MCP Security Gateway

Deny-by-default governance for every tool your agents can call.

SOCFortress MCP Gateway sits between your MCP clients and servers, enforcing exact per-client grants, human approval for risky calls, and a tamper-evident audit trail for every invocation.

Platform features

Nothing is implicitly trusted, on either side of the connection

Deny-by-Default Trust Chain
Every server, tool, client, and grant starts distrusted. Registering a server doesn't approve it, approving a server doesn't discover its tools, and approving a tool doesn't grant any client access to call it.
Two Independent Trust Dimensions
Tool risk (low, medium, high, critical) and server trust (untrusted to verified) are tracked separately, so policies like 'only verified servers may host critical-risk tools' can be written once, tenant-wide.
Immutable, Hashed Tool Catalogue
Every tool definition is SHA-256 hashed and versioned. If a server later changes what an approved tool does, the new version loses its approval automatically — a direct defense against 'rug pull' attacks.
Exact, Per-Client Grants
A tool being approved tenant-wide doesn't mean any client can call it. Grants are exact and per-client, and tool listings are filtered so a client can't discover a tool it isn't authorized for.
Exact-Request-Bound Human Approval
Approving a call binds to its exact arguments — a different argument set requires a new approval. Approvals are single-use, expire, and require separation of duties between requester and approver.
SSRF-Safe Server Registry
Every server registration and connection is checked against a port allowlist and private-network policy, with bounded, re-validated redirects — there's no path to make the gateway reach an arbitrary URL.
Credential Injection, Never Exposed
Upstream MCP server credentials are resolved and injected server-side during invocation. Clients never receive them and can't override the injected header.
Posture, Security Events & SIEM Export
Deterministic posture checks, actionable security event detection, and an append-only audit trail — exportable to your SIEM via HTTPS webhook or syslog-over-TCP.
Ready to put a governance layer in front of every MCP tool call?
Request access Request access
Frequently asked questions
Search keywords..
What exactly does the gateway sit in front of?
Can a client discover tools it isn't authorized to call?
What happens if an MCP server changes a tool's definition after it's approved?
Does the gateway protect against prompt injection or a tool being misused?
Didn’t find the answer you were looking for?
Contact us, we’re here to help