FAQ

Is Your CPA Data Safe with AI? How AIAffiliates Handles Security

June 4, 20265 min readAIAffiliates
Читати українською →

For CPA networks — especially those working in regulated verticals like iGaming and gambling — data security isn't optional. Before connecting any tool to your tracker, messengers, or databases, you need to know exactly where your data goes.

The short answer: your data never leaves your infrastructure. Here's how that works technically.

The MCP architecture

AIAffiliates is built on MCP (Model Context Protocol) — an open standard developed by Anthropic that defines how AI models communicate with external systems. Instead of copying your data into an AI system, MCP works the opposite way: the AI sends a request to your system, gets back only what's needed to answer the question, and that's it.

Think of it as the difference between giving someone a copy of your database vs. letting them ask your database questions. With MCP, your data never moves — only queries and responses do.

What this means practically

No data copying

Your conversion data, partner conversations, and rate registers stay in your systems. AIAffiliates queries them in real time — nothing is stored on our side.

Full encryption

All communication between the AI and your systems is encrypted at-rest and in-transit. Standard TLS for data in motion, AES-256 for data at rest.

Your infrastructure

With the Self-Hosted plan, the entire system runs on your servers. We deploy the code, you own the environment. Nothing touches our infrastructure.

Compliance-ready

The architecture is designed for regulated verticals. Audit logs, access controls, and data residency requirements are all supported.

What about Telegram data?

Messenger indexing is one of the more sensitive parts of the setup. Here's how it works: a dedicated support account is connected to the channels and chats you specify. Messages are indexed locally — on your infrastructure — and the AI queries that local index. Messages are never sent to any external server.

You control which channels are indexed, and you can revoke access at any time.

Self-Hosted vs Managed: the security tradeoff

We offer two deployment models:

For iGaming and regulated verticals, Self-Hosted is almost always the right choice. For networks without strict data residency requirements, Managed is simpler to get started with.

Want to understand what the onboarding process looks like? See how long implementation takes for each deployment model.

Have specific security requirements?

Book a free Automation Mapping session and we'll walk through exactly how the architecture fits your compliance needs.

Book for free →