Skip to main content

The MCP firewall for AI agents

Deploy AI agents
without opening
the doors.

Inline security and automatic EU AI Act evidence for regulated teams — one proxy between your agents and every tool and API.

Business trial · 14 days · no credit card · full compliance engine from day one

MCP — Model Context Protocol

How AI agents connect to the world

MCP is the open standard that lets AI agents call external tools — files, databases, APIs, and more. ShieldAgent sits between your agents and every tool call, making security and compliance automatic.

43%
of public MCP servers allow command injection
33%
allow unrestricted outbound network access
Up to €35M or 7%
maximum EU AI Act fine per non-conformant system, starting 2 Aug 2026

Three public breaches in the last twelve months used MCP as the attack vector — Supabase via Cursor, Postmark, and CVE-2025-6514 in mcp-remote (437,000 downloads). ShieldAgent would have intercepted all three.

See ShieldAgent in action

Every MCP call inspected. Every threat blocked before it reaches your tools.

Built for your role

One product. Three perspectives.

Choose your role to see how ShieldAgent solves your specific challenges.

Security

MCP Firewall

Inline threat detection for every tool call.

ShieldAgent inspects every MCP JSON-RPC request and HTTP API call in real time. A multi-stage pipeline — policy check, injection scan, DLP — evaluates each request before it reaches the upstream tool. Threats are blocked inline in under 50ms.

  • Prompt injection detection (direct + indirect)
  • Tool poisoning and MPMA detection
  • Dynamic least-privilege enforcement per agent, per tool, per call
  • Shadow mode for risk-free evaluation before enforcement
Read the architecture guide
proxy.shieldagent.io● live
finance-bot → send_emailINC-0042
✕ BLOCKED · 28ms
injection: redirect override detected
analytics-bot → query_dbrisk: 8
✓ ALLOWED · 19ms
policy · injection · DLP — all pass
3 agents · 47 policies activep99 <50ms
28ms block
Compliance

Compliance Autopilot

EU AI Act documentation from your audit data.

ShieldAgent generates all eight mandatory Annex IV sections from the same data it collects during security monitoring. No manual evidence gathering. Compliance score updates in real time as new audit events are logged.

  • Automatic Annex IV technical documentation
  • Real-time compliance scoring per AI system
  • Gap analysis with severity and deadline tracking
  • Cross-framework mapping: EU AI Act, ISO 42001, NIST AI RMF, SOC 2
See compliance output
finance-bot · compliance● generating
94/100PDF ready
Annex IV §1–§8
EU AI Act: compliant
ISO 42001: aligned
NIST AI RMF: mapped
Gaps: 2 low · deadline: Aug 2
94/100
Trust

Agent Passport

Verifiable security certificates for every agent.

Each AI agent gets a shareable passport — a public URL showing its risk score, compliance status, policy controls, and behavioral history. Like a SOC 2 trust page, but for individual AI systems.

  • Public or private verification URL per agent
  • Risk score, compliance grade, and policy summary
  • Continuous monitoring — passports update in real time
  • Embeddable badges for proposals and documentation
See example passport
analytics-bot
acme-corp · verified
grade
A
Risk score91 / 100
EU AI Actcompliant ✓
ISO 42001aligned ✓
Policy controls12 active
Blocked (90d)0
verified · last_checked: 2026-04-16T09:42Z
grade: A

The threat landscape

Every MCP connection is an unguarded attack surface.

INJECTION

Prompt injection via MCP tool calls

43% of public MCP servers contain command injection flaws. Attackers embed malicious payloads in tool responses, redirecting agent behavior at the protocol level.

43%of MCP servers vulnerable
TOOL POISONING

5% of open-source MCP servers ship pre-poisoned

Tool poisoning attacks modify tool descriptions at the source, turning install-and-trust into install-and-compromise. Your agent follows the instructions it was given — including the malicious ones.

5%pre-poisoned at source
DATA EXFILTRATION

DLP blind spots in the agent-to-tool path

33% of MCP servers allow unrestricted outbound access. Agents can leak credentials, PII, and financial data through tool calls that traditional DLP never sees.

33%unrestricted outbound

How ShieldAgent works

An inline proxy that inspects every agent request before it reaches the tool.

ShieldAgent sits in the data path between your AI agents and their MCP servers or HTTP APIs. Every tool call passes through a multi-stage security pipeline — policy check, injection scan, DLP — in under 50ms. Nothing reaches the upstream tool without passing inspection.

Zero code changes

Point your agent at the proxy endpoint. Same MCP protocol, same HTTP calls. ShieldAgent is transparent to the agent.

Policy as code

Define allow/block rules per agent, per tool, per parameter. YAML policies version-controlled alongside your code.

