Secure · Agent security

Control every integration,audit every tool call.

Speakeasy sits between your AI agents and internal systems. Authentication, policy, and audit are enforced on every tool call, and security teams get full visibility across every integration in the organization.

Trusted byVerizonMistralCloudinaryLaunchDarklyFivetranPlanetScale

01 · The problem

You can't govern what you can't see

Without a control plane
Where does the data go?
AI tools read and transmit PII, credentials, and financial records with no inspection in the path and no record of what moved
Who approved that server?
Teams connect unapproved MCP servers without security review, opening unmonitored paths into internal systems
Which policy applied?
AI integrations skip the review processes, access controls, and audit requirements that govern everything else
On the control plane
Where does the data go?
Every session is scanned in flight; PII and credentials are detected and flagged before they reach the model
Who approved that server?
Only servers from the curated catalog connect — scanned, version-pinned, and approved before rollout
Which policy applied?
Authentication, policy, and audit enforced on every tool call, recorded in one searchable trail

Speakeasy's AI control plane has been indispensable in enabling Fivetran's AI transformation.

Eli Davis

Fivetran

Fivetran

02 · The control plane

A security control plane for AI usage

Speakeasy sits between your AI agents and internal systems. Connect every integration through one gateway, secure the data in flight, control which servers and tools each team can reach, and observe every call.

Secures every agentAnthropicAnthropicOpenAIOpenAIGoogleGoogleCursorCursorGitHub CopilotCopilotMCP serversInternal APIsCustom agents

03 · Why now

This is already happening inside your organization

AI adoption is outpacing security teams. Agents act on production systems and real data through integrations no one reviewed, and every new connection is an unmonitored path until it crosses a control plane.

Read the Fivetran story

75%

Of enterprises cannot audit AI tool usage across teams

Gartner.

300%

Growth in AI tool usage with little security oversight

Industry data.

40%

Of AI integrations bypass security review entirely

Cloud Security Alliance.

04 · Compliance

Certified and audited

The control plane meets the standards it helps you enforce. Audit reports and compliance documentation are available through the trust center.

SOC 2 Type II

Audited controls for security, availability, and confidentiality of customer data.

Learn more

ISO 27001

Certified information security management system aligned with international standards.

Learn more

GDPR and CCPA

Data processing agreements available. User data deletion on request. TLS 1.3 in transit, AES-256 at rest.

HIPAA ready

BAA available for healthcare organizations. PHI isolation, plus self-hosted deployment with VPC peering.


Every agent

The same controls for every agent

Teams rarely settle on a single agent. The same curation, audit trail, and data protection apply across Anthropic, OpenAI, Google, and the agents your teams build themselves.

Questions

How does Speakeasy handle authentication for MCP servers?
Every MCP server deployed through Speakeasy uses OAuth 2.1 with Dynamic Client Registration (DCR) and PKCE out of the box. Integrate with existing SSO providers like Okta or Entra ID. No credentials are stored on user devices.
What certifications does Speakeasy hold?
Speakeasy maintains SOC 2 Type II and ISO 27001 certifications. Audit reports and compliance documentation are available through the trust center.
Can we restrict which MCP servers are available to specific teams?
Yes. Role-based access control operates at the server, toolset, and individual tool level. Assign different access policies per team, role, or individual. Pair with SCIM for automated provisioning and deprovisioning.
How does data loss prevention work?
Every AI session is scanned in real time for PII, credentials, and financial data using pattern matching and classification models. Sensitive data is detected and flagged before it reaches AI models. Detection patterns are configurable per organization.
Where is data processed and stored?
Speakeasy processes data in SOC 2-certified infrastructure. Tool call payloads are never persisted beyond the audit log. All data in transit uses TLS 1.3 and data at rest is encrypted with AES-256. Data residency options are available for enterprise customers.
How do audit logs work?
Every tool call is logged with the user identity, AI agent, data access scope, timestamp, and result. Logs are searchable in real time and exportable in standard formats for compliance reviews. Retention policies are configurable.
Can Speakeasy detect prompt injection or tool poisoning attacks?
Speakeasy monitors for MCP-specific attack vectors including prompt injection, tool poisoning, tool shadowing, and command injection. Policy violations are detected in real time and flagged in the audit trail.
How do we get started?
Book a demo and our team will walk you through setup, integration with your existing infrastructure, and how to configure policies for your organization.

AI everywhere.

Control here.