Security and compliance
Potloc’s certifications, policies and security documentation live in one place, kept current:
Start there for a security review, a questionnaire, or a copy of a report; Trust and compliance explains what belongs there and what belongs on this site. This page covers what is specific to the MCP server.
How access is controlled
Section titled “How access is controlled”- No API keys. Authentication is OAuth against your Potloc account, SSO included. There is no long-lived secret to store, leak or rotate.
- Access tokens last one hour and are refreshed automatically. You can see every app and AI assistant holding access under Connected apps on your Potloc profile (app.potloc.com/en/profile/authorization), and revoking one signs it out immediately.
- Tokens are audience-bound. A token must carry the
mcp_customerscope; one issued for another Potloc service is refused, so a token cannot be replayed against a server it was not meant for. - You approve every app yourself. Before an app gets access, the consent screen shows you its name and where it will take you once you approve: a website, an app on your computer, or an app link. An app cannot get in on the strength of a familiar name alone.
- PKCE is required, and clients are public with no secret — the shape the OAuth 2.1 and MCP specifications call for.
- Every request is authorized on its own. The transport is stateless: there is no session to hijack, and a request with no valid token never reaches a tool.
What the server can reach
Section titled “What the server can reach”Your Potloc permissions, and only those. There is no employee override and no service account: a tool sees what your role on each survey lets it see. Permissions and data scope sets out what that means role by role.
The server returns questionnaire responses only. Respondent-level rows are reachable in one
place, list_responses, and only through a data layout Potloc has published on your survey, which
carries exactly the columns your spreadsheet deliverable does — the tool renders that layout rather
than deciding for itself what to show.
Using it safely
Section titled “Using it safely”MCP puts your data in front of a model, alongside whatever else that client is connected to. Two habits are worth keeping:
- Turn on confirmation for write actions in your client. The tools that write are marked, and a well-behaved client will ask before running one if you let it.
- Be deliberate about combining connectors. An assistant holding both Potloc data and an outbound channel can move one into the other. Connect what a given piece of work needs.
Questions
Section titled “Questions”Security review, architecture questions, or a compliance requirement not answered at trust.potloc.com: write to support@potloc.com.