Security gateway that wraps any MCP server with per-tool policies, approval gates, and optional Ed25519-signed decision receipts. Shadow mode logs every tool call without blocking; enforce mode applies block, rate-limit, and minimum-tier rules. Receipts are independently verifiable offline with no accounts needed.
Operates Rancher-managed Kubernetes through any MCP client with capability detection, generic resource access, and curated workflows, wrapped in an audit-logged, rate-limited, confirmation-guarded safety model.
Provides a secure MCP boundary for AI agents, intercepting and validating tool calls, redacting secrets, and requiring human approval for sensitive actions with a tamper-evident audit trail.
Wraps your existing MCP servers and checks each tool call against policy and live state before it runs.
Allow, block, or require a refresh, with a reason the agent can act on.
MCP proxy that journals mutating tool calls and enables undo via compensation. It adds checkpoint, list_changes, undo_to, and explain_blast_radius meta-tools while forwarding all original downstream tools unchanged.