Built to survive your IT reviewer
Universal coverage without a universal safety model is a liability engine. This page is the model: how identity works, how credentials are handled, what happens when you leave, and where we honestly say no. Forward it to whoever has to approve this.
The rules everything else follows
Chosen and disclosed, never discovered
Whose credentials does the connector use, and who does the upstream system think is acting? You choose the answer at build time, and we state it everywhere.
In both modes, each connection carries a distinct gateway token, so megamcp's own activity log preserves per-connection traceability even when the upstream sees a single account. On the client side, the gateway implements the hardened 2026-07-28 authorization profile: RFC 9207 issuer validation, issuer-bound credentials, and CIMD as the registration path.
Your keys, treated like keys
- Encrypted at rest with KMS envelope encryption
- Never logged, never returned by any tool
- Decrypted only in-runtime at call time
- Isolated per connector and per connection
- Destroyed within 24 hours of cancellation, hard-deleted, not soft-deleted
Leaving is clean, and that is a promise
- All connector URLs deactivate immediately on cancellation or trial expiry
- Upstream OAuth tokens are revoked wherever the provider supports revocation
- Stored credentials are destroyed within 24 hours
- Activity logs remain exportable for 30 days, then purge
- The same guarantee applies per member: revoking one connection deactivates that person's URL, revokes their token, and destroys their credential without touching anyone else
Prefer to keep your configuration? Pausing retains it and stops billing at the next cycle, as the alternative to deletion.
Audit everything. Store only what you choose.
The activity log records every tool call: who, what, when, and result, with confirmation events captured per round-trip. It is immutable and exportable. What it stores about your business data is up to you.
Logs are encrypted at rest, retained 90 days, and purged 30 days after cancellation. Log content is excluded from all analytics pipelines: only metadata such as tool name, status, and latency flows to internal analytics. Storage is single-region at v1, stated plainly.
The panic button is never more than one click away
Where we honestly say: not self-serve
Systems that store PHI, consumer financial records, or similar regulated data are not self-serve in v1. We detect them at intake and route you to a compliance conversation with our done-for-you team, where BAAs and appropriate infrastructure commitments are handled per engagement. That is a trust posture, not a rejection: you get an honest path instead of a quiet liability.
Also available: DPA on request and a current subprocessor list. Every connector ships with a policy summary export covering scopes, enabled tools, safety modes, identity model, logging settings, build provenance, and protocol posture, built to forward to the person who approves tools like this.
Send this page to your reviewer
Then connect your software with a read-only trial. Evidence beats assurances.