> ## Documentation Index
> Fetch the complete documentation index at: https://terrascout.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and privacy

> How Ploti MCP authenticates users, scopes access, handles data, and supports revocation

# Security and privacy

Ploti MCP uses the same workspace authorization and data-access rules as the Ploti application. There is no separate trusted path for external assistants.

## Authentication

Remote assistants connect through OAuth 2.1 over HTTPS. Ploti supports dynamic client registration, authorization-code exchange with PKCE (`S256`), short-lived access tokens, and rotating refresh tokens.

* Redirect URLs must match the registered value exactly.
* Authorization codes are single-use.
* A refresh token is replaced every time it is used.
* The consent screen names the requesting client and workspace before access is granted.
* Ploti passwords and OAuth tokens are never returned through MCP tools.

## Access boundaries

Every connection resolves to a Ploti user and workspace. Server-side checks apply that identity to every session and tool call.

* A connection can access only the workspace approved during consent.
* Sessions are isolated by connection identity, not merely by workspace.
* Data queries are constrained to the session's current map viewport.
* Plan entitlements and dataset permissions are enforced by the data service, not trusted to the assistant.
* Saved outputs use the same workspace authorization as other Ploti content.

## What data passes through MCP

When you ask an assistant to use Ploti, the assistant provider sends the tool name and inputs needed for that request to Ploti. Ploti returns the requested result, such as a concise data preview, source reference, map metadata, or artifact link.

Ploti does not request unrelated conversation history. The assistant provider controls what conversation context it sends with a tool call; review that provider's privacy and data-use terms separately.

Do not include passwords, complete payment-card data, protected health information, government identifiers, or other unnecessary sensitive data in prompts or files.

## Storage and retention

| Data                                                                 | Retention behavior                                                                        |
| -------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| Session state                                                        | Expires after one hour without MCP activity                                               |
| Sandbox compute                                                      | Stops automatically when idle; unsaved sandbox-only files are not durable                 |
| Background job result                                                | Available for one hour after completion                                                   |
| Artifact view grant                                                  | Read-only, scoped to one artifact, and expires after seven days                           |
| Saved checkpoints, tables, queries, filters, files, and chat records | Stored as workspace content until deleted under the workspace's normal retention controls |
| OAuth grant                                                          | Remains until revoked or otherwise invalidated                                            |

For complete handling and deletion terms, read the [Ploti Privacy Policy](https://ploti.ai/privacy), [Terms of Service](https://ploti.ai/terms), [Acceptable Use Policy](https://ploti.ai/aup), and [Subprocessor List](https://ploti.ai/subprocessors).

## Revoke access

You can disconnect Ploti from the assistant's app or connector settings at any time. Workspace administrators can also remove access according to the controls available in Ploti and the connected host. After revocation, the client cannot start new sessions or read existing sessions with the revoked grant.

If you suspect unauthorized access, disconnect the integration and contact [support@ploti.ai](mailto:support@ploti.ai).

## Safe and intended use

Ploti is intended for lawful property, land-use, ordinance, site-selection, and geospatial research. It must not be used for unlawful surveillance, harassment, discrimination, access-control bypass, or regulated eligibility decisions about people in housing, lending, insurance, employment, or similar contexts.

Property and ordinance data can be incomplete, delayed, or inconsistent across sources. MCP results are research aids, not legal, surveying, title, environmental, engineering, or investment advice. Verify material findings with the cited source and appropriate professionals.

## MCP compatibility

The server uses Streamable HTTP and returns standard MCP text results even when a host does not support interactive UI. Tools include titles and read/write/destructive annotations so compatible hosts can present appropriate confirmations.

For the standards Ploti follows, see the [Model Context Protocol specification](https://modelcontextprotocol.io/specification/), [Anthropic Software Directory Policy](https://support.claude.com/en/articles/13145358-anthropic-software-directory-policy), and [OpenAI plugin guidelines](https://developers.openai.com/plugins/app-guidelines).
