Built for security teams

Govern every AI agent through one gateway

Agents sign in through your identity provider and only reach the tools you allow. Each call is checked for prompt injection and destructive commands, and every one is logged and exported to your SIEM.

Trusted by

What the gateway enforces

Most security teams meet MCP after it has spread: servers on laptops, shared keys in config files, and no record of what an agent did. Putting the gateway in front gives you one place to set who can reach what, and one log of what they did.

SSO through Okta, Azure AD, or Google Workspace, with SCIM group sync, so agent access follows your directory groups.

The identity provider picker scrolling through the full list: Okta, Entra ID, Google, Auth0, JumpCloud, OneLogin, PingFederate and more

Each tool in a server is switched on or off separately, so a team can get read access to a system without the tools that write to it.

Mint Guard screens each call as it happens. Prompt injection and destructive commands are blocked before they execute and flagged in the log.

Each call is logged with the user, agent, server, and tool behind it, immutable, and exported to your SIEM or streamed via OTLP.

Security first

Your DLP stack keeps working

Advanced middleware lets you route tool calls through AWS Bedrock guardrails, Google Cloud Model Armor, or OpenAI moderation, in blocking or masking mode. The DLP you already run then covers agent traffic. For rules of your own, middleware hooks run your code on each call, versioned, pre or post, in enforce or dry-run mode.

Middleware template gallery with AWS Bedrock guardrails, Google Cloud Model Armor, OpenAI moderation, and allowlist templates

Sensitive data is redacted from responses

Built-in patterns match API keys, tokens, and credentials, and model-based detection catches PII and other sensitive data that no pattern describes. Both redact from the response before it reaches the model. Add your own patterns for internal formats.

Built-in secrets detection rules listing patterns for Airtable tokens, Anthropic API keys, Artifactory credentials, and AWS access keys

Enforced by your MDM

Push the gateway config to every laptop through your MDM. Claude, Cursor, and the other AI tools then connect through the gateway by default, and any MCP server installed outside it is visible in the log.

Private network tunnels

A reverse proxy inside your network holds one outbound connection to the gateway. Databases and internal APIs become reachable to agents with no inbound rules, and every call is screened and logged like everything else.

Enterprise ready

SOC 2 Type II audited

Audited annually by an independent third party and monitored continuously through Drata, with EU and US data residency options. DPA and sub-processor documentation on request.

Compliant with HIPAA standards

HIPAA attestation completed. We sign BAAs with customers handling protected health information.

Zero-trust by default

Every request is authenticated through your identity provider and authorized per tool at the gateway. No shared credentials, and no access granted by network location.

Immutable audit records

Every call is logged with the user behind it, retained for as long as you set, and exported to your SIEM. Records cannot be edited.

Full security documentation in our Trust Center
Tobias Boelter

“Visibility is the first step, but we need systems that provide visibility and mechanisms to act on what we learn. Security teams need to block risky behaviors that should never happen and defend against prompt injection at runtime.”

Tobias Boelter

Former Head of Security @ Harvey AI

Start in monitoring mode

See what your agents are doing today, then turn on enforcement when you are ready. Book a review with our security team.

Frequently asked questions

Every tool call as it happens, for prompt injection and operations that should not run. Dangerous commands are blocked and sensitive files stay out of reach. MintMCP maintains the detection policy, so you do not write the rules yourself. Start in monitoring mode to see what would have been blocked, then switch to enforcing.

Yes, without opening an inbound port. A reverse proxy inside your network holds one outbound TLS connection to the gateway, so there are no inbound rules, no VPN for each agent runtime, and nothing new listening on the perimeter. Those internal servers get the same screening and logging as everything else.

No. Advanced middleware lets you route tool calls through AWS Bedrock guardrails, Google Cloud Model Armor, or OpenAI moderation, in blocking or masking mode. For your own rules, middleware hooks run your code on each call, versioned, pre or post, in enforce or dry-run mode.

SSO connects to Okta, Azure AD, or Google Workspace, and SCIM group sync keeps access matched to your groups as people move. Policies cascade from the organization down, so a team can have a narrower tool set than the organization default.

Push the gateway config through your MDM, so the AI tools on every laptop connect through it by default. Any MCP server installed outside it is visible in the log.