Home · MCP · Security and isolation

Understanding MCP

Security and data isolation

OAuth access triggered by you, encrypted tokens, strict isolation between customers, read-only by default, hosting in the European Union.

4 min read

Security is not an option bolted on afterwards: it is Alpative's number one design rule. Every access is triggered by you, logged and limited.

Customer ACustomer BGatewaytoken scoped percustomer and per MCPData AData BOne customer can never reach another customer's data.

The guarantees

  • Access through OAuth 2.0, triggered only by you, never in the background.
  • Tokens encrypted at rest (AES-256-GCM) and limited to one customer and one specific MCP server.
  • Strict isolation: one customer can never reach another customer's data.
  • Read-only by default. Write access stays disabled until you enable it.
  • Hosting in the European Union.

What Alpative does not do

Alpative does not resell your data, does not use it to train models, and does not keep your reports. When write access is enabled (Expert plan), sensitive changes such as a tag are prepared in a draft, and putting them live requires your explicit confirmation.

You stay in controlYou can disconnect a source or delete your account at any time. The tokens are then erased.
Security and data isolation · Alpative MCP