INFABODE
ANYWHERE
Overview
Our Data
AI Connectors
Pricing
Sign In
Get Started
Security documentation
MCP Client Security Q&A
How the remote Infabode Anywhere MCP service handles authentication, customer data, logging, retention and assurance. This page complements our Privacy Policy and Terms.
Read-only
MCP tools never create, update or delete records.
No prompt storage
Questions, conversations and responses are not retained.
OAuth + TLS 1.2+
Scoped tokens, hashed at rest, encrypted in transit.
Service overview
3 questions
What is the Infabode MCP?
Infabode Anywhere is the Infabode service that provides authorised access to Infabode real estate data through a remote Model Context Protocol (MCP) server. When connecting the MCP, customers may assign their own display name to the connection or agent. Compatible AI assistants and applications can use the service, subject to the user's subscription, licence and permissions.
Is the service read-only?
Yes. The client-facing MCP tools retrieve, search, list, compare and summarise information. They do not create, update or delete records through an MCP session.
Which MCP clients are supported?
The service is a client-agnostic, remote MCP server. It can be added to any system that supports custom remote MCP connections, including Claude, ChatGPT, Cursor and Grok. Microsoft Copilot is also supported where the customer creates its own agent and adds the Infabode MCP. Availability and setup options within each client may depend on that provider's product plan and controls.
Data access and collection
6 questions
What information does the MCP receive from a user request?
The MCP receives the bearer token and session headers needed to authenticate and operate the connection, technical metadata such as IP address and user-agent information, and the structured MCP request. Tool arguments may include search terms, filters, dates, organisation names or identifiers, locations, sectors and pagination values.
Does the MCP directly access content held by the connected AI platform?
No. The Infabode MCP receives MCP calls sent by the selected client; it does not independently obtain broad access to the user's stored chat history, email, files, calendars or collaboration content. The selected client controls what it sends in each MCP request.
Does Infabode receive the complete natural-language prompt or conversation history?
No. The MCP receives the content included by the client in MCP requests — principally authentication data, structured tool arguments, resource identifiers and client metadata. It does not independently retrieve the user's complete natural-language prompt or conversation history.
Does Infabode store the user's question or MCP response content?
No. Infabode does not store the user's natural-language question, prompt, conversation history or successful MCP response content. The persistent MCP usage record is deliberately limited to tool or resource identifiers and a small set of user-context fields, including api_user, organisation, user_id and timestamps.
How does Infabode use customer data sent through the MCP?
Customer data remains under the customer's control. Infabode processes the information sent in an MCP request only to authenticate the user, apply permissions and provide the requested Infabode service. Infabode does not retain the user's question or response content and does not repurpose customer data for model training, advertising, profiling or unrelated commercial use.
What information can be returned to the user?
The MCP returns read-only, permission-filtered Infabode data in structured form. Depending on the user's licence and permissions, this may include publications, organisations, feeds, locations, transactions, research metrics, and market, deal or asset context, together with viewer profile and service-status information. The connected AI client decides how that structured result is presented to the user.
Logging, storage and retention
5 questions
What operational data is logged or recorded?
Infabode takes a deliberately light-touch approach. The persistent MCP usage dataset records only the tool or resource identifier and a severely limited set of user-context fields: api_user, organisation, user_id and timestamps. It tracks which MCP capabilities are used; it does not contain the user's question, prompt, conversation, tool arguments or the data returned by the tool.
Are successful tool response bodies stored in MCP analytics?
No. Successful tool-response bodies are not stored. The usage dataset contains only tool or resource identifiers and the limited user-context fields described above.
How long is MCP-related data retained?
Infabode permanently retains the limited MCP usage fields described in this document. It does not retain users' natural-language questions, prompts, conversation history, tool arguments or successful tool-response bodies in that dataset. MCP access tokens expire after 30 days and OAuth grants remain active until revoked. Separate Google Cloud technical and application logs use the configured logging retention periods, including 30-day default and 400-day required logging buckets.
Where is MCP-related data stored and processed?
The production application is hosted primarily in Google Cloud's London region. Supporting database, replica and backup infrastructure is located in London, Frankfurt, Paris and the EU multi-region. The limited persistent MCP usage dataset is held in Google BigQuery's EU multi-region. Google Cloud's global logging buckets and a US multi-region logging dataset hold GKE technical and application logs; these logging resources are separate from the MCP usage dataset and are not used to store users' questions, prompts, tool arguments or response content.
How is data deleted when a customer leaves?
A user's granular connected data is deleted from active systems when the user's account is removed. Associated access tokens and OAuth grants are removed or revoked, and the associated Auth0 identity is unlinked. Backups operate on a seven-day rolling cycle, so any deleted user data remaining in a backup is permanently removed within seven days. Infabode retains aggregated historic usage records, but those records are no longer assigned or attributable to the deleted user.
Security, privacy and assurance
8 questions
How are users authenticated and authorised?
Users authenticate through OAuth when adding the MCP connection. The service validates the token signature, issuer, audience, expiry and required mcp:read scope, maps the identity to an Infabode user and organisation, confirms an active grant and verified membership, and applies method-level and field-level access controls.
Is data encrypted?
MCP and OAuth endpoints use HTTPS with TLS 1.2 or later for data in transit. Stored opaque tokens are hashed. The limited Google BigQuery usage dataset uses Google Cloud's default encryption at rest, while Auth0 manages the keys used for OAuth JWTs.
Which third parties support delivery of the MCP?
The AI assistant or application chosen by the customer — such as Claude, ChatGPT, Cursor, Copilot or Grok — is the customer-selected MCP client and is separate from Infabode's own service providers. Infabode uses Google Cloud infrastructure to process MCP requests and Google BigQuery to hold the limited usage dataset. Auth0 supports identity and OAuth.
Is customer data used to train AI models?
Infabode does not use customer prompts, MCP requests, tool arguments or MCP response data to train AI models. The Infabode MCP processes authorised requests and returns permission-filtered Infabode data; it does not operate or supply an Infabode model-training pipeline.
Any data sent by the customer's selected AI client, or returned to that client, is also subject to the client provider's terms, account settings and enterprise data controls. Customers are responsible for selecting and configuring a client whose data-use terms meet their requirements.
What security assurance is available?
Infabode is working towards ISO 27001 certification. Most of the supporting security documentation and controls are already in place and operating. Infabode does not currently claim to be ISO 27001 certified.
Who within Infabode can access user data?
Infabode operates strict data-access controls. Access to identifiable user data is restricted to two authorised people and is limited to circumstances where access is required to operate, support or secure the service.
What privacy and contractual documentation is available?
Infabode's Privacy Policy and Terms of Service apply to the Infabode MCP service and are available for clients to review. Infabode does not currently provide a separate MCP-specific privacy policy or Data Processing Agreement. Clients with particular contractual or data-protection requirements may contact Infabode to discuss them.
How are security incidents reported and communicated?
Infabode monitors the service around the clock and investigates security issues immediately. Clients can report concerns through hello@infabode.com. If a data breach occurs, affected clients will be contacted within 24 hours and kept informed as the incident is investigated and addressed.
Security questions or vulnerability reports
Contact hello@infabode.com. Clients with specific contractual or data-protection requirements can reach the same address to discuss them.
Privacy & Terms
Connect
Real Estate MCP
API Docs
Data Lake
Integrations
Advertising
Use Cases
Contribute
Recruitment
Events