# Security at Connector Central

> Security review pack · Version 1.1 · Last reviewed: September 15, 2026

A practical summary for your practice owner, IT adviser, or compliance reviewer.
[Download review pack · PDF](https://connectorcentral.com/downloads/connectorcentral-security-review.pdf).
Free to download. No email required. The full accessible review is at [Security](https://connectorcentral.com/security).

## Data flow and processing locations

Connected systems ↔ Connector Central ↔ Your chosen AI.
Connector Central checks access, uses encrypted credentials on the server, calls the connected system, and returns the result to your AI assistant. The AI receives the data needed for the request, never the credentials. Raw tool inputs and results are processed transiently and are not stored; operational metadata and hashes are separate records.

The application and databases are hosted in the EU, at Hetzner in Nuremberg, Germany. This does not mean all processing stays in the EU. PostHog uses EU analytics hosting; browser analytics pass through Cloudflare. Hatchbox (deployment), Postmark (email), and Honeybadger (errors) are US-based. Cloudflare provides network security, proxying, and object storage, with global processing. Google Ads and Google Analytics process website/conversion events where configured.

Workspace information includes names, email addresses, memberships, settings, profile images and logos. PostHog is cookie-free but can associate signed-in activity with email and name. Review the [sub-processor list](https://connectorcentral.com/legal/sub-processors) and [Cookie Policy](https://connectorcentral.com/legal/cookies).

Your firm chooses its AI and connected software providers under separate agreements. Review their processing locations, retention and model-training settings. Connector Central cannot guarantee their handling of data after they receive it.

## Protection and access

Provider credentials are encrypted at rest and used server-side; saved secrets are not displayed again. HTTPS protects traffic to Connector Central. Workspace data is scoped in the application and protected by forced database row-level security on shared infrastructure.

Owners and Admins manage per-person connector access, read/write/destructive tiers, and connected provider-account reach. Those limits do not guarantee restrictions on individual clients, records or fields within an account. Owners retain owner-level access, with owner action caps available for tool tiers. There is no human approval step for each action.

Live provider verification checks credential usability; it is not continuous monitoring or a provider audit. Revocation, disconnection and applicable limit changes affect the next agent request, without undoing requests already sent or ending provider-side sessions.

Staff have Owner, Admin and User roles. TOTP two-factor authentication is optional for all users, including Admins. OAuth consent binds an MCP-compatible client to one workspace and the person's access. This verifies Connector Central membership, not membership of the firm's organization at the AI provider.

## Privacy, retention, and deletion

- Raw inputs/results are transient and not stored.
- Activity uses the workspace's configured period (30-day default), with daily cleanup.
- Audit and execution evidence has no automatic time cutoff and remains until workspace deletion. Audit history and recorded actor names survive member removal.
- Platform usage facts retain workspace ID, tool identifiers and timestamps permanently, including after deletion, without member names or raw inputs/results.
- Disconnecting a provider retains its encrypted connection record. Workspace deletion removes live records and the logo; provider-side revocation is separate.
- Personal account deletion also deletes owned workspaces and removes other memberships. Those other workspaces and their audit history remain.
- Analytics, error reports and support messages have separate retention rules. Contact support about access or erasure requests.
- Backups may retain copies after live deletion. Contact support about data-return and deletion requests.

Read the [Privacy Policy](https://connectorcentral.com/legal/privacy), [DPA](https://connectorcentral.com/legal/dpa), and [Terms](https://connectorcentral.com/legal/terms). DPA data-return/deletion obligations continue to apply. Using Connector Central does not by itself establish your firm's compliance or delete data at other providers.

## Independent assurance

**Status as of September 2026**

- **SOC 2 Type I:** Preparing. Audit firm selection underway; report planned for late 2026.
- **SOC 2 Type II:** To follow the Type I report.

Our security review pack describes the controls in scope for the audit.
No auditor is engaged and no SOC 2 report is available yet. This is the intended scope and a planned timetable, not an assurance that a report will be issued by that date.

## Review, access, and support

Email [support@connectorcentral.com](mailto:support@connectorcentral.com) for review questionnaires, access, data return, correction or erasure. We verify identity/authority and explain the available information and retention limits. There is no self-service workspace export; we cannot export raw payloads we do not store. Export client records from the connected software holding them.

Review your profile in account settings and workspace records in Activity. Owners delete workspaces in workspace settings. Arrange ownership transfer before personal account deletion if a workspace must remain.

For responsible disclosure, email support with subject "Security" and reproduction details, without accessing or changing others' data. We investigate, keep you informed, and ask for time to fix the issue before disclosure. For sub-processor notifications, use subject "Sub-processor updates".
