⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape · ⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape ·

Built for a new kind of production actor

SentnelOps is an AI agent runtime governance platform. It acts as an MCP firewall between AI agents (Claude Code, Cursor, custom agents) and the systems they access, giving every agent an identity, enforcing YAML policies on every tool call before it executes, and producing an audit-ready evidence trail. Deploys as a proxy in your own VPC.

Start free with Scout · Deploys in your VPC
Watch product overview

Our Mission

Our mission is runtime governance for AI agents. Every agent gets an identity, every tool call is a policy decision, and every decision goes on the record — enforced inline, before anything executes.

Agents act. SentnelOps governs.

Why SentnelOps Exists

  • AI agents are becoming production actors — writing code, opening pull requests, querying databases, touching cloud infrastructure.
  • The controls we have — IAM, service accounts, gateways — were built for humans and deterministic services, not agents.
  • When something goes wrong, nobody can answer the basic questions: which agent did what, was it allowed, and can you prove it?
  • MCP is the wedge: the standard path agents take into real systems, and the natural place to enforce.

The category is AI agent runtime governance. Autonomous, never ungoverned.

Our Approach

1

Intercept before execution

Every MCP tool call is evaluated against policy before the server ever sees it — permit, block, or pause for approval.

2

Zero trust by default

Every agent starts with no permissions. You grant exactly what each agent can call, on which server, under which conditions.

3

Human-in-the-loop where it matters

Any policy rule can require approval. The request arrives as a Slack DM with full context, and the agent resumes only after explicit sign-off.

4

Evidence, not just logs

Every call is recorded with agent identity, parameters, timestamp, and the policy rule matched — structured for SOC 2 Type II export.

Who's Building It

SentnelOps is built by Rupam Biswal, an engineering leader with 12+ years of experience who scaled AI platform teams from 1 to 20+ at Yellow.ai. The lesson that carried over: market trust in agents is the product — agents only get adopted where they can be governed and proven. Follow the work on GitHub and LinkedIn.

MCP firewallAgent identityRuntime policyAudit evidence

Who We Build For

Platform teams

Rolling out Claude Code, Cursor, and custom agents against GitHub, AWS, databases, and internal APIs — and need one place to control what those agents can touch.

Security teams

Need every agent to have an identity, explicit least-privilege grants, and inline enforcement on every tool call before it executes.

DevOps teams

Run agents against real systems and have to prove to auditors exactly which agent did what, and whether it was allowed.

Where We Are Today

SentnelOps ships today as a proxy you deploy in your own VPC — calls, logs, and data never leave your network. Start free on the Scout tier: one MCP server, 1,000 calls a day, and a full call log, from zero to your first intercepted call in under ten minutes.

Start free with Scout. Upgrade when you need policy enforcement and audit export.

Building the governance layer for AI agents

AI agents will run more of production every quarter. The teams that win will run them with identity, policy, and evidence — autonomous, never ungoverned.