PPrivacy MCP

Security controls

How we protect your OneTrust connection and data — including what we don't do yet.

Tip: use your browser's Print command and choose “Save as PDF” to download a copy.

This document describes the security controls that protect your data when you use Privacy MCP. It is written to match how the service actually works today, including what it does not yet do. Last updated October 2026.

1. What the service does

Privacy MCP connects your own OneTrust tenant to an AI assistant (such as Claude, ChatGPT or Gemini) over the Model Context Protocol (MCP). When you ask your assistant a question, it calls Privacy MCP, which calls the OneTrust API using the API client you provide, and returns the result to your assistant.

You  ->  AI assistant  ->  Privacy MCP  ->  OneTrust API (your tenant)

We are an independent service. We are not affiliated with, endorsed by, or sponsored by OneTrust.

2. What we store, and what we don't

We storeHow it is protected
Your account (name, email)Managed by our identity provider (Neon Auth). Passwords are never stored by us.
Your organization's settings, members and rolesDatabase, access-controlled
Your OneTrust host name and API client IDDatabase
Your OneTrust client secretEncrypted with AES-256-GCM before it is stored. Never displayed again after you save it.
Access tokens issued to your AI assistantOnly a SHA-256 hash is stored, never the token itself
Audit records of calls (who, which operation, when, outcome)Tamper-evident hash chain (section 6)
Usage counters and billing references (Stripe customer and subscription IDs)Database
We do not store
The contents of OneTrust records returned to your assistant. Audit records keep the size of a result, not the result.
Your conversations with your AI assistant.
Payment card numbers. Payments are handled entirely by Stripe's hosted pages.

Data in transit. Data returned by OneTrust passes through our servers in memory on its way to your AI assistant. We do not write it to disk or to the database, but it does transit our infrastructure. Once it reaches your AI assistant, it is governed by that provider's terms and your settings with them.

3. Encryption

  • In transit: all connections use TLS (HTTPS). The service sends HTTP Strict Transport Security headers.
  • Secrets at rest: your OneTrust client secret is encrypted with AES-256-GCM. Each ciphertext is cryptographically bound to your organization, so it cannot be copied into another organization's record and decrypted there. The encryption key is held in the hosting platform's encrypted environment configuration, separate from the database.
  • Database at rest: stored on Neon (PostgreSQL on AWS), which encrypts data at rest.
  • Tokens: random, high-entropy values. We store only their hashes.

4. Authentication and access control

  • Sign-in to the website uses email and password through Neon Auth, with sessions in signed, HTTP-only cookies.
  • Connecting an AI assistant uses OAuth 2.1 with PKCE. You sign in on our website and choose the organization to connect. Authorization codes are single-use and expire after 5 minutes. Access tokens expire after 1 hour. Refresh tokens last 30 days and are rotated on every use, so a stolen, already-used refresh token is rejected.
  • Membership is re-checked every time a connection is refreshed. If you remove someone from an organization, their connection stops working at the next refresh, and revoking their tokens ends it immediately.
  • Roles. Every person in an organization is either an admin or a member. Only admins can change OneTrust credentials, manage billing, delete the organization, invite people, or change anyone's access. An organization always keeps at least one admin.
  • Invitations. Admins invite people by email address. Each invitation is a single-use link that expires after 7 days and works only for the invited address; only a hash of the link is stored. Invitations and every access change are recorded in the organization's audit log.
  • Per-person read-only. An admin can make any member read-only, or make the whole organization read-only. The change applies immediately, even to assistants that are already connected. Removing a member ends their connections at once.
  • Revocation. Tokens can be revoked per user. Deleting an organization revokes everything (section 8).
  • Brute-force protection. An address that sends more than 20 invalid tokens in a minute is temporarily blocked. This protects against guessing and is not a limit on normal use.
  • Abuse monitoring. We watch for accounts that sweep our operation catalog far beyond normal use and review alerts. This monitoring does not limit normal use.

5. Limiting what the assistant can do

You decide how much power to give the AI.

