Vault · Early access

One door to every MCP tool. Every call checked and recorded.

People plug MCP servers into Claude, ChatGPT, Cursor and their own agents, each with its own tokens and no oversight. Vault gives your company one governed MCP endpoint: admins connect servers once, people sign in with the company account, and every tool call is checked against the groups and rules you set.

  • 01
    MCP tokens live on every laptopEach person connects servers with their own keys, so access can't be reviewed or revoked in one place.
  • 02
    Anyone can call any toolThere is no way to say which team may use which server, let alone which individual tool or what it may be asked to do.
  • 03
    Shared secrets get pasted aroundAPI keys and passwords travel through chats and files, with no record of who can use them.

Example goal

Every MCP tool call governed

Primary metricTool calls with a grant and an audit record
100%

of calls through Vault, target 100%. Illustrative numbers.

How it works

Connect once. Govern every call.

  1. Connect servers once

    An admin connects an MCP server with OAuth or a custom setup and approves its tool definitions. Connecting a server gives nobody access.

  2. Grant by group

    Access is deny by default. Give a group individual tools or whole servers, and add rules on a tool's inputs, with exact values or patterns.

  3. Share secrets without showing them

    Let a group use a shared secret without anyone seeing its value.

  4. Everything is recorded

    Each call is checked again against the current groups and rules, and logged with the person and the AI client that made it.

What it includes

Built for your security review. From day one.

Vault is in early access. Book a call to see it and shape what comes next.

  • One MCP endpoint for Claude, ChatGPT, Cursor and AgentWorks agents
  • Sign-in with your company account, and each AI client's access can be revoked
  • Deny-by-default grants per group, server or single tool
  • Rules on tool inputs: exact values or full-string patterns
  • New or changed tool definitions are held for review
  • Shared secrets granted to groups without revealing their value
  • An audit log of every call, with the person and AI client
  • A chat assistant that sets up access and explains each change

Built for your security review

Runs in your cloud. Every action on the record.

  • Self-hosted

    Deployed in your cloud account or data center. Evidence stays in your environment.

  • Approvals

    Anything that changes production or reaches people waits for approval by default.

  • Audit trail

    Every run, tool call, decision and cost is recorded per workflow.

  • Your models

    Your enterprise Claude, ChatGPT or Gemini agreements, or private endpoints.

  • Scoped access

    Tools, folders and secrets are granted per workflow, and every command agents run is OS-sandboxed.

  • SSO and roles

    Sign-in through your identity provider, with roles and per-workflow access.

FAQ

Questions, answered.

Is Vault available?

It is in early access. Book a call and we will set it up with you.

Which MCP clients work with it?

Any client that can connect to a remote MCP server, such as Claude, ChatGPT, Cursor and AgentWorks agents. People sign in with the company account, and a client can be disconnected at any time.

Does connecting a server give people access?

No. Access is deny by default. A server's tools reach people only through the groups an admin grants them, and new or changed tool definitions wait for review.

Can a rule limit what a tool is asked to do?

Yes, for the values a tool exposes as inputs, using exact values or full-string patterns. For things like free-form queries or opaque IDs, also use a narrowly scoped credential upstream.

Where does it run?

On your AgentWorks server, in your own cloud or data center.

Govern MCP before it sprawls. Join the early access.

Tell us which MCP servers and AI clients your teams use, and we will set up Vault with you.