Privacy policy
Effective 27 August 2026. OpsTruth is published by AYOBAMI JOHN HAASTRUP.
Data processed
The public MCP service receives the public GitHub repository identifier, public HTTPS health URL, caller-held evidence snapshots and protocol artifacts that a user deliberately submits. It fetches bounded public repository, CI and response-header evidence to produce the requested report.
Data minimisation
The service does not accept private-repository credentials, user tokens or secret values. Environment files and key files are not opened. Secret-like findings are returned only as redacted types and locations. Deployment response bodies are not retained.
Aggregate usage analytics
For reliability and product improvement, Cloudflare Analytics Engine receives bounded aggregate fields only: tool, outcome, verdict, capped evidence and gap counts, CI and deployment-probe flags, signing status, rounded latency, plugin version and coarse client family. Optional feedback records one controlled reason code and surface. Prompts, repository names, URLs, IP addresses, graph contents, receipts, free text and stable user identifiers are not recorded.
Storage
OpsTruth does not create user accounts or persist user reports, snapshots or evidence graphs. Portable snapshots are returned to the caller. Cloudflare and GitHub may process standard request metadata under their own terms. Public GitHub responses may be cached briefly to protect availability and rate limits.
Evidence signing
Reports and Evidence Graph snapshots may include an Ed25519 signature generated with a Cloudflare Worker secret. The public verification key and fingerprint are returned so integrity and signer trust can be checked independently. Signature validity does not prove that an executor was authorised or that its claimed outcome occurred.
Purpose and sharing
Data is processed only to provide repository verification, maintain service reliability and improve the tool. It is not sold or used for advertising.
Your choices
Submit only public repositories, public HTTPS endpoints and protocol artifacts you are comfortable asking the service to inspect. Feedback is optional. For questions, use the support page.