The core of MCPify’s security story is narrow and checkable: your upstream API credentials are held server-side and never reach the AI model, and everything runs on certified Google Cloud infrastructure in the EU. This page says which parts are ours and which are Google’s.
The question every MCP integration has to answer: what does the model get to see?
Upstream API credentials are held in Google Secret Manager and used by the gateway to call your API. They are never sent to the AI client, never included in a tool response, and never visible to the model.
Where an upstream API uses OAuth, the gateway owns the token lifecycle — storage, refresh, and revocation — through a single shared credential vault. The AI client sees tool calls, not tokens.
Each MCP service carries its own credentials and its own endpoint. A tool call is routed and authorised against that service, so one connected API cannot borrow another one’s access.
Verifiable from the deployment, not from a checklist
Built on certified cloud infrastructure, operated by a publicly traded company
Certifications held by Google Cloud Platform, not by MCPify
Runs in Google Cloud europe-north1
EU data protection standards
Publicly traded operator
To be exact about the certifications: SOC 1, SOC 2, SOC 3 and ISO 27001 are held by Google Cloud Platform, which MCPify runs on. MCPify does not hold its own SOC 2 or ISO 27001 certification. If your review process needs that distinction documented, ask and we will put it in writing.
If you find a security issue, tell us and we will act on it. Use the security channel on the contact form, or email the address below.
Send us the questionnaire. We will answer what we can evidence and say plainly where we cannot.
Start the conversation