Custom security policies
213 JSON-defined rules holding 1,100+ patterns across 15 policy packs and 8 compliance templates. Injection, path traversal, prompt injection, and jailbreaks are graded by severity, assigned per proxy, and evaluated in a deterministic priority order.
Regex engineRisk scoringReal-time block
Read the guide →
Data redaction & unmasking
Mask PII, secrets, and sensitive content before it reaches the provider, then restore the original values in the response. The end user never sees the difference; the provider never sees the data.
PIISecretsRound-trip
Read the guide →
MCP vulnerability scanner
Runtime security analysis of live MCP endpoints: tool-permission auditing, API-surface assessment, malicious-payload detection, and tool-schema safety analysis, all wired into the policy engine with a triage workflow.
Runtime scanAuto-blockTriage
Read the guide →
MCP conformance enforcement
Requests that declare the modern spec are held to it: batches, missing or mismatched protocol headers, and versions below your pinned floor are refused with spec-correct errors, and a server prompt phishing for credentials raises an alert. Enforce or observe, per proxy.
Batch rejectionVersion pinningEnforce / observe
Read the guide →
Canary token detection
A tripwire for data leakage. It detects when a canary from 1 user or session surfaces in another, using sliding-window extraction that defeats evasion, plus provider memorization and stale-canary signals.
Cross-userCross-sessionMemorization
Read the guide →
Rug-pull detection
Continuously watch MCP tools and A2A AgentCards for silent changes: URL redirects, dropped skills, and capability flips. Baselines are fail-closed and severity scales with how much actually changed.
Card diffTool baselinesFail-closed
Read the guide →
Traffic analysis
An always-on heuristic engine over every MCP and LLM proxy request, flagging automated scanning, attack sequences, and anomalous content patterns. Monitor-only by design, so it surfaces behaviour without blocking it.
Always onHeuristicMonitor-only
Read the guide →
Session quarantine
A surgical kill switch. Block 1 user, API key, or IP without stopping the proxy or disrupting anyone else. Quarantined sessions are rejected at the earliest point in the pipeline, before any content analysis or upstream call.
Kill switchPer-userPre-analysis
Read the guide →
Alerting & notifications
Send alerts where your team already watches: SIEM, SOAR, Slack, email over SMTP, and webhooks, each with its own severity threshold and delivery rules.
SIEM · SOARSlack · EmailWebhooks
Read the guide →