Formal assurance reports, security-review materials, and the current
subprocessor list are available through the
Prefect Trust Center. For implementation detail
beyond the public documentation, contact
horizon-support@prefect.io.
Identity and authentication
Human sign-in, including SAML or OIDC single sign-on, is backed by WorkOS. The Horizon gateway identifies callers to protected MCP servers through interactive MCP client sign-in tokens or personal and service-account API keys before server code runs. Dashboard requests act as the signed-in user. REST API requests act as the user or service account that owns the credential. See Authentication for both request paths and Single sign-on for enterprise identity provider setup. API keys covers credential ownership and lifecycle, while external authentication covers downstream OAuth and API-key credentials.Access control
After authenticating a caller, Horizon evaluates organization membership, organization role, server access, and capability policy. Organization roles govern members and organization settings. Server roles and explicit grants control access to individual servers, while capability policies can narrow access to specific MCP tools, resources, and prompts. These checks run at the gateway before protected MCP traffic reaches server code. See Authorization for the request decision flow and Roles for role definitions.Data handling
For each served MCP request, Horizon records the method, server, session, client, outcome, and acting identity. It also records request and response payloads by default. You can disable either one per project for future traffic. Horizon retains traffic records indefinitely, and customers cannot set a retention period. The experimental sensitive-data redaction feature can block or mask detected values in tool results, but it is best-effort and is not a compliance control. See Data handling and sensitive-data redaction for the full storage and redaction behavior.Encryption
Horizon individually encrypts stored environment variables and connector credentials, and its underlying data stores are encrypted at rest. Traffic to the Horizon dashboard, API, and served MCP endpoints uses HTTPS. Horizon-generated logs omit stored secret values, and connector credentials are never returned to callers. The data protection page documents these guarantees and where plaintext can appear.Deployment and residency
Horizon’s generally available control plane and hosted server compute operate in AWSus-east-1, with MCP requests entering through a global serving edge.
Customer-selectable regional residency is not available today. AWS PrivateLink
and customer-managed deployments through BYOC or self-hosting are also not
available today. There is no committed availability date for these options. See
Hosted servers,
Compute model, and Deployments for the
current hosted deployment model.