Security
For personal MCP reconciliation, the honest answer starts with what ClariLayer does not do: we do not hold your warehouse or CRM credentials, run SQL on our servers, or call HubSpot. Your agent uses its own source access and sends one supported evidence envelope; ClariLayer reconciles that against the context you saved.
ClariLayer is a trust product that sits next to your warehouse or CRM workflow, so the first question prospects ask is fair: what actually touches my data, and where does it go? This page answers that plainly. We would rather state a posture you can verify than a slogan you have to take on faith.
For the personal MCP path, your client is the only connector to the live source. ClariLayer does not sit in the warehouse or HubSpot connection. What reaches ClariLayer is a supported evidence envelope assembled by your client: warehouse actual_sample or row-free HubSpot crm_evidence. We reconcile that against one compatible saved definition at a time. The separate, gated Governed Context Edge can use team connectors only when a team explicitly configures them, under that surface’s own controls.
The personal MCP reconcile data flow
Source-access boundary — credentials stay with your agent
Your agent + source connection
A local MCP client using a context key, or claude.ai using OAuth, holds the source connection and assembles evidence.
Warehouse or HubSpot
Your source, your credentials. On this personal path, only the client connects; ClariLayer does not.
Crosses to ClariLayer — assembled and sent by your agent
ClariLayer reconciles
Compares one compatible saved definition against the supplied evidence and records a caveat on drift. On this path, no source credentials, SQL execution, or HubSpot calls reach ClariLayer.
Warehouse · actual_sample
Columns plus an optional row count and optional preview rows. Preview rows are allowed and can contain real warehouse values, so the agent controls whether to include them.
HubSpot · crm_evidence · GA
Bounded property metadata and aggregate value distributions only. CRM rows are recursively forbidden.
ClariLayer lives at the last step only. For warehouse evidence, we do not claim raw data never leaves: optional preview rows can carry real values. CRM has a stricter contract and forbids rows. What we can state plainly across both personal evidence paths is the boundary: ClariLayer receives no source credentials, executes no SQL, and makes no HubSpot calls. The gated Governed Context Edge team-connector surface is separate and uses controls agreed with the team that explicitly configures it.
Step by step
Each explicit personal reconcile follows the same ownership boundary. Your client does the source work; ClariLayer sees only the supported evidence it sends and compares one compatible saved definition.
In the personal path, local agents connect over MCP with a context key and claude.ai connects as an OAuth custom Connector. The client keeps and uses its own authorized warehouse or HubSpot connection; ClariLayer never receives those source credentials.
For personal warehouse work, your agent runs SQL with its own access. For HubSpot, it reads property metadata and aggregate distributions through its own provider connection. ClariLayer executes no SQL and makes no HubSpot API or MCP call on this path.
On the personal path, a warehouse definition uses actual_sample: columns, an optional row count, and any optional preview rows the agent chooses to include. A HubSpot CRM definition uses bounded crm_evidence: declared property metadata and aggregate value distributions, with CRM rows recursively forbidden.
Each explicit personal reconcile compares one compatible saved definition with the supplied evidence. A mismatch records a caveat; otherwise the entry stays asserted. HubSpot reconcile is generally available.
What we promise — and what we won’t pretend
The same honesty that runs through the product runs through our security posture: we state exactly what is true, and we refuse the comforting overstatement. A claim you cannot verify is just asserted text — and asserted text is the trust problem ClariLayer exists to fix.
For personal MCP reconciliation, ClariLayer stores no database passwords, connection strings, warehouse tokens, HubSpot credentials, or CRM refresh tokens. Your client remains the connector to the live source. Separately, teams can explicitly configure gated Governed Context Edge connectors under that surface's own controls.
In personal MCP reconciliation, we do not execute your queries or call HubSpot. ClariLayer's job begins after your client supplies a supported evidence envelope: structuring the comparison and recording the result against saved context.
Warehouse actual_sample may include preview rows, and those rows can carry real values. HubSpot crm_evidence is different: it accepts property metadata and aggregate distributions only, and recursively rejects CRM rows at any nesting depth.
The context you save — definitions, schema notes, reusable SQL, caveats — is stored against your account and isolated by row-level security. Single-player by default: it is yours until you deliberately bring it into a shared team layer.
Stated plainly, not over-claimed
ClariLayer’s whole reason to exist is that an asserted claim and a checked one are not the same thing — and we hold our own posture to the same standard. The architecture above is how the personal MCP reconciliation path is built today: your client connects to the warehouse or HubSpot, ClariLayer does not. The separate gated team-connector surface uses its own controls. Check the personal path yourself against the docs, the quickstart, and the MCP connection — a claim you can check beats a badge.
Connect ClariLayer for personal MCP reconciliation. Your client keeps its own warehouse or HubSpot access; on this path ClariLayer never asks for source credentials, runs SQL, or calls HubSpot. It reconciles the supported evidence your client sends against the context you save.
Connect your AIWe use privacy-friendly analytics
With your consent we use PostHog and Vercel Analytics to understand how ClariLayer is used so we can improve it. We never sell your data. Errors are always monitored (without analytics) so we can keep the app reliable. You can change your mind anytime.