A GroupDocs MCP server lets Claude Desktop, Claude Code, Cursor, GitHub Copilot and other MCP clients work with your documents locally: the client starts the server as a child process on your own machine, and files are read and written in folders you choose. The full architecture and security model is documented on each product’s on-premise page, for example Running GroupDocs MCP servers on-premise: architecture and security model. This post compares the three common ways to connect an AI agent to documents and explains what does and does not leave the machine.

Which architectures can connect an AI agent to documents?

There are three. They differ in the question a security reviewer asks first: where does the document go?

Cloud upload Hosted API Local MCP server
How it works The assistant or a plugin uploads the file to a vendor service Your code or agent calls a vendor REST API with the file The AI client starts a server process on your machine
Where the document goes A third-party cloud A third-party cloud or your own tenant Nowhere: read from and written to local folders
Network surface Outbound to the vendor Outbound to the vendor stdio only; none with a license file, usage reports only (no document content) with metered licensing
Inbound ports Not applicable Not applicable None
Air-gapped use Not possible Usually not; depends on the vendor’s deployment options Possible with a license file
Who runs it The vendor The vendor You, as part of the AI client

The third column is what the GroupDocs MCP servers implement. The rest of this post covers how it works and where its limits are.

What does the data flow of a local MCP server look like?

The AI client launches the server as a child process and talks to it over standard input and output using JSON-RPC. The server never listens on a network port, and with a license file it makes no outbound connections either.

+--------------+          +--------------------+         +------------------+
|  AI client   |  stdio   | MCP server process | reads / | local filesystem |
| (Claude,     | <------> | (GroupDocs engine) | <-----> | storage / output |
|  Cursor, ..) | JSON-RPC |   child process    |  writes |     folders      |
+--------------+          +--------------------+         +------------------+
       |
       | prompts and quoted fragments only
       v
+--------------------+
|   model provider   |  (cloud, or a local model inside your network)
+--------------------+

A security reviewer gets four checkable statements:

  • Transport: standard input and output to a child process. There is nothing to firewall and nothing to expose.
  • Inbound ports: none.
  • Telemetry: none. The document engine runs in-process.
  • Network use: at install time only, to pull the package from nuget.org or the image from ghcr.io. At runtime the server makes no outbound calls, with one licensing exception described below.

You can verify this instead of trusting it: run a task and watch for listening sockets and outbound connections.

What leaves the machine when an agent processes a document?

Documents do not leave the machine. Prompts and quoted fragments do.

The model behind your AI client sees the conversation. If the model is cloud-hosted, your instruction text reaches the model provider, and so does anything the agent quotes back to you. Two examples:

  • After a comparison, an agent reports that a payment term changed from 30 to 45 days. That sentence is part of the conversation and travels to the provider.
  • After an extraction, an agent reports an invoice total. The file did not move, but that value did.

A useful habit is to phrase prompts so the answer carries less content, for instance asking which files have a total above a threshold instead of asking for the totals. For sensitive corpora, pair the server with a locally hosted model. Then the whole loop (client, model, server, files) stays inside your network.

Does a local server need internet access?

Not for processing. It depends on the license mode:

  • License file: read from local disk by the local process. This works fully offline and is the right choice for air-gapped networks.
  • Metered (pay-per-use): the server reports usage to GroupDocs, so it needs outbound egress. The report contains no document content, but the connection itself must be allowed by your firewall.

If both metered keys and a license file are configured, the metered keys take precedence. Keep the keys in environment variables rather than in committed configuration. Each product’s licensing page describes the setup, and the get_license_status tool reports the active mode.

How do you run the server inside the perimeter with Docker?

The Docker image is often the easier option for a platform team: one image with the native dependencies, no SDK on the host, and a boundary limited to the folders you mount. Each product has its own image, named ghcr.io/groupdocs-<product>/<product>-net-mcp. The command below shows the shape for one product; replace the placeholders.

docker run --rm -i \
  -v /srv/documents:/data \
  -v /srv/licenses:/license:ro \
  -e GROUPDOCS_MCP_STORAGE_PATH=/data \
  -e GROUPDOCS_LICENSE_PATH=/license/GroupDocs.<Product>.lic \
  ghcr.io/groupdocs-<product>/<product>-net-mcp:<tag>
  • Pin the tag. The quick-start commands use :latest; for production, pin the tag to the version you tested so a rebuild cannot change behavior under a running workflow.
  • Mount deliberately. The container sees only the folders you give it, which is a tighter boundary than a process running as your user.
  • Mount the license read-only.
  • Air-gapped segments: pre-pull the image, or pre-cache the NuGet package, and pin the version.

Your AI client runs this docker run command as the server command in its MCP configuration, so the container is the child process in the diagram above. The docs describe the images as multi-arch (linux/amd64 and linux/arm64).

Is a local MCP server suitable for regulated industries?

It removes the largest question in a privacy review, which is transfer of documents to a third-party processor. Teams in legal, financial, healthcare and public-sector settings whose policy forbids uploading documents can use it as a building block for HIPAA or GDPR oriented workflows. This describes architectural suitability only. GroupDocs MCP servers are not certified for any regulation, and your obligations still depend on the model you pair them with, your license mode and your own controls.

What are the limits of this model?

  • One server serves one client process. A stdio server is started by one client on one machine. It is not a multi-user service. For a shared service, put your own service in front of the GroupDocs library instead of running many MCP servers.
  • Metered licensing needs egress. Usage reports go out, as described above. Choose a license file if the network must be closed.
  • Prompts still reach the model provider unless you use a locally hosted model.
  • Evaluation mode has limits. Without a license the servers run in evaluation mode with product-specific restrictions. For example, the Comparison server compares only the first 2 pages and watermarks the result. Call get_license_status first and read the licensing page of your product.
  • Parser ships as a Docker image only. GroupDocs.Parser.Mcp has no NuGet package, so the Docker route above is the only route for that product.
  • Platform exceptions. Two PDF-specific operations currently fail on Linux, including the Docker image, because the PDF engine’s image handling depends on System.Drawing.Common, which .NET supports only on Windows: GroupDocs.Annotation.Mcp generate_pages_preview on PDF files (Word documents render), and GroupDocs.Redaction.Mcp redact_image_area and erase_metadata on PDF files (redact_text on PDF, and all three on Word documents, work). Run those on Windows with dnx; see the product posts.

FAQ

Is MCP secure for sensitive documents? With a GroupDocs MCP server the documents are processed in-process on your machine over stdio, with no listening ports and no telemetry. What remains to assess is the model your AI client uses, because prompts and quoted fragments go there.

Can I run Claude tools without sending data to the cloud? Documents stay local either way. To keep prompts local as well, use a client that supports a locally hosted model, so no part of the conversation leaves your network.

What data does an MCP server send? At runtime a GroupDocs MCP server sends nothing over the network when a license file is used. With metered licensing it sends usage reports to GroupDocs, never document content.

Per product: on-premise pages in the documentation

Each page covers the same architecture with the commands for that product. These are the canonical references for a security review.

Per product: where to start on the blog

Each product has a series of four posts. The first one explains the pattern; the other three apply it.