THE GOVERNED MCP GATEWAY SHIP AGENT CAPABILITY · PROVE CONTROL · YOUR INFRASTRUCTURE BY DIGITALAPI.AI

Enterprise MCP governance · self-hosted or managed

Every agent call, through one gate you control.

MCP — the protocol agents use to discover and call tools — is spreading through your company one server at a time. Amelfi puts every call on one governed path: agents see only approved tools, credentials never leave the broker, and every decision is on the record, inside your infrastructure.

Security review
ONCE
Unapproved tools
INVISIBLE
Revocation
ONE PLACE
Runs in
YOUR CLOUD
ROUTE CHART — PROD POLICY V3 · DEFAULT DENY · SAMPLE
01 02 03 04 05 06 authn discover policy creds route audit denied at 03 — never reaches upstream agents sales-agent support-bot ci-workload etl-job approved tools crm_update contract_read tickets every call takes the same path
AUDIT · METADATA ONLY LIVE SAMPLE

The gap

Your IdP governs login. Your API gateway governs services. Nobody governs this.

Count the MCP servers already running in your org; the number isn't zero. Each one ships its own tool list, credential flow, and audit story — a pattern security can't approve at enterprise scale.

LAYER 1 · COVERED

Identity layer

Your identity provider decides who can log in. Solved, standardized, audited.

LAYER 2 · COVERED

Network & API layer

Your API gateway governs service-to-service calls. Solved, standardized, audited.

LAYER 3 · UNGOVERNED

Agent-to-tool layer

Which tools may an agent discover — and call, with whose credentials? This is the boundary Amelfi governs.

The visual model

See the governed gateway, not another architecture paragraph.

Thirteen illustrated guides trace the boundary from discovery and credentials through routing, policy, incidents, and operations.

The illustrated guide to MCP Gateway

From API sprawl to one governed path.

follow every boundary.

A visual library for teams already building with MCP: policy-filtered discovery, credential brokering, private connectors, deployment boundaries, incident drills, and the control-plane triage loop.

The adoption tax

Every team is paying the MCP adoption tax — twice.

Each new MCP server re-implements the same boundary from scratch. Each one is a security review that never actually happens. Set the dial to your org and watch the tax compound — then pay it once instead.

statement · mcp adoption hand-rolled mode
servers in your org
4 servers
52
subsystems rebuilt
64
eng-weeks spent
4
reviews owed · 0 done

the sprawl

Each hand-rolled server re-implements all thirteen subsystems: authentication, authorization, agent identity, tool-level access, credential handling, private connectivity, discovery and approval, audit logging, SIEM export, session handling, rate limits and quotas, health and metrics, incident response.
payments-mcp
crm-mcp
infra-mcp
search-mcp

every column is the same 13 subsystems, rebuilt from scratch — hover any cell.

the bill · per server

01Authentication2 wks
02Authorization2 wks
03Agent identity1 wk
05Credential handling1 wk
08Audit logging1 wk
··8 more subsystems9 wks

subtotal · 13 subsystems16 eng-wks
× servers4

TOTAL DUE64 eng-wks

+ 4 security reviews owed · 0 completed

THE FIX · OFF

Flip the switch: Amelfi ships all thirteen as shared infrastructure — reviewed once by security, reused by every team, revoked from one place.

See the controls

Illustrative counts — the subsystems every hand-rolled boundary re-implements. Your list is probably longer. Read the full breakdown →

Control model

Every sprawl failure maps to a default-deny control.

Deny overrides allow. Unauthorized tools are hidden at discovery — not denied after the fact.

Visible denied tools

Policy-filtered discovery

Discovery is part of authorization. An agent's tool list contains only what it may call — everything else doesn't exist. Try the rule:

POLICY SIMULATIONSALES-AGENT · PRODSAMPLE
Policy v3 · default deny
allow contract_read
allow crm_get_account
The agent's tool list
  • contract_read
  • crm_get_account
  • crm_update_stage

1 tool hidden at discovery. It doesn't exist to this agent.

