The short answer
Yes. The VRTrust MCP gives an AI assistant the same access you already have in VRTrust, and nothing more. You sign in with your own account, your assistant asks for your approval before every change, and the MCP cannot move money or touch payment credentials.
This article covers the VRTrust MCP connector (https://mcp.vrplatform.app/directory).
There are two layers to understand:
The VRTrust MCP controls what the assistant can see and do in your VRTrust account.
The AI assistant (for example, Claude or ChatGPT) stores the conversation, including any data the assistant reads from VRTrust. Its provider's security and privacy policies apply to that data.
How sign-in works
You connect with your own VRTrust login through OAuth, the same secure sign-in standard used by most business apps. Your password is entered on the VRTrust sign-in page and is never shared with the AI assistant.
Your account, your access. The MCP applies your VRTrust user permissions to every request.
One person, one connection. Each team member signs in individually, so access always follows that person's own role.
No stored credentials. The MCP server does not keep credentials of its own. It only forwards your authenticated requests to the VRTrust API.
API tokens are a fallback only. Use one only if your AI tool can't complete OAuth sign-in. A token carries its own permissions rather than a person's sign-in, so give each person their own token and never share one. Treat a token URL like a password: don't share, commit or screenshot it.
For setup steps, see Connect an AI Assistant Using VRTrust MCP.
What the assistant can and can't do
The assistant reads data when you ask, and your assistant asks for your approval before it changes anything. Your role and VRTrust's accounting locks still apply to everything it does.
Safeguard | What it means for you |
Reads follow your role | It can only see teams and records your VRTrust user can see. A Read Only member gets no write access. |
Changes need your approval | The MCP marks every create, update and delete as a change that needs approval, so your AI assistant asks you before running it. This only works if you keep approvals on. If you set a change tool to "Allow always", the assistant can make changes without asking. |
Accounting locks are respected | Locked periods stay locked. The MCP can't bypass them. |
Emails only when you ask | The assistant is instructed to send owner invitations and statement emails only when you specifically ask, and you approve each one like any other change. |
Only reviewed actions | The MCP allows only a server-side list of reviewed operations. Tool inputs, URL parameters or headers can't expand it. |
No money movement | It cannot initiate transfers, execute or retry provider payments, or manage payment credentials. Bank and payout credentials never pass through the AI assistant. |
Who else handles your data
To run the MCP, VRTrust uses these service providers:
Clerk handles sign-in.
Cloudflare hosts the MCP server.
Sentry receives operational monitoring data, such as which tool ran, how long it took and whether it failed. It doesn't receive your records.
See the VRTrust privacy policy for details.
What happens to your data inside the AI assistant
When the assistant reads VRTrust data, that data becomes part of your conversation and is stored by the assistant's provider. Encryption, model training, retention and certifications are set by that provider, not by VRTrust, and they differ between personal and business plans.
Review your provider's policies before connecting the assistant:
Claude (Anthropic): Privacy Center and Trust Center
ChatGPT (OpenAI): Enterprise privacy, Privacy policy and Trust Portal
Using a different AI assistant? Check that provider's data and training policies the same way.
Best practices for accounting firms and property managers
Use a business plan. Business plans from AI providers usually keep your data out of model training by default. On a personal plan, check your privacy settings and turn off model training on your chats.
Give the least access needed. Assign a Read Only VRTrust role to anyone who only needs to review data.
Keep approvals on for changes. Read each proposed change before approving it. Don't use "Allow always" for tools that make changes. That approval step is what keeps changes under your control.
Sign in individually. Have each person connect with their own VRTrust login instead of sharing an API token.
Check your own obligations. Confirm that your firm's confidentiality and client-data policies allow third-party AI tools.
How to disconnect and revoke access
You can disconnect at any time.
Remove the connector in your AI assistant's settings. The assistant stops using VRTrust once the connector is removed.
Delete any API token you used under Settings > API tokens in VRTrust.
Revoke the OAuth sign-in grant by contacting VRTrust support. Removing the connector doesn't end the grant on its own. Support will end it for you.
Frequently asked questions
Can the AI pay owners or move money?
No. The MCP can record payments that already happened, but it cannot initiate transfers or execute payments.
Can the AI see my clients' bank logins?
No. The MCP cannot view or manage payment credentials.
Can the AI change my books without me knowing?
Not if you keep approvals on. Your assistant asks before each change, unless you've set that tool to "Allow always". Locked periods stay locked either way.
Will my data be used to train AI models?
That depends on your AI provider and plan, not on VRTrust. See the Claude and ChatGPT links above.
Can my staff see more than they should?
No, as long as each person signs in with their own VRTrust account. The MCP then enforces that person's role. Don't share API tokens between people.
Where can I get my AI provider's SOC 2 report?
Request it through the provider's trust center: Anthropic Trust Center for Claude, or OpenAI Trust Portal for ChatGPT.
Still have questions? Contact VRTrust support and we'll walk you through it.
