Security & privacy

Your Oracle rules, enforced by Oracle. Your data, not kept by us.

MyAi acts only as the signed-in person, only reads, keeps every organisation separate, and does not store your Fusion business data. This page says precisely what that means.

Per-user OAuth — no service account

Each person signs in on your organisation's own Oracle page, through a confidential application your administrator creates and controls in your identity domain. MyAi never sees a password, and there is no shared or privileged account anywhere.

Oracle applies the person's roles and data access to every call. Remove someone's access in your identity domain, or deactivate the application, and their MyAi access ends the next time their Oracle session needs refreshing.

Two identities, never mixed

Claude holds only MyAi's own access token: random, valid for one hour, and bound to MyAi. It never holds your Oracle token, a session id or your pod address. Your Oracle tokens stay inside MyAi and are verified against your identity domain's own keys.

MyAi's sign-in follows OAuth 2.1 with PKCE (S256), single-use codes, exact redirect matching and rotating refresh tokens; a replayed code or refresh token revokes the whole link.

Read-only by construction

MyAi sends only GET requests to Oracle's REST API. Reports run only from a registry that refuses any job whose name or package indicates it changes data. Every Oracle tool is marked read-only to Claude.

Running a report submits an Oracle scheduled report process as you — it appears in your Scheduled Processes like any report you run yourself — and changes no business data.

Tenant isolation

Your organisation is chosen once, at sign-in, by a verified e-mail domain or organisation code — never from a request field or anything Claude sends. Tokens are verified only against your identity domain's keys, requests go only to your pod, and each call checks that the session belongs to that person in that organisation.

E-mail domains are proved by an e-mail link or a DNS TXT record before they route anyone to your organisation.

Data

What is stored — and what is never stored

In Claude, MyAi is a pass-through: business data flows between your Claude session, MyAi and your pod, and is not kept. MyAi Web keeps each person’s own chats for them, as below.

Data MyAi stores, keeps briefly, and never stores
DataWhat happens to it
Organisation configurationStored: company name, verified e-mail domains, administrator e-mails, pod URL, identity-domain endpoints, the application's client ID, plan, seats, status and any custom-report list. The client secret is kept only in a secrets vault, never in the database, logs, pages or e-mail.
Oracle sign-in tokensStored encrypted for each linked person while their link is active (at most 30 days, rotated on use), bound to that link. MyAi's own tokens and codes are stored only as one-way hashes.
Usage countsStored per organisation per day: number of tool calls, tool names, success or error kind and timing. People are counted only by a keyed hash, never by name or id. Kept up to 400 days.
BillingYour subscription and customer ids with our payment processor. Card details are held only by the payment processor; MyAi never sees them.
Large query results and report filesHeld briefly and encrypted so Claude can page through a large result (up to 30 minutes) or download a report file (a link valid for 15 minutes that works only for the person who ran it). Then discarded.
MyAi Web chatsKept for the person who had them, for 30 days, encrypted: their questions, the answers, and the tables and report files those answers showed. Only that person can open them; deleting a chat deletes them all. Never used for anything else.
Fusion business dataNever stored beyond the handling above. Never logged.
Your questions and Claude's answers in ClaudeNever stored. The conversation happens in your Claude account; MyAi receives only the tool calls Claude makes, and does not log their arguments or results.
PasswordsNever seen. You sign in on Oracle's page, not ours.

Logs record, for each tool call, the organisation, a user identifier, the tool, the duration and the outcome — never argument values, results or tokens.

Encryption and infrastructure

  • In transit: HTTPS only, from Claude to MyAi and from MyAi to Oracle. Plain HTTP is only redirected.
  • At rest: databases, file storage and secrets are encrypted with a dedicated, automatically rotated key. Sessions and caches are encrypted again by MyAi before they are written.
  • Network: a web application firewall and rate limits in front; application servers in private subnets; outbound traffic only over HTTPS from static addresses.
  • Fair use limits: 60 actions per minute per person and 600 per minute per organisation.

Security review and disclosure

MyAi's connector, control plane and infrastructure have been through an adversarial internal security review (cross-tenant access, OAuth, identity, request forgery, secrets, injection, billing and denial-of-service), and every finding was fixed with a regression test. An external penetration test is planned before general availability.

Found a vulnerability? Please e-mail security@testingthetestingapp.online. Please give us a reasonable time to fix an issue before disclosing it publicly. We welcome good-faith research that avoids other customers' data and any disruption of the service.

Hosting

Regions & data residency

MyAi runs in one primary region — Frankfurt, EU (AWS eu-central-1) — and reaches Oracle Fusion pods in any Oracle region from there.

What stays in-region

Your organisation's configuration, encrypted session tokens and usage counts. Fusion business data is never stored anywhere; it is processed transiently to answer.

Additional regions

Further regions — for example the United States or the Gulf / Middle East — are added when a customer needs data residency there.

Independent deployments

Each region is a separate deployment with its own connector URL (for example mcp.<region>.testingthetestingapp.online) and its own static egress IPs, which you allowlist for that region.

Request a region

Improvement feedback is opt-in

When an answer comes from a Preview module, Claude asks you to confirm or correct it. Whether anything is shared with MyAi depends on two switches, both off by default:

  1. Your organisation's administrator allows improvement feedback.
  2. You tick the box when you link Oracle, or ask Claude to change your MyAi privacy setting at any time.

With either switch off, nothing is recorded.

Exactly what is shared when both are on

  • The module (for example “Purchasing”) and whether you confirmed or corrected the answer.
  • The names of the Oracle resources and fields the answer used (for example invoices, InvoiceAmount).
  • Your organisation and a keyed hash of your user id, so confirmations from different people and organisations can be counted.

Never values, filters, questions, notes, rows, names or amounts. Records are kept 120 days and are used only to decide when a Preview module is ready to become generally available.