All documentation
On this page
For IT and security
Mailbox MCP for IT and security teams
The answers a vendor questionnaire asks for, in the order it asks them, with a link to the page that says more.
Mailbox MCP is a hosted MCP server: a person connects a mailbox they already own and an AI assistant they already use can read and act on it, on their instruction, through the Model Context Protocol. Everything below is true of the service as built on the date at the foot of the page, and every figure is the one the privacy policy states, because both read the same constant.
Company
| Legal entity | BSolve IT Limited, trading as Mailbox MCP |
| Registered in | England and Wales, company number 04607330 |
| VAT number | GB 806 170 747 |
| Registered office | 5 Epping Close, Barton Seagrave, Kettering, Northamptonshire, NN15 6TR, United Kingdom |
| Security contact | support@mailbox-mcp.com, read by the person who built the service |
| Data protection | The controller for account data; the processor for the customer's mail and calendar data, under the data processing agreement |
Hosting and location
Hosting is on
365i, which is
part of BSolve IT Limited, the processor: the
servers are run by us, in London. The data-centre operator
behind them is a United Kingdom provider whose name we give on request,
and it holds no key to any customer data. The service and the control
panel run on a
365i Unmanaged VPS
in London, United Kingdom; this website runs on
365i
hosting, also in the UK, behind the StackCDN edge cache. There is
no CDN and no third-party proxy in front of the service itself, and
there is no other region. The emails the service sends, such as an
address confirmation or a receipt, go out through the product's own
mailbox on 365i's mail platform at mail.mailbox-mcp.com.
Nothing that holds customer data is hosted outside the United Kingdom
except payment, which is Stripe's and is described below.
MoreSecurity: how connections are made
Sub-processors
4 organisations process something on our behalf. Stripe holds a payment record, the data-centre operator holds an encrypted copy of what we store, and Cloudflare and Brevo now handle a support request when a customer sends one from the control panel. None of the four is ever given a password, a token or the contents of a mailbox message. 365i is not among them: it is part of BSolve IT Limited, so the hosting is ours rather than a sub-processor's, and the organisation listed for it is the data-centre operator behind our servers. Your mail provider, your calendar provider and your AI provider are not on this list either: you chose each of them, they already hold what they hold, and the privacy policy describes what reaches each.
| Company | What for | Where, and customer data |
|---|---|---|
| Stripe | Payment. Card details are entered on Stripe's systems and never reach ours; we hold the record that a payment happened and the account email it was made under. | United States and European Union, under Stripe's own data processing agreement and its own transfer mechanism. |
| The data-centre operator | The United Kingdom provider whose infrastructure our servers run on: the 365i VPS the service and the control panel run on, the 365i hosting this website and the off-site backup copy sit on, and the mail platform the service's own emails go out through. Named on request. | United Kingdom. It holds no key to any customer data: everything we hold is encrypted as the privacy policy describes, and the keys are ours. |
| Cloudflare | The uptime monitor: it requests the service's 2 public health endpoints every 10 minutes and keeps the results. Also stores a support request sent from the control panel, in a Cloudflare Worker with its own database, and its Workers AI (Cloudflare's hosted model) drafts the reply we read before we answer; the customer never sees an unsent draft. | United States (San Francisco), on a global network. The health checks carry no customer data. A support request does: the customer's name and account email, their message, how urgent they said it is, which mailbox it concerns if they chose one, and, only if they tick to include it, diagnostic detail such as plan, account age, each mailbox's provider and connection state, recent error codes and which AI clients are connected. Never a password, a token or the contents of a mailbox message. A closed ticket is deleted 12 months later; one still open or answered is kept until it is closed. |
| Brevo | Delivers the monitor's alert emails to us when the service stops answering. Also sends the acknowledgement to the customer, with their reference, and a notification to us, when a support request is submitted. | France (Paris). An alert carries the endpoint's status and nothing else. A support email carries the customer's name, account email and their message as the text of the email; never a password, a token or the contents of a mailbox message. |
Changes to this list are announced by email to the account address 30 days before they take effect, and a customer who objects can close the account before then; the DPA sets that out.
MorePrivacy: who else is involved
What we hold and for how long
Message content is never stored. Mail and calendar data pass through the server in memory while a request is served and are not written to disk, so there is no archive of a customer's mail here to be breached, subpoenaed or lost. What is held is the account, the mailbox connection settings, an encrypted credential per mailbox and per connected calendar, and the records below.
| Account details and credentials | Until the account is closed or the mailbox removed, then deleted |
| Record of each MCP call | 90 days, then deleted. The rolling limit reads only the last 24 hours of it |
| Audit record of each MCP call | 400 days, then deleted |
| IP addresses | Part of the 2 records above and deleted with them |
| Web server logs | A rolling 90 days |
| Payment records | As long as UK tax law requires accounting records to be kept |
| Support emails | Up to 2 years |
MorePrivacy: how long we keep it Security: what we hold
Encryption
In transit: TLS on every path. The AI client to the service, the control panel and this website are HTTPS; Microsoft 365 and Google are reached on fixed encrypted endpoints that cannot be downgraded. A mailbox on a custom IMAP host uses the ports the customer gives, exactly as a desktop mail client does, and the privacy policy says in as many words that a plaintext port is a choice available to them.
