Security
Enterprise AI needs enterprise-grade foundations.
How DataGardener MCP is secured: OAuth authorisation bound to the connection, per-customer entitlement to intelligence modules, read-only tools that reject writes, UK data storage, and ISO/IEC 27001 and Cyber Essentials certification.
Access controls
What is in place today.
Only controls confirmed from the live DataGardener MCP server or from public listings are described here. Anything not yet confirmed is listed separately rather than implied.
OAuth authorisation
Remote connections to DataGardener MCP are authorised with OAuth. Identity travels with the connection's bearer token, not with a shared key pasted into a prompt. A legacy login-link flow exists for older SSE connections.
Verified from the live server
Entitlement per connection
Each connection sees the intelligence modules its DataGardener agreement allows. Tool results outside the entitlement are not returned.
Verified from the live server
Read-only tools
Every tool reads. Aggregation pipelines that attempt to write ($out, $merge and similar) are rejected by the server. An agent cannot modify DataGardener data.
Verified from the live server
Usage reported with results
Record-returning tools report the usage consumed with each response, so administrators can see what an agent did.
Verified from the live server
Default filters
Dissolved and dormant companies are excluded by default so agents work on the live business population unless explicitly asked otherwise.
Verified from the live server
UK data storage
DataGardener's G-Cloud 14 listing states data storage in the United Kingdom on an AWS-based cloud service.
From the G-Cloud 14 listing
Not claimed on this site
The following are discussed under NDA during a security review rather than stated publicly: Audit log export format; SSO and identity-provider federation; Role-based access within a customer; Data retention periods; Encryption implementation details.
Security and quality
Independent certification of how DataGardener manages information security and quality.
- Verified 2026-10-03

ISO/IEC 27001
DataGardener operates an information security management system certified to ISO/IEC 27001:2022 by Perry Johnson Registrars, Inc. (PJR), certificate C2024-05296, valid 27 September 2024 to 26 September 2027, scope: provision of products and services in data processing and hosting.
- Certificate
- C2024-05296
- Standard
- ISO/IEC 27001:2022
- Issued
- 2024-09-27
- Expires
- 2027-09-26
Issued or operated by Perry Johnson Registrars, Inc. (PJR). View certificate (PDF).
- Verified 2026-10-03

ISO 9001
DataGardener's quality management system is certified to ISO 9001:2015 by Perry Johnson Registrars, Inc. (PJR), certificate C2024-05294, valid 27 September 2024 to 26 September 2027, scope: provision of products and services in data processing and hosting.
- Certificate
- C2024-05294
- Standard
- ISO 9001:2015
- Issued
- 2024-09-27
- Expires
- 2027-09-26
Issued or operated by Perry Johnson Registrars, Inc. (PJR). View certificate (PDF).
- Verified 2026-10-03

Cyber Essentials
Cyber Essentials is the UK government-backed scheme that certifies an organisation has the baseline technical controls in place to protect against common cyber attacks. DataGardener Solutions Limited holds a Cyber Essentials Certificate of Assurance, certificate d28e5613-1bc4-4b0f-ac3d-e7fd511f4de0, certified 4 December 2025 with recertification due 4 December 2026, scope: whole organisation.
- Certificate
- d28e5613-1bc4-4b0f-ac3d-e7fd511f4de0
- Standard
- Cyber Essentials (profile 3.2, Willow)
- Issued
- 2025-12-04
- Expires
- 2026-12-04
Issued or operated by IASME Consortium (certification body: Cyber Garrison). View certificate (PDF).
Client-side controls
MCP hosts such as Claude let administrators and users set per-tool permissions (always allow, ask, or block). Because DataGardener MCP tools are read-only, most organisations can allow search and describe tools and ask before larger record pulls.
Tested today with Claude (web, desktop and mobile, via Connectors). Any MCP client that supports remote servers with OAuth authorisation can connect. Clients beyond those listed are not yet tested by DataGardener.
Connection and authentication guideReady for your security questionnaire.
DataGardener is FSQS and JOSCAR registered and holds ISO/IEC 27001, ISO 9001 and Cyber Essentials. Ask for the evidence pack.