The problem
You run a 40-person accounting firm. Your team wants their AI assistant to read client files in QuickBooks and draft emails in Gmail. Your developer says that needs "MCP servers" and asks where you want them to run.
You do not know what to answer. You want to know who holds the passwords, who fixes it when it breaks, and what it costs.
Why this keeps happening
MCP is a common standard that lets AI tools connect to other software, such as your accounting or email system. Each connection has to run somewhere. Technical guides treat that as a server question. For you it is a business question.
There are three choices. As of September 2026, Obot's guide sums up the trade-offs like this:
| Where it runs | Good for | Trade-off |
|---|---|---|
| Hosted by a provider | Speed and very little upkeep | Your data passes through their systems, and you depend on their plans |
| Self-hosted in your own cloud | Full control and strict data rules | Someone on your side has to run and maintain it |
| Local, on one computer | One person trying things out | Does not work for a whole team, and every setup differs |
Getting it wrong costs in two directions. Self-host with nobody on call, and every outage stops your team. Pick a hosted service without checking where client data goes, and you may break a promise you made to your own clients.
How to fix it
Answer these questions in order. The first clear answer usually decides it.
- Must client data stay inside your own systems? If yes, self-host in your own cloud account.
- Is there someone who can fix it at 3am? If no, use a hosted service.
- Is this one person experimenting? Local is fine for now, but plan to move before the team relies on it.
- Where are the logins stored, and who can see them? Get the answer in writing.
- Can you switch off a connection yourself, right away?
- Can you see what each connection did, and when?
One rule applies whichever way you go: your passwords should never be pasted into the AI's instructions. Why AI tools should never pass your logins along explains the risk.
What BlueBear does to help
BlueBear runs ready connections for common business tools, such as Gmail, HubSpot, QuickBooks, Google Drive and Dropbox, on its own servers today. Each is set up per client, the logins are held by the platform rather than inside the AI's instructions, and every run leaves a record.
If your data must stay in your own cloud account, BlueBear can be deployed there instead. Managed hosting vs your own cloud compares the two.
Not available yet: hosting your own custom-built tool on BlueBear for other businesses to use.
What to do next
Go through the six questions with your developer this week. Write the answer down in one sentence: where it runs, who holds the logins, and who gets the call when it breaks.
Want your team's AI assistant connected to your business tools without running the servers yourself? Get in touch.
Questions people actually search for
- should i host my ai tool connections myself
Host them yourself if your data must stay in your own systems and you have someone to maintain them. Use a hosted service if nobody on your team can keep them running and your data rules allow it. Keep local setups for one person trying things out.
- what is the difference between hosted and self-hosted mcp
MCP is a common standard that lets AI tools connect to other software. A hosted connection runs on a provider's servers, who keeps it running. A self-hosted one runs on your own servers or cloud account, where you control it and maintain it.
- who holds the passwords when an ai tool is hosted
Usually the hosting provider stores the logins the connection needs. Ask exactly where they are kept, who can see them, and how you revoke access. A good setup never puts your passwords inside the AI's instructions.
- can a small business run mcp servers without a developer
Running them on your own servers takes technical upkeep, so most small businesses without a developer use a hosted service. Choose one that lets you see what each connection did and switch access off yourself.