For CPA networks — especially those working in regulated verticals like iGaming and gambling — data security isn't optional. Before connecting any tool to your tracker, messengers, or databases, you need to know exactly where your data goes.
The short answer: your data never leaves your infrastructure. Here's how that works technically.
The MCP architecture
AIAffiliates is built on MCP (Model Context Protocol) — an open standard developed by Anthropic that defines how AI models communicate with external systems. Instead of copying your data into an AI system, MCP works the opposite way: the AI sends a request to your system, gets back only what's needed to answer the question, and that's it.
Think of it as the difference between giving someone a copy of your database vs. letting them ask your database questions. With MCP, your data never moves — only queries and responses do.
What this means practically
No data copying
Your conversion data, partner conversations, and rate registers stay in your systems. AIAffiliates queries them in real time — nothing is stored on our side.
Full encryption
All communication between the AI and your systems is encrypted at-rest and in-transit. Standard TLS for data in motion, AES-256 for data at rest.
Your infrastructure
With the Self-Hosted plan, the entire system runs on your servers. We deploy the code, you own the environment. Nothing touches our infrastructure.
Compliance-ready
The architecture is designed for regulated verticals. Audit logs, access controls, and data residency requirements are all supported.
What about Telegram data?
Messenger indexing is one of the more sensitive parts of the setup. Here's how it works: a dedicated support account is connected to the channels and chats you specify. Messages are indexed locally — on your infrastructure — and the AI queries that local index. Messages are never sent to any external server.
You control which channels are indexed, and you can revoke access at any time.
Self-Hosted vs Managed: the security tradeoff
We offer two deployment models:
- Self-Hosted — everything runs on your servers. Maximum control. You own the code and the environment. Recommended for networks with strict compliance requirements.
- Managed — we host the system on our infrastructure. Faster to set up, easier to maintain. Data still doesn't leave the secure environment, but it lives on our servers rather than yours.
For iGaming and regulated verticals, Self-Hosted is almost always the right choice. For networks without strict data residency requirements, Managed is simpler to get started with.
Want to understand what the onboarding process looks like? See how long implementation takes for each deployment model.
Have specific security requirements?
Book a free Automation Mapping session and we'll walk through exactly how the architecture fits your compliance needs.
Book for free →