Security, Privacy, and Data
See how Investigations MCP authenticates users, enforces access, and handles your data.
Early AccessSpyCloud Investigations MCP is in Early Access. Tools, limits, and behavior may change before general availability, targeted for early 2027.
This page answers the questions security, privacy, and AI governance teams ask most often about SpyCloud Investigations MCP. For SpyCloud's broader security posture, see the SpyCloud Trust Center.
How data flows
- You enter a prompt in your MCP client.
- Your client and its AI model decide which SpyCloud tools to call, based on your prompt and your permitted scopes.
- The client sends each tool call and its parameters (for example, the email address to search) to the SpyCloud MCP server.
- SpyCloud checks your permissions, runs the query against Investigations data, and returns the result to your client.
- Your client and its AI model use the result to compose the answer.
Your prompt and the data SpyCloud returns are handled by your chosen MCP client and AI provider under that provider's terms and your organization's configuration. Review those terms before you use SpyCloud data in any AI tool.
Authentication and tokens
How does authentication work?
Investigations MCP uses an OAuth 2.1-aligned authorization code flow with PKCE (S256). You sign in with your SpyCloud Console credentials, or through your identity provider if your organization uses single sign-on for the Console. You never store SpyCloud passwords, API keys, or other long-lived credentials on your workstation to use the MCP.
MCP clients must support Dynamic Client Registration (DCR) or Client ID Metadata Documents (CIMD). Authorization uses scoped Auth0 JSON Web Tokens (JWTs).
How are tokens handled?
Access tokens are short-lived JWTs, signed with RS256 and validated against SpyCloud's published keys (JWKS) on every request. Tokens pass through the MCP server and are not logged or stored server-side. Refresh tokens are not issued by default. When a token expires, you sign in again through your client.
How does SpyCloud validate MCP clients?
SpyCloud validates clients at authorization time. Only approved redirect targets and vetted client identifiers are accepted. If your organization routes AI traffic through a gateway, contact Product Success so the gateway's callback URL can be reviewed.
Access control
Can the MCP reach all of my SpyCloud data?
No. The MCP does not expose your Investigations dataset to the model in bulk. Your client calls specific tools based on your request, and each call returns only what that tool retrieves.
Can the MCP bypass my SpyCloud permissions?
No. A tool call succeeds only when all three layers allow it:
- Your organization's Investigations license and entitlement.
- The MCP scopes assigned to your user.
- A per-tool permission check on every call.
A user can sign in successfully and still see no tools if no dataset scopes have been assigned.
Can the MCP change anything in my SpyCloud account?
The Early Access tools retrieve data only. None of them change settings, watchlists, or other configuration in your SpyCloud account.
Can an administrator revoke a user's access?
Yes. Where your organization uses single sign-on for the SpyCloud Console, deactivating the user in your identity provider blocks MCP access immediately. To remove MCP access for a specific user without deactivating their account, contact SpyCloud Product Success.
Data handling
What does SpyCloud store?
- Queries are not stored or logged. SpyCloud records query metadata only.
- Responses: select responses are cached, encrypted, in AWS-backed storage to support pagination.
- User data: the only other user data SpyCloud stores lives in Auth0, SpyCloud's identity service.
Is data encrypted?
Yes. Traffic is encrypted in transit with TLS end to end. Customer-managed encryption keys (CMEK) are supported.
Where is the MCP server hosted?
On Amazon Web Services, in Amazon Elastic Container Service (ECS).
Does SpyCloud log MCP activity?
Yes. SpyCloud keeps structured JSON logs of authentication events, client registrations, and tool calls. Logs are available on request.
Using results responsibly
Are MCP results a system of record?
No. MCP answers are AI-assisted syntheses of SpyCloud data, and the same question can follow a different tool path each time. Before a finding goes into a case file, report, or legal filing, confirm it with a deterministic pull from the Investigations API.
What if my organization hasn't approved AI tools for sensitive data?
Use the Investigations Module or the Investigations API instead. The MCP is not suited to air-gapped environments or to organizations without an approved path for LLM use with sensitive data.
Updated about 2 hours ago