Security & Privacy MCP Connection Information
Updated
by Josh Gray
This security policy applies to every Insightech MCP connector, regardless of which AI assistant you're using (Claude, Microsoft Copilot, Google Gemini, or ChatGPT). Where a platform has a nuance worth knowing, it's noted at the end.
What Insightech Receives
Your questions are processed by your AI assistant, which calls the Insightech MCP server to retrieve or edit analytics data. Query text and tool parameters relevant to a request are sent to Insightech. Insightech never receives your AI platform's login credentials.
How Access Is Controlled
- Each user authenticates individually with their own Insightech account, using your existing sign-in method — including multi-factor authentication where enabled.
- Insightech authorizes every request against that specific user's own permissions. You can only reach the profiles your account already has access to — connecting an AI assistant grants no additional access.
- Access tokens are opaque, bound to the Insightech MCP service, and can be revoked at any time.
- Sign-in requires a verified email address, and revoked accounts are rejected.
Data Region
Each connector is locked to one Insightech data region and refuses requests for profiles hosted in another region. Choose the setup guide and endpoint matching your data region so your analytics data stays there.
Removing the Integration
Remove the connector or data store from your AI assistant's settings. To also invalidate existing Insightech sessions for affected users, ask your Insightech representative to revoke their access.
Platform Specific Notes
- Google Gemini Enterprise shows an explicit on-screen notice when you configure the connector, noting that query text and tool parameters may be sent to the third party (Insightech) and that Insightech may be able to link that data with your identity. This is the same access model described above, just disclosed inline as part of Google's connector setup flow.
- Microsoft Copilot agents in the marketplace, including Insightech's, are reviewed and certified by Microsoft prior to listing - this doesn't change your individual data access, which is still scoped per-user as above.
- Claude custom connectors don't require organization-wide approval by default; if your workspace restricts which connectors can be added, that's a setting managed by your Claude admin, separate from Insightech's own access controls.
Getting Help
Questions about what's shared or how to revoke a specific user's access — contact your Insightech representative or support@insightech.com.