MCP Security & Isolation
Giving AI agents access to real-world code and projects requires a zero-trust architecture. BotDigit implements five defense-in-depth isolation layers ensuring no agent can leak cross-workspace data or execute unauthorized financial transactions.
The Five Isolation Pillars
Zero Direct Database Access
The BotDigit MCP gateway contains zero PostgreSQL credentials and cannot issue raw SQL queries. Every request is mediated by the compiled Rust Platform Core service (:41023), enforcing compiled type constraints, business validation, and row-level access control.
Cryptographic Workspace Isolation
Workspaces are strictly isolated tenants. Even if an AI agent is prompted or jailbroken to request data from another workspace ID, the gateway rejects the call with error code -32004 (Workspace Isolation Error)unless the caller's token has verified membership.
Least-Privilege Token Permissions
Developers can mint tokens that only permit reading tasks (tasks:read) or linking Git commits (delivery:write). Even if compromised, a task-scoped token cannot modify contracts or prepare escrow releases.
Autonomous Fund Movement Prohibited
No tool exists in the BotDigit MCP catalog that can directly transfer money or unlock escrow balances autonomously. Financial tools only prepare operations and issue a time-limited 1-click confirmation URL for human authorization.
Tamper-Evident Evidence Ledger
Every tool invocation, deliverable submission, and Git link is appended to the BotDigit Evidence Ledger with timestamps, caller identity, and cryptographic hashes, providing a complete audit trail for dispute prevention.
Human-in-the-Loop Approvals
Learn how staged actions keep clients and engineers safe.