⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape · ⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape ·

[ AUDIT EVIDENCE ]

Prove what your agents did. Every call. Every decision.

SentnelOps intercepts every MCP tool call before the server sees it, so the audit trail is complete by construction — attributed to an agent identity, matched to a policy rule, and stored in your own database with zero data egress.

[ EVIDENCE CAPTURED PER CALL ]

agent_identityWhich agent made the call — the anchor for attribution
tool_nameThe exact MCP tool invoked on the target server
parametersThe full arguments the agent sent, as received
timestampWhen the call was intercepted by the proxy
decisionPermitted or blocked — the enforcement outcome
policy_ruleThe specific policy rule that matched the call

Logged for every call — permitted or blocked · written to your database, not ours

Complete by construction

The SentnelOps proxy sits between your AI agents — Claude Code, Cursor, custom — and your MCP servers: GitHub, AWS, Postgres, internal APIs. Every call passes through it before the server sees it, so nothing can happen off the record. An AI agent audit trail assembled from scattered application logs always has gaps; one produced at the enforcement point does not.

Decisions, not just events

Each record captures the enforcement outcome and the policy rule that produced it. You can show an auditor not only that a destructive call was blocked, but which version-controlled YAML rule blocked it — because policies are enforced at call time by the runtime policy engine, not reconstructed after the fact.

Your VPC, your database

The proxy is deployed in your VPC and logs go to your own database. Zero data egress: call parameters, responses, and evidence never transit SentnelOps servers. The evidence your auditors review is evidence you physically hold — see the MCP firewall architecture for how it sits in your network.

⟨ ATTRIBUTION VIA AGENT IDENTITY ⟩

"An agent did it" is not an answer an auditor accepts. Every call in the log carries an agent identity, so "who dropped that table?" resolves to a specific agent, its matched policy rule, and the exact parameters it sent. SentnelOps is zero trust by default — every agent starts with zero permissions, and each grant is explicit: per agent, per server, per condition. That means the audit trail doubles as a permission inventory: what an agent did, and what it was ever allowed to do, come from the same source. Read more on agent identity.

[ EXPORT & RETENTION ]

When your auditor asks for evidence, export the full call log as CSV — structured for SOC 2 Type II, so the fields map onto what an audit actually requests instead of a raw log dump you have to reshape. Retention scales with your plan, and because the data lives in your own database, you can always keep it longer on your own terms.

Scout
Free
7 days retention
Sentnel Starter
$299/mo
90 days retention
Command Team
$799/mo
1 year retention

First call logged in under 10 minutes.

Point your agents at the SentnelOps proxy and the audit trail starts building itself. Scout is free; paid plans start at $299/mo when you’re ready. Or see what your agents can actually do first — we run a 10-day governance assessment in your own VPC.