borgelsmcp
Sign in

Security

Borgels MCP security

Borgels is a governed AI action layer. AI clients see only the business capabilities enabled for an organization; every action is checked against policy, needs approval where it matters, and is recorded in a redacted audit trail. Raw connector tools are internal and stay behind capability and connector boundaries.

Controls

AuthenticationBearer JWT validation against Supabase JWKS
AuthorizationOrganization membership, scopes, tool policy, package allow-list
Provider secretsService-role access only, separated from runtime config
AuditTool calls and denials with secret-field redaction

Report an issue

Send security reports to security@borgels.com with endpoint, reproduction steps, and expected impact. Do not include third-party credentials or production customer data in reports.