Skip to content

Security

Your agent gets exactly the access you have

Every MCP tool call runs inside the permissions you already grant that person. Nobody at either end of a shared connection ever handles a credential.

Compliance

  • SOC 2 Type II
  • ISO 27001 certified
  • GDPR compliant
  • HIPAA compliant

One security review covers every application your people reach through Elaichi, not one review per app.

Reports and certificates in the Trust Center

01 · Credentials

Nobody ever handles a credential

Connecting an application happens in a hosted flow. The credential is encrypted at rest in a dedicated vault, and the API returns it to nobody, not to a person and not to a model.

In once

through a hosted sign-in

Handed back to

  • A person in the console
  • A model in any client
  • A colleague you share with
The credential goes in once and does not come back out. Tools run server-side, with the credential resolved at the moment of the call and nowhere else.

Share a capability, not a password

A colleague uses your connection for one constrained job. They call the application through it without ever seeing the credential, and they cannot step outside the tools you shared with them.

02 · Access

An agent gets exactly the access of the person it acts for

Every call is checked against the permissions that person holds right now, across 8 predefined roles and any custom role you build. Revoke a share, disconnect an account or remove someone, and the very next request reflects it.

38
permissions to build a role from
8
predefined roles, plus custom roles
~1 min
for a role change to land everywhere
Nothing about the tools changed. Access did, and the same three calls stop landing from the next request onward.

03 · Restrictions

You choose what the agent can even see

Restrictions work on individual tools, not on whole applications. Set them on a role, or on one person, where a person-level rule can only narrow what the role allows.

Where it is checked

  1. 1 Listing connectors and tools
  2. 2 Connecting an account
  3. 3 Saving a toolbox
  4. 4 Advertising tools to a client
  5. 5 Running a call
  6. 6 The outbound request
Two tools from the same application, one allowed and one not. A restricted tool is left out of the list the agent is shown, and a call to it is refused.

Audit

Every action is attributed to a person

The append-only log records who, or which agent acting on whose behalf, did what, down to the record changed in the third-party system.

Every tool call lands there with the tool, the connection, the status and the duration. Forward the whole stream to your Datadog, with batched retried delivery and a dead-letter queue.

Audit log

Append only

  • EC

    Emily Carter

    Claude

    Salesforce salesforce.update_opportunity

    Opportunity 006Ag00000R2xQ1

    200 312 ms
  • EA

    Elaichi Agent

    acting for Jake Morgan

    Jira jira.transition_issue

    OPS-2841, moved to In Review

    200 288 ms
  • MB

    Megan Brooks

    ChatGPT

    Slack slack.post_message

    Message in #revenue-ops

    200 194 ms
  • RH

    Ryan Hayes

    Cursor

    Notion notion.update_page

    Refused, restricted for this role

    Restricted 9 ms

The rest of the review

Short answers to the questions that come next.

Sign in the way your company already does
SAML SP and OIDC RP implemented in-house, so no third-party auth vendor sits in the login path. DNS-verified domains, enforced SSO, JIT provisioning, SCIM v2 user and group sync, group-to-role mapping, passkeys, and step-up auth on sensitive actions.
Cut a client off and it is off
Session, API and invite tokens are stored as keyed hashes and shown exactly once. MCP access runs on OAuth, so there is no URL or token to lose, and disconnecting a client ends its session immediately. Rate limits apply on both the data plane and the control plane.
Read from the source, at the moment of the call
Deals, tickets and pages are fetched from the application when an agent asks for them. You also choose where the data Elaichi does hold lives, across 3 regions: US, EU and APAC.
Your models, your bill
Bring your own keys for 4 model providers. Nothing is routed through us for inference, so prompts and results do not become our data, and there is no markup and no lock-in.
Offboard someone in one action
Removing a member runs a preflight. Personal connections that shared toolboxes depend on must be transferred or deleted before the removal completes, and unreferenced connections are cleaned up, vault account included.
Automations will run under the same rules
Scheduled automations, and dashboards computed from your connected apps, are launching soon. They will be checked against the same roles and restrictions as the person they act for, and land in the same audit log.

Bring your security team. We will go line by line.

Permissions, restrictions, audit, SSO, SCIM and data residency, on the record. Or start a trial and read the audit log yourself.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.