Your CRM never moves.

Everything on this page is true of the service as it runs today, not a roadmap. Where something is not yet in place, we say so, and say when.

  1. Your people Claude on web, desktop or phone stores: nothing
  2. Claude Understands the request, calls a tool sees: the records asked about in this turn
  3. SuiteMCP One hosted service, isolated per customer stores: encrypted refresh token · hashed access tokens · call traces, secrets redacted
  4. Your SuiteCRM Wherever you host it, as the signed-in user stores: your records, as always. The password never leaves it.

TLS everywhere · AES-256-GCM at rest · OAuth 2.1 with PKCE · audience-bound tokens · per-tenant isolation · one-click revocation

The controls, named precisely

Sign-in
OAuth 2.1 with PKCE and dynamic client registration. The CRM password is used once to sign in and never stored; the web path keeps only an encrypted, revocable refresh token.
Tokens
Access tokens live 30 minutes and are bound to this service as their audience. Refresh tokens rotate on every use with reuse detection, and are stored as hashes. Nothing is passed through to another system.
Permissions
Every call runs as the signed-in CRM user. SuiteCRM’s roles, ACLs and security groups decide what can be read or changed; SuiteMCP never re-implements them. A denial from the CRM surfaces as a plain error.
Writes
Read-only and write tools are declared separately, destructive ones are marked, and Claude asks before acting on them. The trial plan cannot write. Every write lands in SuiteCRM’s own audit timeline, attributed to the user.
Isolation and encryption
Each customer has their own CRM address and credentials; no secret is shared between tenants. Stored secrets are encrypted at rest with AES-256-GCM. Every connection is HTTPS.
Logging and revocation
Every tool call is traced with secrets redacted and payloads size-capped. Any connection can be revoked in one click, which invalidates its tokens immediately. Login attempts are throttled per user and per address.

The questions IT asks, answered in one breath each.

Does our CRM data train the model?

Anthropic states that it does not train on data from its commercial products by default; its Commercial Terms say Anthropic may not train models on Customer Content. Consumer plans (Free, Pro, Max) can differ depending on the user’s Model Improvement setting, so for business use we recommend Claude Team or Enterprise and link to Anthropic’s own policy rather than paraphrasing it.

Where does our data go, and how long is it kept?

Your CRM never moves. SuiteMCP holds no copy, no sync and no index of your records. The records a user asks about in a turn pass through the service to Claude and are not retained by SuiteMCP. SuiteMCP stores one encrypted refresh token per connection, hashed access tokens, and call traces with secrets redacted.

Where does Claude process our data?

Anthropic processes prompts in the United States and global regions under its Data Processing Addendum with Standard Contractual Clauses. Anthropic does not offer EU-resident processing for Claude on the web. Your SuiteCRM stays wherever you host it, and SuiteMCP itself runs on Hetzner in the European Union.

Can it delete everything?

It can do what the signed-in user can do, and no more. Every call runs under that person’s SuiteCRM roles. The trial plan is read-only. Tools that write are annotated as such, tools that delete are annotated as destructive, and Claude asks before it acts on them. Every write lands in SuiteCRM’s own audit timeline, attributed to the user.

What about prompt injection through CRM records?

A record can contain text that tries to instruct the model. We treat tool results as data, plans gate which tools can write, the trial cannot write at all, and Claude confirms writes with the person. We do not claim this risk is zero for any product, including ours, which is why the audit trail and one-click revocation exist.

Is MCP itself safe?

The connection uses OAuth 2.1 with PKCE, tokens bound to this service as their audience, 30-minute access tokens, refresh tokens that rotate with reuse detection, per-customer isolation, and one-click revocation. Read and write tools are declared separately, as the protocol specifies.

Anthropic’s own pages: Is my data used for model training? · Data Processing Addendum · Trust portal. Claude is a trademark of Anthropic, PBC; SuiteMCP is not affiliated with Anthropic.

What we deliberately do not do

  • No sync. We never copy your CRM into our systems.
  • No training. Commercial Claude plans do not train on your data by default.
  • No stored password. Used once to sign in, then discarded.
  • No shared secrets. Each customer has their own credentials and CRM address.
  • No silent writes. Every write is attributed to the user in SuiteCRM’s audit log.

Where things run

SuiteMCP runs on Hetzner in the European Union, on ISO 27001 certified infrastructure. Your SuiteCRM stays wherever you host it. Claude processes prompts in Anthropic’s United States and global regions under Anthropic’s Data Processing Addendum. If EU-resident model processing is a requirement, tell us; today no Claude web plan offers it, and we would rather say so than imply otherwise.

Subprocessors

CompanyPurposeLocation
Anthropic, PBC Model inference for Claude United States
Hetzner Online GmbH Hosting of the SuiteMCP service European Union

The full list, with change notice terms

Compliance, honestly

No SOC 2 report yet. Controls are aligned to the SOC 2 Security criteria and an audit is on the roadmap. Ask for our completed security questionnaire and we will send it the same day.

Incident response: if an incident affects your data we notify your technical contact without undue delay, with what happened, what was affected and what we did. Security researchers can report issues to the address below and will hear back within two working days.