# Reach MCP — security, data and risk

- **Session, not password.** The Chrome extension reads the LinkedIn session of the account owner's own browser. No LinkedIn password is typed into Reach. Removing the extension revokes that path; deleting the account in the app removes the stored session.
- **Storage.** Session cookies are stored encrypted (Fernet, key held in Google Secret Manager). Every LinkedIn request is logged per account (type, method, URL, status) for the owner's dashboard and audit. Webhook signing secrets are stored encrypted and shown to the owner on request.
- **Proxy.** Each account gets a residential proxy in a location chosen at connection time, with a session id rotated periodically. Proxy errors flip the account to `error` and emit a webhook event.
- **Limits.** Daily quotas per family are enforced by the server before each write (see [Quotas](/docs/quotas.md)); playbooks add a numbered preview and explicit confirmation before any write.
- **Authentication.** MCP clients use OAuth 2.1 with PKCE (dynamic client registration); REST and non-OAuth MCP clients use API keys, which can be restricted to specific accounts. Team members and clients connect their own sessions through invitation links.
- **Hosting and jurisdiction.** Backend on Google Cloud Run and Cloud SQL in `europe-west1` (Belgium); app and site on Cloudflare Pages. Operated by Kanbox (France). GDPR page: https://www.reachmcp.com/gdpr.
- **Risk, stated plainly.** Reach MCP is not an official LinkedIn API. LinkedIn automation carries real account risk; new or fake accounts are the most exposed. Proxy, enforced limits and pacing reduce it; nothing removes it, and Reach never claims zero risk.
- **Security contact.** https://app.reachmcp.com/.well-known/security.txt.
