GummbleGummble
AppsPricing

Security & procurement

The facts before your vendor review.

A plain-language snapshot of how Gummble protects access, what the MCP server can do, what data is handled, and which enterprise controls are not available today.

Send procurement requirementsRead the privacy policy

Current posture

Built for a transparent first-pass review, not as a certification claim.

MCP tools
14
Write tools
0
MCP auth
OAuth
Reviewed
July 26, 2026

Controls in place

A narrow, account-bound research surface.

01

OAuth-protected access

Remote MCP access uses OAuth. Access tokens are signed, issuer-checked, audience-bound to the Gummble MCP resource, and associated with an individual Gummble account.

02

Read-only tool surface

All 14 MCP tools are declared read-only and non-destructive. They search and return Gummble library content; they cannot write to your codebase, design files, projects, or documents.

03

Encrypted in transit

Traffic to Gummble is encrypted in transit. Backend access is tied to the authenticated user so plan entitlements and rate limits can be enforced per account.

04

Scoped operational logging

For MCP requests, Gummble records the account, tool called, time, result metadata, and sanitized search terms. Common identifiers and secrets are redacted before analytics capture.

What the MCP service handles.

Gummble receives tool requests, not the surrounding conversation in your AI client. Search terms are operational data and should not contain secrets or confidential customer information.

AI conversation content
Not received or stored by Gummble.
Customer files and documents
Not uploaded or stored by the MCP server.
MCP usage data
Tool activity and sanitized search data; retained for up to 24 months.
Account deletion
Personal data is deleted within 30 days, except records retained for legal or billing reasons.

Service providers

Core subprocessors and infrastructure.

These providers support delivery, operations, analytics, and billing. The privacy policy controls if this summary and the policy ever differ.

CloudflareMCP edge runtime, content delivery, and storage
VercelWeb application hosting
RailwayAPI hosting
PostHogProduct analytics
SentryError monitoring
PolarSubscription billing and payment processing

Procurement boundaries

Not currently offered.

SOC 2 / ISO certification

Not currently certified

Gummble does not currently claim SOC 2 or ISO 27001 certification. Do not treat this page as a certification report.

SAML / enterprise SSO

Not currently offered

The current Team plan supports account-based access and domain join, but does not include SAML or enterprise SSO.

Standard DPA

Not publicly offered

No standard data processing addendum is published today. Send required terms before purchase so fit can be assessed without assumptions.

Contractual uptime SLA

Not currently offered

Gummble does not currently publish a contractual uptime commitment or a public status page.

Need a vendor answer?

Send the exact checklist before you buy.

We will answer against the current product. Requirements that are not supported will be called out explicitly.

enterprise@gummble.com
Gummble

Browse thousands of curated UI screenshots from the world's best apps. Find design inspiration for your next project.

Browse

  • Browse Apps
  • App Design Inspiration
  • Browse Flows
  • Browse Screens
  • Browse Patterns

Categories

  • All Categories
  • Dating Apps
  • AI Photo Editors
  • AI Chatbots
  • Finance Apps
  • Budget Planners
  • Habit Trackers
  • Language Learning

UI Patterns

  • Onboarding
  • Login
  • Checkout
  • Empty States
  • Search
  • Settings

Company

  • Pricing
  • Gummble UI Design MCP
  • MCP for AI App Builders
  • Mobbin Alternative
  • Mobbin MCP Alternative
  • Refero Alternative
  • About
  • Blog
  • Affiliate Program

© 2026 Gummble. All rights reserved.

SecurityPrivacyTerms