OAuth-protected access
Remote MCP access uses OAuth. Access tokens are signed, issuer-checked, audience-bound to the Gummble MCP resource, and associated with an individual Gummble account.
Security & procurement
A plain-language snapshot of how Gummble protects access, what the MCP server can do, what data is handled, and which enterprise controls are not available today.
Controls in place
Remote MCP access uses OAuth. Access tokens are signed, issuer-checked, audience-bound to the Gummble MCP resource, and associated with an individual Gummble account.
All 14 MCP tools are declared read-only and non-destructive. They search and return Gummble library content; they cannot write to your codebase, design files, projects, or documents.
Traffic to Gummble is encrypted in transit. Backend access is tied to the authenticated user so plan entitlements and rate limits can be enforced per account.
For MCP requests, Gummble records the account, tool called, time, result metadata, and sanitized search terms. Common identifiers and secrets are redacted before analytics capture.
Gummble receives tool requests, not the surrounding conversation in your AI client. Search terms are operational data and should not contain secrets or confidential customer information.
Service providers
These providers support delivery, operations, analytics, and billing. The privacy policy controls if this summary and the policy ever differ.
Procurement boundaries
Gummble does not currently claim SOC 2 or ISO 27001 certification. Do not treat this page as a certification report.
The current Team plan supports account-based access and domain join, but does not include SAML or enterprise SSO.
No standard data processing addendum is published today. Send required terms before purchase so fit can be assessed without assumptions.
Gummble does not currently publish a contractual uptime commitment or a public status page.
Need a vendor answer?
We will answer against the current product. Requirements that are not supported will be called out explicitly.