What “unknown” means here#
On this site, unknown means we found no source either way. It is never a synonym for unsupported, and it says nothing about the product.
A vendor may run excellent controls and document none of them publicly. From outside, that is indistinguishable from having none — which is precisely why the questionnaire exists.
So do not treat a column of unknowns as a verdict. Treat it as your agenda.
Questions about the specific server#
Does this MCP server write an audit record when a tool is invoked? What is recorded, and how do we retrieve it?
What does the server retain from a session, and for how long?
In which region does this endpoint process requests? Is that configurable?
Which tools can write or delete? Is there a configuration that disables them?
Can access be scoped per user or per workspace, or is a single credential shared across everyone who connects?
Questions about the company, kept separate#
Which compliance attestations cover *this service* specifically, as opposed to the company's flagship product?
Is there a DPA covering this endpoint, and a sub-processor list that includes it?
How are incidents affecting this endpoint communicated, and is it on your public status page?
Keeping these separate from the server questions matters. A company-level attestation is real evidence about a company and no evidence at all about whether one particular endpoint logs tool calls.