Trust & Security
How we protect your data and your generated code.
Encryption
- • TLS 1.3 in transit
- • AES-256 at rest
Hosting
- • Microsoft Azure — West Europe region (Amsterdam)
- • On-premise deployment available on Enterprise plan
Data retention
- • Generation artifacts: 30 days (last 3 versions per source)
- • User account data: until explicit deletion upon request
- • Source code analyzed during generation: not stored — processed in-memory only
LLM access
- • Standard: Anthropic API (Claude) — tool description enrichment only, not source code
- • Enterprise: Anthropic Zero Data Retention (ZDR) by default
- • Enterprise:
--no-llmmode — no external LLM calls at all - • Enterprise: on-premise LLM option (Llama, Mistral via self-hosted endpoint)
Compliance
- • GDPR compliant — DPA available on request
- • SOC 2 Type I — planned, timeline TBD
- • ISO 27001 — planned, timeline TBD
Subprocessors
Third-party services that may process data on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting, compute, database | EU West (Amsterdam) |
| Anthropic | LLM enrichment of tool descriptions (not source code) | US (ZDR available on Enterprise) |
| Groq | Automated quality evaluation of generated servers | US |
Enterprise plans can opt out of Anthropic and Groq with --no-llm mode or on-premise LLM.
Contact
- • Security enquiries: security@mcp-forge.vulcai.io
- • Responsible disclosure: submit a report
- • DPA requests: contact@vulcai.io
Last updated: 2026-05-29 · Back to dashboard →