  • Read-only mode. Read-only can be set for an entire organization, for the plan, or for an individual user's connection. In read-only mode, operations that create, change or delete data are removed from the assistant's tool list entirely, and a direct attempt to call one is refused by the server before anything reaches OneTrust.
  • Least privilege at the source. The strongest control is the API client you create in OneTrust. Whatever permissions you grant that client are the upper limit of what any assistant can do through Privacy MCP. We recommend creating a dedicated client with only the permissions you need.
  • Host allowlist. Credentials can only point at OneTrust hosts (*.onetrust.com, *.onetrust.eu). The service refuses any other address, which prevents it from being aimed at internal or third-party systems.
  • Platform blocks. Operations that read or write files on the server, and the module that calls arbitrary customer-hosted URLs, are disabled for every customer.
  • Subscription enforcement. If a subscription is suspended, past due or cancelled, every call is refused until it is restored.
  • Your AI assistant's confirmations. Many assistants ask you to confirm actions that change data. Keep that setting on.

6. Audit logging

Every call is recorded in your organization's own audit log: the user, the operation, the HTTP method and path, the outcome (ok, error or denied), the duration, and the size of the result. Request arguments are recorded as names plus a SHA-256 hash of the values. The values themselves are not stored in readable form.

  • Tamper-evident. Each record includes a hash of the one before it. Editing or deleting a record in the middle of the log breaks the chain and is detectable. This is tamper-evident, not tamper-proof: someone with full database access could in principle rewrite the whole chain.
  • Writes are logged first. For any operation that changes data, a "started" record is written before the call is made. If the audit record cannot be written, the change is not made.
  • Denied calls are logged too, including calls blocked by a suspended subscription.
  • View and export it yourself. Organization admins can see recent activity and download the full log as CSV (for spreadsheets) or JSON (every field, plus a chain-verification result) from the dashboard, for any date range. The JSON export includes instructions so you can re-check the hash chain independently. Each export is itself recorded in the log, so it shows who took a copy and when. Download your log before deleting an organization, because deletion removes it.

7. Tenant isolation

  • Every request is authenticated and resolved to its organization on its own. No organization's credentials, connection state, usage, or audit log is shared with another.
  • Connections to OneTrust are cached per organization and dropped when credentials change.
  • The service is stateless: nothing from one request carries over into the next.
  • Isolation between organizations is covered by our automated test suite.

8. Retention and deletion

  • You can delete your organization at any time from the dashboard (admins only). Export your audit log first if you need to keep it. Deletion is immediate and permanent. It removes the stored OneTrust credentials, every access token and connection, members, usage records and the audit log, and cancels the subscription first so billing stops. Your OneTrust tenant itself is never touched.
  • Billing records may be retained by Stripe as required by financial regulations.
  • Database backups are managed by our database provider and age out under its retention policy.
  • Disconnecting the connector in your AI assistant ends that assistant's access, and you can revoke it from our side as well.

9. Payments

Subscriptions are handled by Stripe. You enter card details only on Stripe's hosted pages; they never reach our systems. Stripe's notifications to us are verified with a cryptographic signature before they are acted on.

10. Hosting and sub-processors

ProviderPurposeLocation
VercelApplication hostingUnited States (East)
NeonDatabase and sign-in (Neon Auth)United States (AWS us-east-1)
StripePayments and billingPer Stripe

Services you choose to connect: OneTrust (your tenant, in the region you chose) and your AI assistant provider (for example Anthropic, OpenAI or Google).

11. Development practices

  • Security-relevant behavior (authentication, token handling, tenant isolation, read-only enforcement, plan limits, billing, deletion) is covered by an automated test suite.
  • Administrative functions are protected by a separate credential and are disabled unless explicitly configured.
  • The admin interface sends strict browser security headers, and responses are not cached.

12. Responsibilities you share

  • Create a dedicated, least-privilege API client in OneTrust, and prefer read-only where you can.
  • Review what your AI assistant proposes before approving changes.
  • Protect your sign-in and your AI account, and remove members who leave.
  • Remember that information you ask an assistant to retrieve is sent to that assistant's provider.

13. What we do not yet have

Being direct about the gaps helps you assess the risk:

  • We do not currently hold a SOC 2 report or ISO 27001 certification.
  • We have not yet commissioned an independent penetration test.
  • Multi-factor authentication for website sign-in is not currently offered.
  • The service is hosted in the United States only.
  • Ordinary software, supplier and infrastructure risks still apply, including the availability of OneTrust itself. OneTrust applies its own API rate limits to your tenant, and those limits can affect performance independently of Privacy MCP.

14. Reporting a vulnerability

Please report suspected vulnerabilities to security@privacymcp.ai. Include enough detail to reproduce the issue. We ask that you give us reasonable time to fix a problem before disclosing it, and not access data that is not yours. We will acknowledge reports and keep you informed.

15. Questions

For security questionnaires, a data processing agreement, or anything not covered here, contact hello@privacymcp.ai.