The problem
AI coding agents are now connected to your file system, your CI/CD, your cloud APIs, your Slack, your databases — through MCP servers that most organizations configured in an afternoon. The attack surface is real.
24,000+ secrets found exposed in MCP configurations in early 2026
The governance tooling doesn't exist yet. That's what we're building.
From the blog
All posts →The MCP Security Threat Model
A complete framework for understanding the attack surface of MCP-enabled AI agents in developer environments — 8 threat categories, attack scenarios, mitigations, and a security checklist.
Also delivered as a post series — no email required to read the individual posts. Read the series →