Deny removed: crm_update_stage is now discoverable and callable in prod.

Loose secrets

Credential broker

Service, user-delegated OAuth, agent-scoped, and workload credentials resolved at call time. The agent holds an opaque reference — nothing to leak, nothing to rotate out of a repo.

agent broker tool ref:cr-7f2 s•••••t never sees the secret resolved server-side, at call time
Server sprawl

Approved registry

Private MCP servers and selected API operations registered with owner, risk, environment, and approval before anything is exposed.

"Who can call this?"

Policy + simulation

Versioned, default-deny authorization with explicit deny and pre-deployment simulation. Every decision has a stable, human-readable reason.

No audit trail

Metadata-only audit

Who, what, when, why, which policy version — searchable and exportable to your SIEM. Payloads and secrets never appear.

Slow incident response

Revocation + emergency disable

Revoke a tool, credential, server, agent, or session. Emergency disable shows blast radius before it fires and requires a reason.

The governed path

One drawing for the path every governed call takes.

A governed call passes six gates between an agent and your backend. A denied call fails closed with a clear reason — before the upstream is ever touched.

TRUST BOUNDARY — GOVERNED SEGMENT ZONE A — YOUR AGENTS MCP CLIENTS chat · IDE · hosted platform AGENTS / WORKLOADS owned · scoped · revocable AMELFI GATEWAY RUST DATA PLANE · SELF-HOSTED 1 · AUTHN / IDENTITY 2 · CEDAR PDP 3 · DISCOVERY FILTER 4 · CREDENTIAL BROKER 5 · PRIVATE ROUTER 6 · AUDIT EMITTER SESSIONS: AFFINITY · RECONNECT · DRAIN · TERMINATE · REVOKE FAIL CLOSED · REASON CODE no upstream attempt ZONE B — YOUR PRIVATE ESTATE PRIVATE MCP SERVERS approved + registered INTERNAL APIS selected ops → MCP tools OTEL / SIEM your telemetry sink 1 2 3 4 5 6

> deny path: fail closed at the first gate that says no — clear reason, no upstream attempt, full audit record. See the six gates in the product →

Find your page

Three jobs share this boundary. Start on yours.

On the other side of the boundary? Tool owners and agent builders get less friction than the ungoverned path. Five worked scenarios live in Solutions.

There are five ways to solve this without us — including doing nothing. The comparison covers when each one is the right call, and where we lose.

Read the honest comparison

Why we're building this

We spent years watching enterprises connect software to software — and reviewing what happens when that's done without governance. Agents raise the stakes: they discover capabilities on their own, hold credentials they shouldn't, and act faster than any review cycle.

We believe the answer isn't slowing agents down — it's giving them one path that security already trusts. That's what we're building, in the open where it counts: no invented metrics, no claimed certifications we don't hold, runnable evidence for everything we ship.

— the Amelfi team at DigitalAPI.ai

Pricing without a security tax

Security isn't paywalled.

Every plan runs the same governance core. You pay for capacity, integrations, and support, never for a safer version of the gateway.

Compare plans

Next step

Start where you're comfortable.

Read for five minutes, talk for twenty-five, or bring one real boundary and prove the whole path with your security team watching.

5 MIN

Read the docs

Quickstart, Helm install, policy guide. See exactly what you'd be running before you talk to anyone.

Open the docs
25 MIN

Book a walkthrough

A working session on your architecture: where the gateway sits, what your IdP and SIEM see, what a pilot would look like.

Book a walkthrough
4–6 WEEKS

Run a pilot

One boundary, on your infrastructure: one allowed call, one denied call, one revocation — witnessed end to end.

Talk to the team

Scope your first governed boundary

We reply to every message — or write to us directly. Early design partners shape the roadmap.

[ ✓ ]

Message received.

We'll get back to you to schedule a walkthrough and scope your first governed boundary.