This article applies to client-side IT administrators and technical sponsors responsible for enabling PI's MCP connector during the current Pre Beta phase.
Please quote and/or share this resource with security, IT, and procurement reviewers for the Predictive Index MCP connector.
How the security model for PI's MCP works
Read-only by design. The connector cannot send, email, invite, save, or modify anything in PI. Nothing the AI host does through the connector can change your PI data.
Identity mapping. The connector maps the signed-in user to their PI profile using their verified PI sign-in token. Identity is never taken from text typed into the AI host, so a user cannot be impersonated by prompt input.
Data scoping. Obi returns only data the signed-in user is already permitted to see in PI.
Security runs server-side. Every request runs through PI’s security pipeline — prompt-injection and jailbreak protection — on PI’s servers, regardless of the AI host. The host is explicitly not relied on as a security boundary.
IP protection. PI’s behavioral-science corpus is never sent to the AI host. The host receives only Obi’s finished answer, which carries employees’ personal data and is governed by your agreement with that host.
Telemetry. PI collects usage telemetry to identify Obi usage originating specifically from the MCP connector.
Data handling. The integration adheres to PI’s standard security protocols for the PI platform.
Network and firewall settings
The following must be reachable by the AI host and by the user’s browser during sign-in:
Endpoint | What it is for |
The connector endpoint | |
PI single sign-on | |
PI platform APIs Obi calls | |
PI web app, used during login and consent | |
Your AI host’s own domain (e.g. https://claude.ai) | Host traffic |
A few important notes:
No custom ports are required beyond standard HTTPS (443). Additional endpoints may be specified before full launch.
Some hosts — Claude.ai among them — call remote connectors server-side, so connector traffic may not appear in your device or network logs even when everything is working correctly. Egress rules do not gate this traffic. Your enforceable controls are host-side governance and PI provisioning.
Logging and auditing
PI records connector usage for auditing: authentication (connect and disconnect) events, and request metadata — timestamp, user, channel (MCP), and request type. Usage is attributable to the MCP connector surface, so it can be reported separately from PI’s web, Teams, and Slack surfaces. No chat content is persisted beyond Obi’s operational needs. Audit logs are available on request.
You can see | You cannot see |
That a user connected or disconnected | What the user asked |
That a request was made — when, by which user, on the MCP channel | What the host said back |
MCP usage reported separately from Obi’s other surfaces |
|
Host-side logging of connector calls varies by host and is generally thin; check your host’s own audit documentation for what it records.
Incident response and data-subject requests
No single party holds the whole record. PI can attest which user made which request and when. The prompt text and the host’s answer are the host’s records — where a host does not retain them, an end-to-end reconstruction is not possible.
Connector use is not anonymous. Employee notice, and any works-council consultation, remain your responsibility.
Removal and offboarding
Control | Effect |
A user disconnects the connector in host settings | Ends that user’s link in that host |
An admin removes the connector org-wide | Removes availability in that host |
Deactivate the user in PI, or remove their Obi access | Cuts off access regardless of host configuration — the definitive control |
Offboarding actions available to you:
Confirm removal of connector access in both the AI host and PI.
Retain data in accordance with PI retention guidelines, or request a purge at the completion of the Pre Beta phase.
Further security and privacy documentation
Additional support
For additional resources or specific technical requests, contact Stefano Hernandez ([email protected]).
