This article explains how Perk MCP, the connection between your AI assistant and your Perk data, protects and handles your information. Use it to review Perk MCP with your security and IT teams. In short: Perk MCP acts within your existing Perk permissions, doesn't store the data it returns to your assistant, and isn't used to train AI models.
What Perk MCP can access
Perk MCP gives your AI assistant access only to data that the signed-in person can already see in Perk. You sign in with your Perk credentials and approve access on a Perk consent screen. The assistant gets only the permissions that match your existing Perk role, with the same company-level data separation as the Perk web app.
A traveler sees only their own data, and admin, reporting, and approval functions need the matching Perk role. Each person sees only the tools their role allows.
Perk MCP can return the following data, limited to what the signed-in person can already see:
| Data | What it includes |
|---|---|
| User profile | Name, email, and role. Admins can also see other users in their account. |
| Trips | Travelers, dates, itineraries, costs, and booking status. |
| Travel search and policy | Availability, pricing, and policy rules. |
| Expenses | Amounts, merchants, categories, statuses, and receipts. |
| Cards and invoices | Company cards, pending card transactions, invoices, and invoice line items. |
| Reports | Aggregated spend, travel, and team reports, for people with reporting access. |
| Perk Events | Event details and attendee lists. |
| Trip approvals | Approval links. |
What your assistant can and can't do
Perk MCP lets your AI assistant take some actions in Perk, but the assistant can't complete, pay for, change, or cancel a travel booking. Specifically:
- For flights, trains, and cars, the assistant builds a checkout link, and you open it in Perk to complete the booking.
- For hotels, the assistant can add a selected rate to a trip that isn't booked yet, and you complete checkout in Perk.
- For trip approvals, the assistant gets the approval link, and you act on it in Perk.
- For expenses, the assistant can create, update, submit, approve, or send back expenses and upload receipts. To approve, you need to be an approver in Perk.
- For events and reports, the assistant can create Perk Events and generate reports.
Starting a travel search can create a draft trip. Tools that make changes tell the assistant to confirm with you first.
How your data is handled
Perk MCP doesn't store or cache the data it returns to your AI assistant. The service keeps only the following:
- Encrypted sign-in tokens
- Short-lived operational information, such as rate-limiting counters and session information
- Operational logs and traces, which Perk uses for security monitoring and troubleshooting and which may include request details
All of this falls under Perk's existing data processing arrangements and Data Retention Policy, available on the Perk Trust Center.
Perk doesn't use data exchanged through Perk MCP to train AI models. Perk MCP doesn't call any AI model itself. It only returns data to the AI assistant that your company chooses and contracts.
How Perk protects against misuse
Perk MCP limits what an AI assistant can do, even if someone hides instructions in the data it reads (known as prompt injection). Perk MCP uses these protections:
- Every action stays within your own Perk permissions and the access you approved, so a hidden instruction can't make the assistant do anything you couldn't already do in Perk.
- Every result is marked as untrusted data. Before results reach the assistant, Perk removes hidden characters, special formatting that a model could mistake for instructions, and attempts to fake the untrusted-data markers.
- Perk MCP tells the assistant never to follow instructions found in results and never to call tools because of them.
- Each tool is marked as read-only or not, and destructive or not, so AI assistants can decide which tools need your approval. Some AI assistants such as Claude and ChatGPT let you require approval for individual tools in the connector settings.
Perk records each tool call, including the user and account, the tool, the AI assistant, the session, the outcome (success or error), and the response time. Perk also marks Perk MCP requests separately from web app activity and records each consent grant. Alerts cover errors, unusual traffic, and sign-in failures. You can access selected logs in the Perk app. Account admins can request access to further logs through their account manager when incidents occur, according to their contract.
Where Perk MCP runs and who processes data
Perk MCP runs on Amazon Web Services in the EU (Ireland). Perk holds operational logs in its EU monitoring environment. Perk hosts client data related to the Spend and Pay services on Google Cloud Platform (GCP), in regions in Switzerland, Belgium, Germany, and Ireland.
Perk MCP uses Perk's existing sub-processors, which you can see on the Perk Trust Center. Two tools rely on existing providers:
- The visa requirements tool sends trip route and nationality details to Perk's visa information provider.
- Receipt uploads use Perk's existing secure file storage.
Security testing
An independent third party has run a penetration test of Perk MCP. For more information about Perk's security practices, see the Perk Trust Center.
Where to go next
- For technical detail, see Perk MCP security and data handling on Perk Developers.
- To review Perk's sub-processors, see Perk Trust Center sub-processors.
- To learn about Perk MCP, see About the Perk MCP.
- To connect an assistant, see Connect your AI assistant to Perk.
- For examples of what Perk MCP can do, see What you can do with Perk MCP.