Secure · Agent security
Control every integration,audit every tool call.
Speakeasy sits between your AI agents and internal systems. Every prompt, response, and tool call is checked against policy in flight, and security teams get full visibility across every agent, MCP server, and Skill in the enterprise.
01 · The problem
You can't govern what you can't see
Speakeasy sees every action.
AI tools read and transmit PII, credentials, and financial records with no inspection in the path and no record of what moved
Every session is scanned in flight; PII and credentials are detected and flagged before they reach the model
Teams connect unapproved MCP servers without security review, opening unmonitored paths into internal systems
Only servers from the curated catalog connect, scanned, version-pinned, and approved before rollout
AI integrations skip the review processes, access controls, and audit requirements that govern everything else
Authentication, policy, and audit enforced on every tool call, recorded in one searchable trail
The browser-based approach we relied on just doesn't work for AI-based workflows.

Thierry Dang
Security Operations
02 · The control plane
Every agent action, secured on one control plane
Understand how AI is used, define what it can access, and enforce security policy across every agent, MCP server, and Skill in your enterprise. One governed path between your agents and your systems.
- 1. Curate
- Approval workflow before rollout
- Releases scanned for excessive scopes
- Access follows your identity provider
03 · How it works
Legacy tools can't see the loop
An agent works in a loop: prompt, model, tool call, result. Your existing security stack sits around that loop and sees encrypted traffic between sanctioned endpoints. Speakeasy sits in the loop, where every step is readable and enforceable.
Each tool watches its own layer. None of them can read what an agent says or does.
- SWG / CASB
- Sees domains and SaaS logins. An agent writing to production through an MCP server is ordinary TLS to an approved endpoint
- DLP
- Scans files, email, and endpoints. Customer records leave inside prompts and tool payloads it never parses
- EDR
- Watches processes and binaries. The agent is a sanctioned app on a managed device; the risk is in what it sends, not what it runs
- SIEM
- Correlates the events it receives. Agent sessions emit none, so there is nothing to alert on
Speakeasy is the path between your agents and your systems, so policy runs where the action happens.
01
Deploy through your MDM
Roll out to every device with Jamf, Intune, or the MDM you already run. Coverage is fleet-wide from day one, with no per-team setup.
02
Route every agent
Claude, ChatGPT, Cursor, and the agents your teams build act through the control plane, each under its own identity from your identity provider.
03
Enforce policy in flight
Every prompt, response, and tool call is checked in real time. Allowed actions continue to your systems, violations stop at the plane, and every decision lands in the audit trail.
Becoming AI-native meant that we needed an entirely new governance & security stack. You can't use old tools to cover your team's new way of working.

Shreyas Kumar
Co-founder, Fermat
04 · In production
Proven where the stakes are highest
Security teams at payments, fintech, and infrastructure companies run the control plane in production: company-wide rollouts, tens of thousands of governed agent sessions a week, and shadow MCP usage brought into one catalog.
Read the MoonPay security story60K
Agent sessions governed per week
MoonPay enforces policy across every agent, org-wide.
100%
Employee AI rollout, governed
Fermat rolled out governed AI to the whole company.
200%
MCP usage growth under governance
PlanetScale customers are now agent-based.
05 · Compliance
Certified and audited
The control plane meets the standards it helps you enforce. Audit reports and compliance documentation are available through the trust center.
SOC 2 Type II
Audited controls for security, availability, and confidentiality of customer data.
Learn moreISO 27001
Certified information security management system aligned with international standards.
Learn moreGDPR and CCPA
Data processing agreements available. User data deletion on request. TLS 1.3 in transit, AES-256 at rest.
HIPAA ready
BAA available for healthcare organizations. PHI isolation, plus self-hosted deployment with VPC peering.
Questions