# MarcoPolo > MarcoPolo is an MCP-first enterprise AI data platform operated by Immersa: "Scale AI across the enterprise. Without the leaks." It connects AI models to governed enterprise data through a hosted, remote Model Context Protocol (MCP) server, a sandboxed workspace, centralized credential management, and audit/cost controls. This llms.txt was generated by the API Evangelist enrichment pipeline (2026-07-20) from the MarcoPolo public site, docs, and live probes of the hosted MCP server. It is not an official vendor-published llms.txt. ## Products - Sandbox: governed AI execution environment hosted in your cloud, addressing MCP token waste, inaccurate responses, and data-exposure risk. - Cost Plane: token-usage visibility and model routing optimization. - Connections: unified access to enterprise data sources. ## Connect (MCP) - MCP server (hosted/remote): https://mcp.marcopolo.dev - Transport: MCP over streamable HTTP; requires an OAuth 2.0 bearer token (401 otherwise). - Clients: Claude, ChatGPT, Cursor, Codex, or custom agents. Claude and Codex plugins are provided. - Authentication: OAuth 2.0 (authorization-code + PKCE, device-code) via WorkOS AuthKit. Sign in with Google, Microsoft, GitHub, or email. - Authorization server metadata (RFC 8414): https://mcp.marcopolo.dev/.well-known/oauth-authorization-server - Protected resource metadata (RFC 9728): https://mcp.marcopolo.dev/.well-known/oauth-protected-resource ## MCP tools - install_demo_connection: deploy demo datasets. - connection list: enumerate available connections. - connection describe: inspect a connection's table schemas. - connection query: execute a query file against a data source (result cached in DuckDB). - workspace_shell: run CLI commands within the sandboxed workspace. - connection_setup: generate a secure credential-configuration link. ## Data sources PostgreSQL, Snowflake, BigQuery, Amazon S3, OneDrive, Salesforce, Jira, and local DuckDB. ## Security & compliance - SOC 2 Type II (report available under NDA). - Encryption: TLS in transit, AES-256 at rest. - Annual third-party penetration testing; 100+ monitored internal controls. - Security contact: peoplefirst@immersa.co - Trust: https://www.marcopolo.dev/trust ## Docs - Documentation: https://docs.marcopolo.dev - Getting started: https://docs.marcopolo.dev/getting-started - Pricing: https://www.marcopolo.dev/pricing