Probe MCP Terms Addendum
Contents
Authority to monitor
Probe MCP observes a live network and the devices on it. You may deploy a probe only on a network that you own or are authorised to monitor, and you may point its collectors only at devices you are authorised to query.
You represent that you hold that authority, and that you have met any notice, consent or disclosure obligation you owe to the people who use that network. This matters more here than for a tool that only reads your own account at a vendor: network monitoring, and packet capture in particular, is regulated in many jurisdictions, and the obligations fall on the party operating the monitoring — you.
Do not use Probe MCP to monitor a network, intercept traffic, or reach equipment without authorisation.
The probe container
The probe runs on a host you provide, inside your network, under your control. You are responsible for:
- The security of the host it runs on and the network position you give it
- Keeping the probe reasonably current when we publish updates
- The enrolment codes and probe secrets that bind it to your account
- Decommissioning a probe you no longer use
We grant you a non-exclusive, non-transferable licence to run the probe container for the purpose of using the Service, for as long as your account is in good standing. You may not redistribute it, resell access to it, or reverse-engineer it except to the extent that restriction is unenforceable where you are.
Because the probe runs on your infrastructure, we cannot guarantee its availability, and an outage of your host, your network or your tunnel is not a failure of the Service.
Packet capture
A packet capture records traffic crossing your network segment, which may include communications belonging to people other than you and the contents of anything not separately encrypted.
You may request a capture only where you are authorised to intercept that traffic. Narrow the filter and the time window to what you actually need. You are responsible for how you handle, store and share a capture once you download it.
Device credentials and command execution
Probe MCP can store credentials for your network devices and open command-line sessions to them on your instruction.
- You are responsible for the credentials you supply, for their scope, and for rotating them when appropriate. Supply an account with the least privilege the task needs.
- Commands executed through the Service are your actions, whether you type them or an agent issues them on your behalf. Configuration changes, restarts and anything else performed on your devices are your responsibility and your risk.
- Sessions are recorded, as described in the Privacy Addendum.
- Where you push a temporary copy of a controller credential to our cloud so queries survive a probe outage, that is a deliberate act with an expiry you choose. You are responsible for choosing an appropriate one.
Actions initiated by an AI agent
Probe MCP is designed to be driven by an AI agent. An agent connected to your account acts with your authority, and you authorise it on an explicit grant screen naming the client that is asking.
That grant is a single permission covering everything the MCP server can do for your account — not one permission per capability. A client you approve can read your telemetry, run live queries, request packet captures and open command-line sessions to your devices. You cannot currently grant a subset. Approve a client only if you intend to give it the whole surface, and revoke access when you no longer need it.
You are responsible for what you connect, for approving that grant, and for what the agent does with it — including queries it makes, captures it requests and commands it runs. Agents can act on incorrect inferences. Do not grant an agent access to production equipment without controls you are comfortable with, and do not rely on an agent's output as the sole basis for a change you could not safely undo.
Shareable links
Captures and assessment reports are reachable through unguessable links that do not require a sign-in, so that you can pass one to someone who needs it. Anyone holding such a link can retrieve that file until it expires. Treat these links as confidential and share them deliberately.
Diagnostic tool, not a certified instrument
Probe MCP is a monitoring and diagnostic aid. Its inventories, classifications, counters and flow summaries are inferred from what the network reports and are approximate. It is not a calibrated instrument, not a compliance-monitoring system, and not a security product: it does not detect intrusions, and you should not rely on it to meet a regulatory, contractual or safety obligation. The Service is provided "as is" as described in the Master Terms.
Availability
Probe MCP carries no service-level commitment. We may change, suspend or discontinue features, and we may impose reasonable limits on capture size, retention, query volume and storage.
Contact
For Probe MCP questions: [email protected].
← Back to the Master Terms