Security
Borgels MCP security
Borgels is a governed AI action layer. AI clients see only the business capabilities enabled for an organization; every action is checked against policy, needs approval where it matters, and is recorded in a redacted audit trail. Raw connector tools are internal and stay behind capability and connector boundaries.
Controls
Authentication
Bearer JWT validation against Supabase JWKSAuthorization
Organization membership, scopes, tool policy, package allow-listProvider secrets
Service-role access only, separated from runtime configAudit
Tool calls and denials with secret-field redactionReport an issue
Send security reports to security@borgels.com with endpoint, reproduction steps, and expected impact. Do not include third-party credentials or production customer data in reports.