Security & Data Protection
How AccMCP keeps your accounting data isolated, read-only, and under your control.
Read-only by design
Every MCP tool and BI surface is read-only, except the two export tools, which only create private downloadable files. Nothing ever writes back to Busy.
Tenant isolation
Row-level security on the warehouse enforces isolation per organization at the database level, not just the application level.
No database credentials, ever
You never submit database credentials or connect a database directly. The sync app authenticates with a scoped organization token.
OAuth 2.1 consent
AI clients connect through OAuth 2.1 with a verified client name shown on the consent screen. Tokens are never pasted into a conversation.
Subscription-gated access
Every ingestion and access request is checked against an active subscription and the token's granted scopes.
Audit logging
The BI application maintains an audit log of user and administrative actions for review.
Trust boundaries
- Busy Accounting Software
- Sync app sends the data
- AccMCP syncs it into a governed warehouse
- ChatGPT uses the data
- Claude uses the data
- Grok and other MCP clients use the data
- The BI app displays the data
Data handling
Where does my data live?
In a private, row-level-secured PostgreSQL warehouse scoped to your organization — never shared across tenants.
Who can access it?
Only authenticated requests bound to your organization's token or OAuth session. AccMCP staff never browse customer data outside of a support request you initiate.
What happens if I cancel?
Syncing stops immediately and your data is retained for a defined period before deletion — see the Privacy Policy for the exact retention window.
Found a security issue? See our responsible disclosure policy
Frequently asked questions
Are you ISO 27001 or SOC 2 certified?
We don't hold formal certifications today. This page describes the actual technical practices in place — we'll update it if that changes.