Skip to content

Security and compliance

Potloc’s certifications, policies and security documentation live in one place, kept current:

trust.potloc.com

Start there for a security review, a questionnaire, or a copy of a report; Trust and compliance explains what belongs there and what belongs on this site. This page covers what is specific to the MCP server.

  • No API keys. Authentication is OAuth against your Potloc account, SSO included. There is no long-lived secret to store, leak or rotate.
  • Access tokens last one hour and are refreshed automatically. You can see every app and AI assistant holding access under Connected apps on your Potloc profile (app.potloc.com/en/profile/authorization), and revoking one signs it out immediately.
  • Tokens are audience-bound. A token must carry the mcp_customer scope; one issued for another Potloc service is refused, so a token cannot be replayed against a server it was not meant for.
  • You approve every app yourself. Before an app gets access, the consent screen shows you its name and where it will take you once you approve: a website, an app on your computer, or an app link. An app cannot get in on the strength of a familiar name alone.
  • PKCE is required, and clients are public with no secret — the shape the OAuth 2.1 and MCP specifications call for.
  • Every request is authorized on its own. The transport is stateless: there is no session to hijack, and a request with no valid token never reaches a tool.

Your Potloc permissions, and only those. There is no employee override and no service account: a tool sees what your role on each survey lets it see. Permissions and data scope sets out what that means role by role.

The server returns questionnaire responses only. Respondent-level rows are reachable in one place, list_responses, and only through a data layout Potloc has published on your survey, which carries exactly the columns your spreadsheet deliverable does — the tool renders that layout rather than deciding for itself what to show.

MCP puts your data in front of a model, alongside whatever else that client is connected to. Two habits are worth keeping:

  • Turn on confirmation for write actions in your client. The tools that write are marked, and a well-behaved client will ask before running one if you let it.
  • Be deliberate about combining connectors. An assistant holding both Potloc data and an outbound channel can move one into the other. Connect what a given piece of work needs.

Security review, architecture questions, or a compliance requirement not answered at trust.potloc.com: write to support@potloc.com.