Real-time enforcement

Block threats inline, not after the fact. Median added latency under 50ms. p99 under 80ms.

Full audit trail

Every request, every decision, every block — logged to an immutable Merkle-chain audit trail with cryptographic signatures.

Observability tools tell you what happened. ShieldAgent prevents it from happening.

MCP Firewall

Prompt injection detection (direct + indirect), tool poisoning & MPMA detection, dynamic least-privilege enforcement per agent, per tool, per call.

28ms block

HTTP/REST API Proxy

Same security pipeline for Stripe, GitHub, Slack, and internal APIs. One proxy for every agent connection — MCP and HTTP.

unified

Data Loss Prevention

Configurable regex and ML patterns for PII, credentials, financial data. Block or redact before data leaves your perimeter.

inline

Shadow Mode

Deploy ShieldAgent without blocking anything. See what would have been blocked, what vulnerabilities exist, and what your risk score would be.

--mode=shadow

Human-in-the-Loop

High-risk actions trigger approval gates. Configurable thresholds per policy. Slack and webhook integration for review workflows.

SDKs & API

TypeScript and Python SDKs. OpenAPI spec. Verdict API for programmatic security decisions in your own pipelines.

Comparison

Why not just use an observability tool?

Observability tools show what happened. ShieldAgent prevents it from happening.

Langfuse / Langsmith

Observability only — no blocking, no enforcement, no compliance.

Inline request blocking
MCP protocol native
HTTP/REST API proxy
Prompt injection detection
Tool poisoning detection
DLP (data loss prevention)
Policy as code (YAML)
Immutable audit trailpartial
EU AI Act Annex IV generation
Agent Passport (public)
Prompt Guard / Rebuff

Injection-only detection — no enforcement, no audit, no compliance.

Inline request blockingpartial
MCP protocol native
HTTP/REST API proxy
Prompt injection detection
Tool poisoning detection
DLP (data loss prevention)
Policy as code (YAML)
Immutable audit trail
EU AI Act Annex IV generation
Agent Passport (public)
API Gateways (Kong, etc.)

HTTP-only — no MCP, no AI-specific detection, no compliance.

Inline request blocking
MCP protocol native
HTTP/REST API proxy
Prompt injection detection
Tool poisoning detection
DLP (data loss prevention)partial
Policy as code (YAML)
Immutable audit trailpartial
EU AI Act Annex IV generation
Agent Passport (public)
Manual GRC platforms

Compliance documentation only — no runtime security, no blocking.

Inline request blocking
MCP protocol native
HTTP/REST API proxy
Prompt injection detection
Tool poisoning detection
DLP (data loss prevention)
Policy as code (YAML)
Immutable audit trailpartial
EU AI Act Annex IV generationpartial
Agent Passport (public)
Langfuse / Langsmith

Observability only — no blocking, no enforcement, no compliance.

Prompt Guard / Rebuff

Injection-only detection — no enforcement, no audit, no compliance.

API Gateways (Kong, etc.)

HTTP-only — no MCP, no AI-specific detection, no compliance.

Manual GRC platforms

Compliance documentation only — no runtime security, no blocking.

ShieldAgent complements your existing observability stack. It handles the security enforcement and compliance evidence that observability tools are not designed to provide.

Get started

From install to enforcement in 5 minutes.

Start in shadow mode, review what ShieldAgent finds, enable enforcement when ready.

01
Point your agent at the proxy

Update the MCP endpoint or API base URL in your agent config. No code changes. ShieldAgent proxies the connection transparently.

02
Define policies

Write YAML policies for allow/block rules. Per agent, per tool, per parameter. Ship policies alongside your code.

03
Run in shadow mode

See every request, every threat detected, every block that would have fired. Full visibility before enforcement.

04
Enable enforcement

Switch to enforce mode. Threats blocked inline. Audit trail generates automatically. Compliance evidence starts accumulating.

Why ShieldAgent

Purpose-built for the MCP data path.

ShieldAgent is not an observability overlay or a governance dashboard. It sits inline and makes real-time allow/block decisions on every agent request.

Median latency added< 50ms
Block decision28ms
ProtocolsMCP + HTTP/REST
Detection typesInjection, DLP, drift, agency
Audit trailMerkle-chain, signed
DeploymentManaged SaaS
Read the architecture guide

FAQ

Common questions.

EU AI Act · August 2, 2026

Time remaining until EU AI Act enforcement deadline (August 2, 2026): 0 days, 0 hours, 0 minutes, 0 seconds.

Start protecting your agents today.

Book a 20-minute demo, or start the 14-day Business trial and install the proxy in shadow mode in five minutes.

✓ No credit card to start✓ Shadow mode — zero risk✓ EU data residency✓ <5 min setup