Security documentation
The security index is the access point for MCP Manager’s compliance reports, live controls status, and related resources:| Document or resource | Section |
|---|---|
| SOC 2 Type 2 + HIPAA report (2025) | Trust Center → Resources |
| ISO 27001:2022 & ISO 27701:2019 certificates | Trust Center → Resources |
| TISAX Level 3 assessment result | Trust Center → Resources |
| Penetration test report | Trust Center → Resources |
| Security questionnaires (CAIQ-Lite 4.0.3, VSA-CORE) | Trust Center → Resources |
| ISMS policies (information security, BCM, risk, incident, cryptography) | Trust Center → Resources |
| Live security controls status | Trust Center → Controls |
| Subprocessor list (with change notifications) | Trust Center → Subprocessors |
| Security update announcements (subscribable) | Trust Center → Updates |
The gated documents above — including the SOC 2 Type II + HIPAA report — are obtained by submitting the request form in the Usercentrics Trust
Center Resources section.
IP ranges
MCP Manager’s static IP addresses are published at app.mcpmanager.ai/enterprise/ip-ranges. Allowlist these at your firewall so a sensitive upstream accepts connections only from MCP Manager. A machine-readable version is available at app.mcpmanager.ai/enterprise/ip-ranges.json for automated firewall provisioning. See Architecture & Trust and Hosting & Data Residency for how egress IPs fit into the network-isolation model.Data Processing Agreement
A pre-signed DPA is available at app.mcpmanager.ai/enterprise/dpa. If you require one, download, countersign, and return it to your MCP Manager contact.Non-Disclosure Agreement
A pre-signed NDA is available at app.mcpmanager.ai/enterprise/nda for enterprise customers who require one before proceeding with evaluation or procurement.Business Associate Agreement (BAA)
As a HIPAA-compliant platform, MCP Manager signs Business Associate Agreements (BAAs) with covered entities and business associates. We can provide our own or countersign yours. BAAs are available on select enterprise plans; contact your MCP Manager representative to set it up.Company information
Legal entity names, DUNS numbers, and contact information are at app.mcpmanager.ai/enterprise/company.Further reading
Architecture & Trust
How the gateway path is encrypted, isolated, and hardened — including egress IPs.
Hosting & Data Residency
Where MCP Manager runs, what stays in your environment, and EU data residency.

