Skip to main content

Is My Data Secure When Using the VRTrust MCP with AI Assistants?

How the VRTrust MCP and AI assistants like Claude protect your accounting and client data.

The short answer

Yes. The VRTrust MCP gives an AI assistant the same access you already have in VRTrust, and nothing more. You sign in with your own account, your assistant asks for your approval before every change, and the MCP cannot move money or touch payment credentials.

This article covers the VRTrust MCP connector (https://mcp.vrplatform.app/directory).

There are two layers to understand:

  1. The VRTrust MCP controls what the assistant can see and do in your VRTrust account.

  2. The AI assistant (for example, Claude or ChatGPT) stores the conversation, including any data the assistant reads from VRTrust. Its provider's security and privacy policies apply to that data.


How sign-in works

You connect with your own VRTrust login through OAuth, the same secure sign-in standard used by most business apps. Your password is entered on the VRTrust sign-in page and is never shared with the AI assistant.

  • Your account, your access. The MCP applies your VRTrust user permissions to every request.

  • One person, one connection. Each team member signs in individually, so access always follows that person's own role.

  • No stored credentials. The MCP server does not keep credentials of its own. It only forwards your authenticated requests to the VRTrust API.

  • API tokens are a fallback only. Use one only if your AI tool can't complete OAuth sign-in. A token carries its own permissions rather than a person's sign-in, so give each person their own token and never share one. Treat a token URL like a password: don't share, commit or screenshot it.


What the assistant can and can't do

The assistant reads data when you ask, and your assistant asks for your approval before it changes anything. Your role and VRTrust's accounting locks still apply to everything it does.

Safeguard

What it means for you

Reads follow your role

It can only see teams and records your VRTrust user can see. A Read Only member gets no write access.

Changes need your approval

The MCP marks every create, update and delete as a change that needs approval, so your AI assistant asks you before running it. This only works if you keep approvals on. If you set a change tool to "Allow always", the assistant can make changes without asking.

Accounting locks are respected

Locked periods stay locked. The MCP can't bypass them.

Emails only when you ask

The assistant is instructed to send owner invitations and statement emails only when you specifically ask, and you approve each one like any other change.

Only reviewed actions

The MCP allows only a server-side list of reviewed operations. Tool inputs, URL parameters or headers can't expand it.

No money movement

It cannot initiate transfers, execute or retry provider payments, or manage payment credentials. Bank and payout credentials never pass through the AI assistant.


Who else handles your data

To run the MCP, VRTrust uses these service providers:

  • Clerk handles sign-in.

  • Cloudflare hosts the MCP server.

  • Sentry receives operational monitoring data, such as which tool ran, how long it took and whether it failed. It doesn't receive your records.

See the VRTrust privacy policy for details.


What happens to your data inside the AI assistant

When the assistant reads VRTrust data, that data becomes part of your conversation and is stored by the assistant's provider. Encryption, model training, retention and certifications are set by that provider, not by VRTrust, and they differ between personal and business plans.

Review your provider's policies before connecting the assistant:

Using a different AI assistant? Check that provider's data and training policies the same way.


Best practices for accounting firms and property managers

  • Use a business plan. Business plans from AI providers usually keep your data out of model training by default. On a personal plan, check your privacy settings and turn off model training on your chats.

  • Give the least access needed. Assign a Read Only VRTrust role to anyone who only needs to review data.

  • Keep approvals on for changes. Read each proposed change before approving it. Don't use "Allow always" for tools that make changes. That approval step is what keeps changes under your control.

  • Sign in individually. Have each person connect with their own VRTrust login instead of sharing an API token.

  • Check your own obligations. Confirm that your firm's confidentiality and client-data policies allow third-party AI tools.


How to disconnect and revoke access

You can disconnect at any time.

  1. Remove the connector in your AI assistant's settings. The assistant stops using VRTrust once the connector is removed.

  2. Delete any API token you used under Settings > API tokens in VRTrust.

  3. Revoke the OAuth sign-in grant by contacting VRTrust support. Removing the connector doesn't end the grant on its own. Support will end it for you.


Frequently asked questions

Can the AI pay owners or move money?
No. The MCP can record payments that already happened, but it cannot initiate transfers or execute payments.

Can the AI see my clients' bank logins?
No. The MCP cannot view or manage payment credentials.

Can the AI change my books without me knowing?
Not if you keep approvals on. Your assistant asks before each change, unless you've set that tool to "Allow always". Locked periods stay locked either way.

Will my data be used to train AI models?
That depends on your AI provider and plan, not on VRTrust. See the Claude and ChatGPT links above.

Can my staff see more than they should?
No, as long as each person signs in with their own VRTrust account. The MCP then enforces that person's role. Don't share API tokens between people.

Where can I get my AI provider's SOC 2 report?
Request it through the provider's trust center: Anthropic Trust Center for Claude, or OpenAI Trust Portal for ChatGPT.

Still have questions? Contact VRTrust support and we'll walk you through it.


Related articles

Did this answer your question?