At rest: every stored credential is encrypted with AES-256-GCM under its own random key, and that key is wrapped by a master key that is held outside the database and outside the source code, in a file only the machine's administrator account can read and which the operating system hands to the service at start. Each encrypted credential is bound to the mailbox it belongs to, so a row lifted from the database decrypts against nothing else. Control panel passwords are Argon2id hashes; the token an AI client authenticates with is stored only as a hash of itself.
MorePrivacy: how it is protected Security
Backups
The database is backed up every night, encrypted with a key of its own, and 14 nights are kept, so a fault that quietly corrupted rows for a week is still recoverable from before it began. A verified copy is filed off the machine each night, also in the United Kingdom. The restore is tested every week: the newest backup is restored into a scratch database and a real credential is decrypted out of it, which is the only test that proves a customer could be put back to work rather than that bytes moved. The master key is asserted absent from every backup, so a leaked backup file yields nothing, and a backup job that fails raises an alert rather than a quiet gap.
MoreStatus: what the monitor checks
Access control
The account: a password of at least 12 characters, stored as an Argon2id hash, with time-based one-time password (TOTP) two-factor authentication available on every account. The panel signs you out after 30 minutes without activity in the browser; the underlying session expires after 7 days idle or 30 days at most, and every live session is listed under Settings where it can be ended. Changing the password ends every one of them.
Each connection: a connection made by signing in carries a permission level, read only, draft and file or send and delete, with the calendar as a separate switch, chosen at approval, changed in the panel without reconnecting, and enforced by the server on every call before the AI client is consulted.
Each person, with Team Access: a named person is invited by email address and given their own connector URL per mailbox, a level from the same 3, the calendar on or off, a daily cap and a list of mailboxes, all set by the account holder and changed without reconnecting. The invitation is accepted only by an account whose verified address is the one invited. Every call carries the person who made it in the activity record. Removal is one action and ends every connection the person held on its next call.
Revocation: from the customer's own side, at any time, without us. Removing a mailbox in the panel deletes its credential and every AI client loses it that minute; a Microsoft or Google grant can be withdrawn at the provider; an IMAP app password can be revoked at the provider. An organisation can revoke the app for every user at once, as the administrator pages describe. Our side: the servers are administered only by the people who run the company, and nobody reads a customer's mail except where the customer has asked us to look at something specific or where investigating a fault or abuse requires it.
MoreSecurity: what you can limit Security: per person, with Team Access Security: how to revoke access
Audit
Every MCP call is logged, per customer, and kept for 400 days. A row holds which tool ran, when, on which mailbox, whether it worked, the IP address it was called from, and, where a read raised one, the name of a warning sign as a short label. A row never holds the contents of a message, a filename or a file. The customer reads the log on the control panel's Activity page, filtered by mailbox, tool and outcome, and exports it as a CSV with the same filter applied, so the file downloaded is the rows that were on screen.
Availability
The status page shows the current state, 90 days of history and every incident, read from a monitor on Cloudflare that requests the service's 2 public health endpoints every 10 minutes and alerts the person who runs the service on consecutive failures. The monitor keeps its own status view on its own provider, so a status page exists even when this website does not. No service level agreement is offered, and the terms say so plainly: the service depends on the customer's mail provider, their AI provider and the network between them, none of which we control.
MoreService status Terms: availability
Incident and breach notification
The commitment
Where a personal data breach affects a customer's data, we notify that customer without undue delay and within 72 hours of confirming the breach, by email to the account address, with what was affected and what to do. Where the law requires it, we notify the Information Commissioner's Office within 72 hours.
Because message content is never stored, a breach of our systems cannot expose an archive of a customer's mail. What it could expose is the encrypted credentials and the account records, and the notification would say which, and would tell the customer to revoke the credentials at their provider, which they can do without us and which ends the exposure whatever state our systems are in.
Vulnerability disclosure
A security.txt (RFC 9116) is published at
/.well-known/security.txt
and names support@mailbox-mcp.com
as the contact. A report is acknowledged, investigated, answered with
what was found, and credited if the reporter wants credit. There is no
bug bounty and no payment. Please do not test against another
customer's mailbox, and give us a reasonable chance to fix something
before publishing it.
MoreSecurity: reporting a security problem
Certifications
None. No SOC 2 report, no ISO 27001 certificate, no Cyber Essentials certificate, and no third-party penetration test. If the questionnaire requires one of those, the honest entry is "no", and we would rather you had it from this page than from the fourth email of a procurement.
