Security

Security

We build MCP Bundles with standard safeguards for a hosted service — encryption, access control, and monitoring. A written security overview is available on request for vendor reviews.

At a glance

  • Connection credentials and tokens are encrypted at rest; traffic uses TLS.
  • Production runs in the EU (AWS London, eu-west-2).
  • You choose which services to connect and can revoke access from your dashboard.
  • For eligible integrations, we may cache short-lived metadata summaries from your connected account to speed up search (on by default; opt out per connection in credential settings).
  • Cached connection data is deleted when you disconnect, turn off the setting, or delete your account; see our Privacy Policy.
  • We support GDPR data-subject rights and can provide a Data Processing Agreement for business customers.

Customer & vendor reviews

Evaluating MCP Bundles for your organization? Email us for a security overview, completed questionnaires, or other due-diligence materials. If you have specific security requirements, tell us what you need — we can discuss additional assurance options.

security@mcpbundles.com

Connection data cache

For some connected services (including Aircall, Gorgias, Google Chat, Pennylane, Resend, and SolarWinds Service Desk), MCP Bundles may store short-lived metadata summaries from your account — such as ticket subjects, contact emails or phone numbers, and short message previews — so list and search tools respond faster. This is on by default for eligible connections. You can turn it off anytime in credential settings: Store connection data for faster search.

Cached rows live in our EU database, roll off on a per-provider schedule (typically about 30 days), and are deleted immediately when you opt out, disconnect the credential, or delete your account. We do not use this cache for advertising or unrelated profiling.

If your organization is the controller for end-customer data flowing through these integrations, MCP Bundles acts as a processor for this cached layer. Email privacy@mcpbundles.com for a Data Processing Agreement — we can provide a standard connection-data-cache clause on request.

Privacy requests

For GDPR access or deletion requests, or to request a Data Processing Agreement, contact privacy@mcpbundles.com. How we collect and use data is described in our Privacy Policy.

Responsible disclosure

If you believe you have found a security vulnerability, please tell us responsibly. We investigate good-faith reports and work with reporters to understand and resolve issues.

security@mcpbundles.com

Related policies

Privacy Policy · Terms of Service

© 2026 ThinkChain Inc. MCP Bundles is a ThinkChain Inc product.

Security - MCP Bundles