OAuth-protected access
Remote MCP access uses OAuth. Access tokens are signed, issuer-checked, audience-bound to the Gummble MCP resource, and associated with an individual Gummble account.
Security & procurement
Gummble connects through OAuth, operates with read-only tools, and encrypts all traffic in transit. Here is how we keep your information safe and what we are building next.
Controls in place
Remote MCP access uses OAuth. Access tokens are signed, issuer-checked, audience-bound to the Gummble MCP resource, and associated with an individual Gummble account.
All 14 MCP tools are declared read-only and non-destructive. They search and return Gummble library content; they cannot write to your codebase, design files, projects, or documents.
Traffic to Gummble is encrypted in transit. Backend access is tied to the authenticated user so plan entitlements and rate limits can be enforced per account.
For MCP requests, Gummble records the account, tool called, time, result metadata, and sanitized search terms. Common identifiers and secrets are redacted before analytics capture.
Gummble receives tool requests, not the surrounding conversation in your AI client. Search terms are operational data and should not contain secrets or confidential customer information.
Service providers
These providers support delivery, operations, analytics, and billing. The privacy policy controls if this summary and the policy ever differ.
Enterprise roadmap
Formal SOC 2 and ISO 27001 certification are on our roadmap. This page reflects the controls we follow today — reach out if you need details for your review.
The current Team plan supports account-based access and domain join. SAML and enterprise SSO are planned for a future release.
We can work with your data processing terms. Reach out at the address below and we will review your requirements directly.
A contractual uptime commitment and public status page are in development. We are happy to share current availability data on request.
Questions? We are here to help.
Whether it is a security questionnaire, a specific compliance requirement, or just a quick question — we are happy to help.