> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mcpmanager.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Compliance

> MCP Manager's public enterprise resource center — security certifications, compliance documents, IP ranges, DPA, NDA, and BAA. Everything your legal, security, and procurement teams need, without going through a sales process.

Everything your legal, security, and procurement teams need is at
[app.mcpmanager.ai/enterprise](https://app.mcpmanager.ai/enterprise) — no sales process required.

MCP Manager is built by **Usercentrics**, the compliance and consent infrastructure company behind
billions of data interactions every month. Over 100,000 B2B customers worldwide trust Usercentrics
with their most sensitive data obligations. The company crossed \$120M ARR in October 2025 and is
profitable — purpose-built for the long term and not dependent on the next funding round. That
institutional foundation is what backs MCP Manager's security program.

## Security documentation

The [security index](https://app.mcpmanager.ai/enterprise/security) is the access point for
MCP Manager's compliance reports, live controls status, and related resources:

| Document or resource                                                    | Section                      |
| ----------------------------------------------------------------------- | ---------------------------- |
| SOC 2 Type 2 + HIPAA report (2025)                                      | Trust Center → Resources     |
| ISO 27001:2022 & ISO 27701:2019 certificates                            | Trust Center → Resources     |
| TISAX Level 3 assessment result                                         | Trust Center → Resources     |
| Penetration test report                                                 | Trust Center → Resources     |
| Security questionnaires (CAIQ-Lite 4.0.3, VSA-CORE)                     | Trust Center → Resources     |
| ISMS policies (information security, BCM, risk, incident, cryptography) | Trust Center → Resources     |
| Live security controls status                                           | Trust Center → Controls      |
| Subprocessor list (with change notifications)                           | Trust Center → Subprocessors |
| Security update announcements (subscribable)                            | Trust Center → Updates       |

<Note>
  The gated documents above — including the SOC 2 Type II + HIPAA report — are obtained by submitting the request form in the [Usercentrics Trust
  Center](https://trust.usercentrics.com/) **Resources** section.
</Note>

## IP ranges

MCP Manager's static IP addresses are published at
[app.mcpmanager.ai/enterprise/ip-ranges](https://app.mcpmanager.ai/enterprise/ip-ranges).
Allowlist these at your firewall so a sensitive upstream accepts connections only from MCP Manager.

A machine-readable version is available at
[app.mcpmanager.ai/enterprise/ip-ranges.json](https://app.mcpmanager.ai/enterprise/ip-ranges.json)
for automated firewall provisioning.

See [Architecture & Trust](/mcp-gateway-concepts/architecture-and-trust) and
[Hosting & Data Residency](/deployment/hosting-and-data-residency) for how egress IPs fit into
the network-isolation model.

## Data Processing Agreement

A pre-signed DPA is available at
[app.mcpmanager.ai/enterprise/dpa](https://app.mcpmanager.ai/enterprise/dpa). If you require one, download,
countersign, and return it to your MCP Manager contact.

## Non-Disclosure Agreement

A pre-signed NDA is available at
[app.mcpmanager.ai/enterprise/nda](https://app.mcpmanager.ai/enterprise/nda) for enterprise
customers who require one before proceeding with evaluation or procurement.

## Business Associate Agreement (BAA)

As a HIPAA-compliant platform, MCP Manager signs Business Associate Agreements (BAAs) with covered entities and business associates. We can provide our own or countersign yours. BAAs are available on select enterprise plans; contact your MCP Manager representative to set it up.

## Company information

Legal entity names, DUNS numbers, and contact information are at
[app.mcpmanager.ai/enterprise/company](https://app.mcpmanager.ai/enterprise/company).

## Further reading

<CardGroup cols={2}>
  <Card title="Architecture & Trust" icon="building-shield" href="/mcp-gateway-concepts/architecture-and-trust">
    How the gateway path is encrypted, isolated, and hardened — including egress IPs.
  </Card>

  <Card title="Hosting & Data Residency" icon="cloud" href="/deployment/hosting-and-data-residency">
    Where MCP Manager runs, what stays in your environment, and EU data residency.
  </Card>
</CardGroup>
