General questions about MCP Security and Data
This page covers what happens to your data when you connect an AI tool to Mass Dynamics over MCP. It is written to be forwarded to whoever reviews this in your organization.
Where does my data go?
Your AI tool connects to your existing Mass Dynamics account, governed by our Terms and Conditions. No copy of your data is created and the tool holds no separate store.
The MCP server sits inside the Mass Dynamics network and carries the same safeguards as the rest of the platform.
Authentication. Access by your AI tool to Mass Dynamics is authorized over OAuth. You sign in with your normal Mass Dynamics login and your AI tool operates with your permissions, reaching only what your Mass Dynamics account can reach. No API key is created or stored on your machine.
Uploads. Your files take the same path as files uploaded to Mass Dynamics through a browser: the same storage and the same processing pipeline. Existing data is not moved or duplicated.
Where our data is stored, and how to have it deleted, is in our security and compliance documentation.
Does my AI tool provider keep my data?
Anything your AI tool reads passes through the model in order to answer you. That is between you and them, and what happens to it after that is governed by your own agreement with the AI tool organization (Anthropic, OpenAI, Microsoft or whoever you use).
Terms may vary: retention, caching and training terms may also differ between a personal account and a team or enterprise plan. So you need to check your provider's terms against your own organization's requirements. If your organization already has an enterprise agreement with an AI provider, connecting through that rather than a personal account may be a preferred position.
What we can tell you is the Mass Dynamics side, which is in our security and compliance documentation.
Who can see what?
Each person connects with their own Mass Dynamics account and their own permissions. An AI tool connection reaches exactly what that person can already reach in the browser — no more.
Connecting an AI tool does not change anyone's permissions, and it does not create a shared or service account.
Can I connect more than one AI tool?
Yes, and across as many devices as you like. We do not limit which AI tools you connect or how many. Connecting one is just another way into the same Mass Dynamics account, in the same way the web app and the API are.
Each connection authenticates separately under your own login. Work done through one is there in the others and in the browser.
The one thing to avoid is connecting two copies of the Mass Dynamics server at once. Your AI tool then sees duplicate operations and may call the wrong one. That is why an older Agent Pack setup should be removed before you connect.
Can my whole team or organization use it?
Yes. It changes nothing about your Mass Dynamics plan. How it gets rolled out depends on how your organization manages AI tools, so get in touch and we will work through it with you.
Uploads and network access
Some AI tools need one extra permission for uploads to work smoothly. Files go from your machine straight to storage rather than through the MCP server, so the tool needs network access to *.amazonaws.com.
Claude Desktop needs this allowed in the connector's settings. Claude Code and ChatGPT ask at the moment they need it. This is covered per tool in Connect your AI tool.
Anything further
Email support@massdynamics.com and we will work through it with your reviewers.