What stands in for them is published rather than asserted: a security page whose every claim is checked against the engine source, a threat model that puts one of 3 words, mitigated, partially or not solved, against every attack it names and concedes in the same table it claims, a privacy policy that states the protection mechanisms themselves, a changelog of every release, and the disclosure address above.
Administrators
If your organisation requires an administrator to approve third-party apps, one page for each console carries the app by its identifiers, the permissions it asks for and what each is used for, the one-step approval and the way to revoke it: Microsoft 365 administrators and Google Workspace administrators. On Microsoft the app registers delegated permissions only and no application permissions; on Google, Gmail is connected by an app password over IMAP and only the calendar has an OAuth app.
Data processing agreement
The data processing agreement is a page, incorporated into the terms of service by a sentence in their governing section, so it applies to every business customer without anything being signed. Written by us, not yet reviewed by a solicitor; if your procurement needs a countersigned copy, ask.
Contact
support@mailbox-mcp.com, for the questionnaire itself, for anything on this page that needs a longer answer, and for a security report. It reaches the person who built the service, and a reply comes within one working day, Monday to Friday, UK time.
Frequently asked questions
Where is my data stored?
In the United Kingdom. Hosting is on 365i, which is part of BSolve IT Limited, the processor: the servers are run by us, in London. The data-centre operator behind them is a United Kingdom provider whose name we give on request, and it holds no key to any customer data. The service and the control panel run on a 365i Unmanaged VPS and this website on 365i hosting, all in the UK. Your mail and your calendar are not stored at all: they pass through the server in memory while a request is served and are never written down. What is stored is your account details, your mailbox connection settings, an encrypted credential per mailbox and per connected calendar, a record of each MCP call, and the payment record, all on that London server, with an encrypted backup of the database filed off the machine every night, also in the UK. The one exception is payment: card details are entered on Stripe's systems and never reach ours.
Do you have SOC 2?
No. Mailbox MCP holds no SOC 2 report, no ISO 27001 certificate and no Cyber Essentials certificate, and has not had a third-party penetration test. What stands in for them is published rather than asserted: a security page whose every claim is checked against the engine source, a threat model that puts one of 3 words, mitigated, partially or not solved, against every attack it names, a privacy policy that states the protection mechanisms themselves, a changelog of every release, and a security.txt with a disclosure address that reaches the person who built the service. If your procurement requires a certification, this product does not meet that requirement today, and we would rather you knew before the questionnaire than after.
Is there a DPA?
Yes. The data processing agreement is published at https://mailbox-mcp.com/dpa/ and forms part of the terms of service where the service is used for a business, so it applies without anything being signed. It names the customer as controller and BSolve IT Limited as processor, sets out the subject matter, the data and the data subjects, the processor obligations under UK GDPR, the sub-processors, the breach commitment, international transfers and deletion on termination. It was written by us and has not yet been reviewed by a solicitor, and the page says so; if your procurement needs a countersigned copy, ask at support@mailbox-mcp.com.
How do I revoke access?
From your own side, at any time, without asking us. In the control panel, removing a mailbox deletes the credential held for it and every AI client loses that mailbox that minute; disconnecting a calendar does the same for its credential; each connection made by signing in has its own revocation and its own permission level, changed in the panel without reconnecting. At the provider, a Microsoft 365 or Google sign-in can be withdrawn from the account's own permissions page, and an IMAP app password can be revoked or the mailbox password changed, and access ends immediately either way. An organisation can revoke the app for every user at once from the Microsoft Entra admin centre or the Google Admin console, as the administrator pages describe.
Who are your sub-processors?
4, and 2 of them never see customer data. Stripe takes payment and holds the card details, in the United States and the European Union under its own data processing agreement and transfer mechanism. The data-centre operator behind our servers is a United Kingdom provider whose name we give on request; it holds no key to any customer data. Hosting itself is on 365i, which is part of BSolve IT Limited, the processor, so it is not a sub-processor: the servers are run by us, in London. Cloudflare, in the United States, runs the uptime monitor, which reads only the 2 public health endpoints and holds no customer data. Brevo, in France, delivers that monitor's alert emails to us and holds no customer data either. Your mail provider, your calendar provider and your AI provider are not sub-processors of ours: you chose each of them, and they already hold what they hold. Changes to the list are announced by email to the account address 30 days before they take effect.
What is your breach notification process?
Where a personal data breach affects your data, we notify you by email to the account address without undue delay and within 72 hours of confirming it, saying what was affected and what to do. Where the law requires it, we notify the Information Commissioner's Office within 72 hours of becoming aware. Because message content is never stored, a breach of our systems cannot expose an archive of your mail, which is the single most useful property of the design; what it could expose is the encrypted credentials, and the notification would say so and tell you to revoke them at your provider, which you can do without us.