Mad Fish Elements
HomeTrust CenterSecurity & Compliance

Security & Compliance

How Mad Fish Elements keeps your business data governed, encrypted, and auditable as it flows between your systems and the LLMs your team uses.

Governed by default

Every connection you make runs through a single, policy-enforced gateway. Credentials for your source systems are stored encrypted and never exposed to the model, the LLM only ever sees a scoped MCP endpoint authenticated by your master key.

You decide which tools each connector exposes, which teammates can use them, and how long keys stay valid. Change any of it, and the policy takes effect on the next request.

Encrypted end to end

TLS 1.3 in transit and AES-256 at rest for every credential and payload.

Least-privilege access

Per-tool toggles and per-key source scoping keep exposure minimal.

Fully auditable

Immutable request logs with actor, source, and timestamp, exportable anytime.

Controls you can rely on

Mad Fish Elements is built for teams that answer to auditors. These controls are on by default and configurable per workspace.

Rotating master keys

Rotate or revoke your API key instantly; all connectors re-authenticate against the new key with zero downtime.

Role-based team access

Assign admin, editor, and read-only roles, and scope each member to only the sources they need.

Retention you control

Set log retention windows and stream events to your own SIEM via webhook or S3 export.

Instant offboarding

Remove a teammate and every key and session they held is revoked in the same action.