⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape · ⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape ·

[ SECURITY DOSSIER ]

Zero data egress. Your VPC. Your logs.

Built for CISO review before purchase. Everything your security team needs to know, without the discovery call.

[ HOW IT SITS IN YOUR NETWORK ]

AI Agent (Claude Code, Cursor, custom)
intercepted + logged
SentnelOps Proxy (in your VPC)
intercepted + logged
MCP Server (GitHub, AWS, Postgres, ...)

Proxy overhead: < 15ms p99 · No data leaves your VPC

Deploys in your VPC

SentnelOps runs inside your own infrastructure. The proxy lives in your network. MCP call parameters, tool responses, and logs never transit our servers.

Logs stored in your database

All call logs are written to your own database instance. We provide the schema and query tools. You own the data, full stop.

YAML policy enforcement

Policies are plain YAML files, version-controlled, GitOps-friendly, and testable in CI. Every tool call is evaluated against the policy before the MCP server sees it.

Zero trust by default

Every agent starts with no permissions. You explicitly grant what each agent can call, on which server, under which conditions. No implicit allowlisting.

SOC 2 audit export

The full call log — agent identity, tool name, parameters, timestamp, permit/block decision, policy matched — exports as CSV for your auditors. Structure built for SOC 2 Type II.

Human approval gates

Any policy rule can be set to require_approval instead of block. The call pauses, you get a Slack DM with full context, and the agent resumes only after your explicit approval.

⟨ RESPONSIBLE DISCLOSURE ⟩

Found a security issue? Email security@sentnelops.com with full details. We acknowledge within 24 hours and publish fixes within 30 days unless coordinated disclosure requires otherwise.