothing on disk. The API's own handling of data is covered by the [privacy policy](https://zactonz.com/privacy/).
- **Keys stay in the server process.** They are sent only in the `Authorization` header to the API and are never included in anything returned to the assistant.
- **Arguments are validated** against each tool's schema before any request is made, and arguments outside the schema are refused.
- **Images are fetched for inline display only from the API's own host**, over HTTPS, without following redirects, and capped in size while streaming.
- **Tools that fetch a URL do so from Zactonz's servers**, which refuse private and internal addresses.

## Untrusted content

`read_webpage`, `preview_link` and `read_qr_code` return text written by whoever controls the page or the code. That text can contain instructions aimed at the assistant. The server labels it as third-party data, but the label is advice to the model, not a guarantee. Review what an assistant does after reading pages you do not control.

## Generated files are public links

Screenshots, PDFs, QR codes, barcodes and converted images are stored on `api.zactonz.com` at unguessable URLs that anyone holding the link can open, for the period given on each endpoint's reference page. Do not render documents that must stay private.

## Timing and quota

Calls spend units from your plan's quota, the same as direct API calls. See [rate limits and quotas](https://developers.zactonz.com/apis/rate-limits/).

A tool call is given 55 seconds in total, because MCP clients stop waiting after 60. Within that time the server retries once, and only where a retry cannot repeat work: after a `429` with a short `Retry-After`, after a gateway error on a read, or ten seconds after the API host's request burst guard rejects a call. If the client cancels a call, the server stops.

## Reporting a problem

Bugs and feature requests go to the [issue tracker](https://github.com/zactonz/zactonz-mcp/issues). Report a vulnerability privately by email as described in the repository's [security policy](https://github.com/zactonz/zactonz-mcp/blob/main/SECURITY.md); do not open a public issue for it.
