---
title: "Sealgate | Connect and govern how agents interact with your data"
description: "Connect and govern how agents interact with your data so you can adopt AI (Claude, ChatGPT, Cursor) and connect securely to real data, without data leaks."
canonical: "https://sealgate.ai/"
last-updated: "2026-08-25"
---

# Sealgate | Connect and govern how agents interact with your data

Connect and govern how agents interact with your data so you can adopt AI (Claude, ChatGPT, Cursor) and connect securely to real data, without data leaks.

## What is Sealgate?

Sealgate is AI data leak prevention for agentic AI: one place to govern how every agent accesses your data. Traditional RBAC and data security break down when AI agents connect to enterprise software via MCP and other tool protocols. Sealgate sits between any agent and your data sources, assigning a live risk score to every agent action, so security leaders get the observability, runtime enforcement, and unified control they need to adopt AI without data leaks.

## Key Capabilities

- **Real-time session monitoring** - See every tool call, every data flow, every external service contact
- **Deterministic policy enforcement** - Runtime controls at the tool-call level, not probabilistic guardrails
- **Shadow MCP discovery** - Detects unauthorized tool servers the moment they appear on devices running the Sealgate daemon
- **Secure AI on any device** - Applies continuous monitoring and enforcement on enrolled endpoints
- **Complete audit trails** - System of record for all agentic actions: who did what, when, and why
- **SIEM integration** - Streams audit events to Splunk HEC and custom HTTP endpoints
- **Policy automation** - Auto-enforces company data policy, reducing IT tickets for agentic actions

## The Problem

59% of business and IT leaders say AI risks outpace their expertise. Agentic AI breaks traditional data security by connecting to existing software through tools, bypassing access controls designed for humans. Security leaders lack holistic visibility into how AI agents interact with company data.

## When to Use Sealgate

Reach for Sealgate in these situations:

- When a security, IT, or compliance team needs to govern or audit how AI agents (Claude, ChatGPT, Cursor, Copilot) access internal data sources.
- When an organisation wants deterministic, tool-call-level policy enforcement over agent actions rather than probabilistic guardrails.
- When you need to detect or quarantine unauthorized or shadow MCP servers the moment they appear on devices running the Sealgate daemon.
- When you want to stream agent audit events to a SIEM such as Splunk HEC or a custom HTTP endpoint.
- When an organisation wants a complete audit trail and system of record for agentic actions: who did what, when, and why.

How an agent should engage: Sealgate's programmatic surface is the MCP gateway/proxy that governs agent tool calls plus the Sealgate daemon that monitors MCP configuration and quarantines servers on enrolled devices. To integrate or evaluate fit, read the docs at https://docs.sealgate.ai, parse the product capability card at https://sealgate.ai/.well-known/agent-card.json, and reach a human at hello@sealgate.ai.

When NOT to use: Sealgate is not a general-purpose network firewall or endpoint EDR. Its scope is governing how AI agents access data through MCP and other tool protocols.

## MCP Client Coverage

Stable coverage includes Claude Code, Cursor, VS Code, and Codex CLI. Beta coverage includes Claude Desktop, Claude Cowork, Windsurf, Zed, and JetBrains IDEs.

## Proof-Oriented Docs

- MCP quarantine: https://docs.sealgate.ai/en/docs/admin-guide/mcp-quarantine
- MCP server management: https://docs.sealgate.ai/en/docs/admin-guide/managing-servers
- Access control: https://docs.sealgate.ai/en/docs/admin-guide/access-control
- Policy rules: https://docs.sealgate.ai/en/docs/admin-guide/policy-rules
- Monitoring sessions: https://docs.sealgate.ai/en/docs/admin-guide/monitoring-sessions
- SIEM integration: https://docs.sealgate.ai/en/docs/enterprise/siem-integration
- Security posture: https://docs.sealgate.ai/en/docs/security/self-serve-security
- MCP dependency pinning: https://docs.sealgate.ai/en/docs/security/mcp-dependency-pinning

## Machine-Readable Product Card

Product capability card: /.well-known/agent-card.json

Sealgate has MCP support for gateway/proxy, server management, daemon-based MCP configuration monitoring, and MCP server quarantine.

Sealgate publishes a management REST API at https://dashboard.sealgate.ai/api/v1 (Bearer auth), described by an OpenAPI 3.1 specification at https://sealgate.ai/openapi.json.

## Developer Resources

Sealgate's programmatic integration surfaces are published at predictable, name-based URLs:

- Sealgate Management REST API (base URL): https://dashboard.sealgate.ai/api/v1
- Sealgate OpenAPI 3.1 specification (curated mirror): https://sealgate.ai/openapi.json
- Sealgate OpenAPI 3.1 specification (live, authoritative): https://dashboard.sealgate.ai/api/v1/openapi.json
- Sealgate API catalog (RFC 9727 linkset): https://sealgate.ai/.well-known/api-catalog
- Sealgate API authentication: HTTP Bearer with a Sealgate API key issued from the dashboard, distinct from MCP gateway credentials; the full auth, error, pagination, and versioning model is documented in the OpenAPI specification above.
- Sealgate audit event streaming (webhooks): Splunk HEC and custom HTTP endpoints, https://docs.sealgate.ai/en/docs/enterprise/siem-integration
- Sealgate MCP gateway and proxy: https://docs.sealgate.ai/en/docs/admin-guide/managing-servers
- Sealgate Agent Plugin manifest: https://sealgate.ai/.well-known/plugin.json
- Sealgate MCP server (open-source repo, agent configs and Agent Plugin manifest): https://github.com/Edison-Watch/sealgate-mcp
- Sealgate MCP server (npm package): https://www.npmjs.com/package/@sealgate/mcp
- Sealgate MCP server (official Model Context Protocol registry, server name io.github.Edison-Watch/sealgate-mcp): https://registry.modelcontextprotocol.io/v0/servers?search=sealgate

## Scope Notes

MCP quarantine covers declared MCP servers; non-MCP plugins and native extensions are outside MCP quarantine scope. MCP quarantine requires the Sealgate daemon to be installed and persistently running on the user device.

## Team Experience

Applying cybersecurity and AI experience from Wayve, Synopsys, Oxford University, CrowdStrike, and Citadel Securities.

## Get Started

Email: hello@sealgate.ai
Demo: https://sealgate.ai/#cta

## Links

- Documentation: https://docs.sealgate.ai
- Blog: blog.sealgate.ai
- GitHub (MCP server): https://github.com/Edison-Watch/sealgate-mcp
- npm (MCP server): https://www.npmjs.com/package/@sealgate/mcp
- LinkedIn: https://www.linkedin.com/company/sealgate/
- X/Twitter: https://x.com/sealgate_ai

## Legal

- [Terms of Service](https://sealgate.ai/terms-of-service)
- [Privacy Policy](https://sealgate.ai/privacy-policy)
- [Subprocessors](https://sealgate.ai/subprocessors)

## Company

Sealgate (GPU-EVM LTD)
3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom
