MCP connector security: what the server sees and what it doesn't
Before a lawyer connects an external source to their AI, they want to know exactly what they're exposing, and to whom. This guide explains, without embellishment, how the Europaius connector handles login, what data reaches us, how long access remains valid, and how to revoke it.
Europaius Cyprus: Corpus Contents
The examples in this guide are based on Czech law. The same tools also work with the Europaius Cyprus corpus:
The connector uses OAuth 2.1 with PKCE protection and dynamic client registration. In practice: your AI (Claude, ChatGPT, Copilot) registers itself with us as a client, redirects you to the Europaius login page, you enter your email and type in a one-time code. The AI never sees your code or password; it only receives an access token bound to itself and your account.
An alternative to the code is an API key from the pricing page, suitable for automations and agents. The key can be revoked at any time and a new one issued.
What reaches us and what doesn't
Sent to us: the text of the search query composed by the AI (for example, "termination of residential lease non-payment"), the tool name, parameters (country, number of results), and the document identifier when retrieving full text.
Not sent to us: your conversations, uploaded documents, client names, or anything the AI does not insert into the query. The connector has no access to chat history.
We store: a record of the query with timestamp, account email, and the name of the AI client. This is used for limits, your own records, and anonymous statistics on what people are asking about.
We do not store: the results returned to the AI or its responses.
Tokens and their lifetime
The access token is valid for seven days, the refresh token for ninety days. Both are replaced at every refresh, and the old ones become invalid. Access can be revoked in your AI's settings (by removing the connector) or on our side; either action invalidates the entire token pair. Authorisation codes and email codes are valid for ten minutes and can be used only once.
Where it runs
The server runs on our own infrastructure in the EU, and communication is encrypted via TLS. The corpus consists of public legislation and case law, so the content itself is not confidential; only your query is confidential, and it is bound to your account and not visible to anyone else. The operator does not pass queries on to third parties, except for anonymous aggregate statistics.
Recommendations for law firms
Phrase queries without identifying clients; describe the facts in general terms.
Use business-tier AI plans with training on your data switched off.
When an employee leaves, remove the connector from their AI and ask us to invalidate the tokens linked to their email.
For shared agents, use a separate account with an API key rather than a personal email address.
Connect Europaius to Your AI The connector address is the same for all tools. Sign in with your email, done in under two minutes. https://mcp.europaius.com/mcp Connection Guide → · Pricing
Frequently Asked Questions
Can someone who knows my email address log into my account?
Not without access to your inbox. The code is sent by email, allows five attempts, and is valid for ten minutes.
Does Europaius see what the AI replied to me?
No. The server returns the search results, and its role ends there. The response itself is generated by the AI provider.
How do I download a log of my queries?
Write to us from your login email address and we will send you the log. A self-service export feature is in preparation.
General information only; does not replace legal advice. Connecting the connector requires a Europaius account (free of charge). More About Europaius · Europaius CY