How MoonPay brought its AI sprawl under control with Speakeasy
MoonPay
FinTech
Security
AI Control Plane
Speakeasy
MoonPay is a unified payments platform that allows customers, wallets, exchanges, and businesses to seamlessly move between fiat and digital assets. Trusted by over 30 million people and 900+ partners worldwide, MoonPay connects traditional payment rails and blockchains through a single integration, so users can buy, sell, send, trade, and pay without ever leaving a product.
As MoonPay’s business is built on moving money and holding sensitive customer data, its security team has to deliver speed and control at the same time. When MoonPay’s leadership decided to put AI in the hands of every employee, the security team’s job was to make that rollout safe without slowing it down.
200+
MCP servers under governance60K+
Agent sessions secured5K+
MCP connections brokeredSecuring the AI rollout
MoonPay adopted AI across the company early. Engineers worked with leading AI-powered coding tools. Non-technical teams ran their daily work through AI assistants. In a matter of months, MoonPay went from experimenting with AI to operating on it. Securing that shift became the responsibility of the security team, which is now under growing strain as demands on the function continue to rise.
As AI assistants began proliferating across the enterprise, MoonPay put browser-level controls in place, in line with the conventional approach to governing AI assistants. But by then, AI had already moved beyond the browser. Employees were beginning to connect AI assistants directly to internal systems, including messaging platforms, productivity suites, email, and calendars, using protocol-based connectors. Once connected, those agents could do more than retrieve information. They could act inside sensitive systems: send messages, edit documents, and change records. And once a connector was approved for a single use case, visibility often ended there.
“The browser-based approach we relied on just doesn't see this layer anymore.”
Thierry Dang,
Security Operations at MoonPay
Inside the company, AI use had evolved into something far more connected and autonomous, but the security team still had no reliable inventory of which MCP servers employees were running. That is what makes shadow AI so difficult to contain: the tools themselves may be sanctioned, yet their connections can spread quietly beyond anyone’s line of sight. For a regulated payments company, that lack of visibility is more than simply uncomfortable.
The MoonPay security team’s requirement was specific:
- Visibility first. Full visibility into AI tool and MCP usage, with detection and active response layered on top.
- Cross-agent coverage. One platform spanning Claude (both Code and the desktop Cowork experience), Codex, Cursor, and Gemini.
- Active enforcement. The ability to block unsanctioned shadow MCP servers at the point of use.
And it all had to work in production today.
A range of vendors were evaluated, but most were still selling a roadmap rather than a finished product.
“Everyone was selling me a future. I had a problem in production right now. I needed something that worked across all our AI clients today, not a roadmap.”
Thierry Dang,
Security Operations at MoonPay
That production-ready bar is what brought Speakeasy to the table, and what the proof of concept was built to test.
So MoonPay ran a tightly scoped, time-boxed proof of concept: 30 days, written success criteria, and the Speakeasy AI control plane stood up across its real AI agents. The evaluation criteria included technical compatibility across developer and desktop AI tools; accurate detection of PII, cardholder data, and PHI; enforcement of MCP policies; SSO and RBAC integration through the company’s identity provider; and an exportable audit trail that could feed into the organization’s SIEM.
It came together fast. SSO went live, custom MCP servers to key workplace systems were brought under a centralized control plane, and audit logs began recording every tool call, user, prompt, and result. Within weeks, MoonPay had full visibility into AI agent sessions for the first time, and most employees barely noticed the change.
A cross-agent control plane
The control plane brought agent usage into one place, in line with a visibility-first, then-control approach.
- Connect everything, safely. MCP access brokered through an MCP gateway using OAuth 2.1 with DCR and PKCE, plugged into MoonPay’s existing Okta identity, with role-based permissions scoped per server, per tool, and per team. Unsanctioned shadow MCP servers are blocked by default.
- Observe everything. Full session observability across AI tools made it possible to see who used which tool, what they asked, what the agent did, and what it returned, with risk activities exported to the company’s SIEM for investigation.
- Enforce in real time. Policy-based detection for PII, cardholder data, secrets, prompt injection, and destructive commands, with the option to start in log-only mode to understand the environment before turning on blocking.
Crucially, the coverage matched the AI tools employees were already using, including desktop chat applications and AI coding tools that other vendors in the evaluation could not govern. A single control plane spanning both technical and operational workflows made secure AI deployment across the company a practical possibility.
Live across the whole org
What began as a proof of concept quickly turned into a full production deployment across the company in a single rollout. Observability was extended into the AI tools employees were already using, while the security team brought multiple custom MCP servers behind the control plane and deployed them organization-wide. The deployment scaled across the organization without disruption.
“Speakeasy went live in production across the entire MoonPay org, and it landed without a hitch.”
Thierry Dang,
Security Operations at MoonPay
That frictionless rollout turned the platform from a security tool into an organization-wide standard. Because the control plane is integrated with the company’s existing identity infrastructure and did not alter day-to-day workflows, the security team was able to move from proof of concept to company-wide deployment without a disruptive migration.
What’s next
MoonPay’s AI governance footprint continues to expand. The next phase is focused on broadening its library of custom connectors to cover more business needs, extend monitoring across additional AI tools, and implement detection and response policies on top of the observability layer already established. At the same time, internal demand for team-level sharing of skills and practices points to a broader maturation of AI use across the company.
For a regulated payments company, the lesson is straightforward. AI adoption and security are not a trade-off. With the right control plane, MoonPay said yes to AI across the company and got the visibility and control to back it up.
Learn more about securing AI usage across your organization:
Info sheet
Company
MoonPay
Website
moonpay.comAbout
Crypto payments infrastructure, the fiat-to-crypto on- and off-ramp powering wallets, exchanges, and brands worldwide.
Industry
FinTech, Security, AI Control Plane