Certified Cloud Infrastructure

Security

The core of MCPify’s security story is narrow and checkable: your upstream API credentials are held server-side and never reach the AI model, and everything runs on certified Google Cloud infrastructure in the EU. This page says which parts are ours and which are Google’s.

How your credentials are handled

The question every MCP integration has to answer: what does the model get to see?

Credentials stay server-side

Upstream API credentials are held in Google Secret Manager and used by the gateway to call your API. They are never sent to the AI client, never included in a tool response, and never visible to the model.

OAuth handled by the gateway

Where an upstream API uses OAuth, the gateway owns the token lifecycle — storage, refresh, and revocation — through a single shared credential vault. The AI client sees tool calls, not tokens.

Per-service scoping

Each MCP service carries its own credentials and its own endpoint. A tool call is routed and authorised against that service, so one connected API cannot borrow another one’s access.

What the platform does

Verifiable from the deployment, not from a checklist

  • TLS for all traffic — Cloud Run terminates HTTPS and does not serve plaintext
  • Encryption at rest with Google-managed keys, the Google Cloud default
  • All secrets in Google Secret Manager, never in source, config, or environment files
  • Automated dependency-vulnerability scanning on every change, blocking at merge
  • Request logs retained in Google Cloud Logging; administrative access recorded in Cloud Audit Logs
  • Rate limiting per service on the gateway

Infrastructure & compliance

Built on certified cloud infrastructure, operated by a publicly traded company

Cloud Infrastructure

SOC 1, SOC 2, SOC 3, ISO 27001

Certifications held by Google Cloud Platform, not by MCPify

Data Residency

EU — Finland

Runs in Google Cloud europe-north1

GDPR

Aligned

EU data protection standards

Ayfie International AS

Euronext Growth

Publicly traded operator

To be exact about the certifications: SOC 1, SOC 2, SOC 3 and ISO 27001 are held by Google Cloud Platform, which MCPify runs on. MCPify does not hold its own SOC 2 or ISO 27001 certification. If your review process needs that distinction documented, ask and we will put it in writing.

Reporting a vulnerability

If you find a security issue, tell us and we will act on it. Use the security channel on the contact form, or email the address below.

Security review ahead of you?

Send us the questionnaire. We will answer what we can evidence and say plainly where we cannot.

Start the conversation