MCP server security

A detailed look at how Symmy MCP servers protect the data in your ERP — from permissions and the audit log to EU-based operation.

How data travels between the AI and your ERP

The MCP server is not a copy of your data. It is an intermediary that verifies every AI request and asks your ERP only for what you actually need.

The AI asks Claude · ChatGPT

Claude or ChatGPT sends a request — say, “how much does customer X owe us”. It has no direct access to the ERP; it talks exclusively to the MCP server.

The MCP server verifies and translates Symmy MCP server

The server checks who is asking and which modules they are allowed to see, then translates the request into a specific API call to your ERP.

Only the answer comes back POHODA · Money · Helios…

Only the data for that specific request goes to the AI — no bulk exports. Your data stays where it is: in your ERP.

The five pillars of the security model

The same principles we state for every MCP server — here with the details customers ask us about most often.

01

Read-only until you say otherwise

We always enable a new MCP server in read-only mode. Writes — issuing a document, creating a contact — are activated separately per module, and every write action is confirmed by a human in the AI client before it happens. Nothing gets created or overwritten by accident.

02

Module-level permissions

Permissions are set per module, not wholesale. Invoices and stock, yes — payroll and employee personal data, never. And you can change or narrow the setup at any time.

03

Audit log

Every request is written to the audit log: who asked, when, what the request was and what data was returned. You can always prove what the AI did with the data — to management, an auditor, or yourself.

04

Data in the EU

The MCP servers run in European data centres and a data processing agreement (DPA) is part of the deal. Your data is never used to train AI models — it is passed on solely as the answer to a specific request in your conversation.

05

OAuth 2.0, no shared keys

Every user signs in as themselves via OAuth 2.0 — no shared API key floating around the company. When an employee leaves, you simply revoke their access; nobody else is affected.

A secure connection to your ERP

Security does not end with permissions — how the MCP server connects to your ERP matters too.

Encryption all the way

Communication between the AI client, the MCP server and your ERP is encrypted (TLS/HTTPS).

Whitelisting or VPN

The MCP server connects to your ERP from fixed IP addresses you allow on your firewall, or through a VPN tunnel.

Access can be switched off at any time

You can switch the whole link off in one step — by revoking access or closing the tunnel. Your ERP keeps running completely unchanged.

Choosing an AI tool for your company data? We wrote a checklist of questions to ask every vendor — including us.

Read the checklist in ERPedia →

Security FAQ

Does the AI see all the data in our ERP?

No. It sees only the modules you explicitly allow, and by default it can only read them. Data is also passed on only as the answer to a specific request — no bulk exports.

Will our data be used to train AI models?

No. Your data is not used to train AI models — this is covered by the data processing agreement (DPA), and data is passed on solely as the answer to a request in your conversation.

What if an employee leaves the company?

Every user has their own access via OAuth 2.0. You revoke it in one step, and the audit log shows retrospectively what they asked and when. Other users are not affected.

Can the AI accidentally overwrite or delete something?

Not in the default mode — the MCP server only reads data. Writes are enabled separately per module, and every write action is confirmed by a human before it happens.

Where does our data physically run?

Your ERP stays where you run it today — on your premises or with your hosting provider. Symmy MCP servers run in European data centres, and data only passes through them as answers to requests.

Security questions? Let’s go through them on a demo

We will show you the permission setup, the audit log and the connection to your ERP — no strings attached.

Useful tips and insights from the world of ERP and integrations, for free

From time to time we share the experience, advice and know-how we gain from working with our partners.