Webmcp Policy | AiVIS Cite Ledger
AiVIS Cite Ledger page for webmcp policy. Evidence-backed AI search inclusion and citation readiness guidance.
TLDR
The AiVIS.biz WebMCP Agent Policy defines the security architecture, quota limits, authentication requirements, data protection rules, and acceptable use boundaries for AI agents interacting with AiVIS.biz via WebMCP (Web Model Context Protocol).
What WebMCP is and why this policy exists
WebMCP (Web Model Context Protocol) is the structured interface that allows AI agents to interact with AiVIS.biz in an authorized, sandboxed way. This policy defines the controls that prevent abuse, protect user data, and ensure agent actions stay within consented boundaries.
All WebMCP tool calls run inside the browser security context for the aivis.biz origin. Sensitive actions such as audits or GitHub PR creation are routed through the backend with authentication and quota enforcement. No raw credentials are ever exposed to the browser or agents.
Authentication and per-tier quotas
Most tools require a logged-in AiVIS Cite Ledger account. Actions that change external systems require explicit user authorization. Session tokens are short-lived and scoped to prevent lateral movement.
Quota limits enforce fair usage across tiers. Observer users receive a limited baseline. Starter, Alignment, and Signal tiers receive progressively higher limits for audits, auto-fix PRs, competitor analysis, and citation tests. Enterprise and Agency plans are negotiated via sales.
- Additional per-IP and per-session rate limiting applies.
- Violations surface as clear error messages with upgrade CTAs.
- Allowlisted accounts bypass quota limits for internal and partner use.
User consent and revocation
Consent is granular and per-tool with Allow Once, Session, and Always options. Users can revoke all agent permissions instantly from account settings. Full usage history is visible in the Agent Tools Dashboard so users always know what agents did on their behalf.
- No agent action proceeds without prior user approval.
- Tool invocations are logged for security and billing audits.
- No sensitive user data is returned in tool responses unless explicitly authorized.