Security

Built to keep your account safe

Straight answers about how ghlmcp.io handles your GoHighLevel connection, what stays private, and the controls you have at every step.

What we access

Only what's needed to run the connection between your AI assistant and your GoHighLevel account — and a pairing key that ties your connection to your ghlmcp.io account.

What we never touch

We never see or store your GoHighLevel login. We don't read anything outside GoHighLevel. Your credentials stay with you.

Where your data lives

Everything is transmitted over HTTPS to your own ghlmcp.io endpoint. Nothing is shared with third parties, and access refreshes quietly in the background so you don't have to think about it.

Encrypted at rest

All sensitive values are encrypted at rest with industry-standard AES-256. They're used only to fulfill the requests you or your connected AI initiate.

You're in control

Disconnect any time — from the Chrome extension or your ghlmcp.io dashboard. The moment you do, syncing stops and the connection is removed from our systems.

Never sold, never shared

Your data isn't a product. It's used purely to power the connection between your AI client and your GoHighLevel account.

Sub-account isolation

Each connection is locked to the exact GoHighLevel sub-account you pick. One connection can never reach another.