example](https://github.com/OthmanAdi/codebase-knowledge-builder/blob/main/examples/distribution-architecture.md): source-cited analysis of the repository's own distribution architecture
- [Security policy](https://github.com/OthmanAdi/codebase-knowledge-builder/blob/main/SECURITY.md): private vulnerability reporting and safe reproduction guidance
## Product boundary
Codebase Knowledge
Mastra Governed RAG
> A secure, enterprise-grade Retrieval-Augmented Generation (RAG) system built with Mastra AI orchestration framework, implementing role-based access control (RBAC) with hierarchical permissions, document classification
recipient, status, timestamp and nonce. Unsigned, stale, replayed and wrong-recipient ACKs are rejected.
## Security model
- End to end: messages are encrypted by the sender and decrypted only
source tree
- **Cross-Platform Support**: Works on Windows, macOS, and Linux (Node 20+ required)
- **Security-Hardened**: SSRF guard on every outbound call (full IPv4 + IPv6 private-range blocking), streaming response
Cross-Platform Support**: Works on Windows, macOS, and Linux (Node 20+)
- **Security-Hardened**: SSRF guard on all outbound calls, streaming response-size caps, instance blocklist, thread cross-origin gating, audit
hooks, and commands that supercharge your Claude Code IDE with AI-powered automation and security guardrails.
## Getting Started
- [Installation Guide](https://github.com/cfircoo/claude-code-toolkit#automatic-installation-recommended): Quick setup with `./install.sh` (installs everything
tests and open a pull request.
- [Changelog](https://raw.githubusercontent.com/enkhbold470/bci-mcp/main/docs/changelog.md): Release history.
- [Security](https://raw.githubusercontent.com/enkhbold470/bci-mcp/main/docs/security.md): Threat model and vulnerability reporting.
## Interactive
- [DeepWiki](https://deepwiki.com/enkhbold470/bci-mcp): Ask questions about
setoku.com/docs): the HTTP API, authentication, the MCP tool surface, quickstart, and the security model. Markdown twin: [/docs.md](https://setoku.com/docs.md).
- [Setoku homepage in markdown](https://setoku.com/index.md): the whole
call cannot leave
the device unredacted.
**Designed next** — local encrypted storage (Keychain / Secure Enclave).
## Where the difficulty lives
**Models return text. Code needs records.** A model writes `"0.8"` where
contract.
- [docs/data-model.md]: Meaning of planned, changed and effective event values.
- [docs/architecture.md]: Components, transports and security model.
- [src/server.ts]: MCP server factory.
- [src/api/timetableParser.ts]: XML validation and semantic normalization.
## Key concepts
- Use `getStationBoard
tiers, when introduced, will require a named first paying customer + named feature shipping atomically.
## Security invariants
- Taprun servers never push executable code to clients.
- Taprun servers never initiate connections
hosts (like Claude Desktop) to access Fathom AI meeting data. It acts as a secure bridge between AI assistants and Fathom AI's meeting recording and transcription service.
Think
hosts (like Claude Desktop) to access Fathom AI meeting data. It acts as a secure bridge between AI assistants and Fathom AI's meeting recording and transcription service.
Think
vault API receives ciphertext rather than decrypted secret values; client, account, endpoint, and deployment security remain in scope.
- `phantom_cloud_pull` — After commissioning, pull a vault snapshot. Params: force, confirm