Most tools only watch the request.
We also watch what comes back.

CheckedAgent sits inline between any MCP client and the MCP servers and tools they use, inspecting every request and response in both directions and returning an allow, quarantine, or block verdict — with human review for quarantined items and a hash-chained audit trail.

A compromised MCP server doesn't announce itself — the attack arrives in the response, after every request-side check has passed. CheckedAgent runs a second, purpose-built pipeline on everything a tool returns: is this what the request asked for, and is it safe for wherever it's headed? Most defences never look.

See how the detection pipeline works

Seven things it does by default.

Each one a load-bearing decision. None of them an integration burden you have to carry.

01

MCP-native interception.

Inline sidecar proxy on the JSON-RPC wire — no agent code changes, no model retraining, no developer SDK to integrate.

02

Multi-tier detection pipeline.

Policy fast-path, RE2 patterns, obfuscation analysis, semantic embeddings, behavioral signals, and a dedicated SLM with a 200ms latency budget — every layer independent, every signal logged.

03

Bidirectional inspection.

Request-side prompt injection paired with response-side tool output inspection — closing the gap that single-direction guardrails leave open.

04

Tenant isolation, by construction.

Every query carries a tenant UUID; CORS, identity, rate limits, and audit are scoped per tenant — cross-tenant leakage is architecturally prevented, not policy-enforced.

05

Tamper-evident audit chain.

Every verdict, every signal, every change event written to a hash-chained log — designed for SOC 2, ISO 27001, and EU AI Act Article 12 evidence requirements.

06

Enterprise identity, three-tier trust.

OAuth 2.1, OIDC, mTLS, and a per-agent capability model — tools an agent never uses can never be invoked, even under prompt injection.

07

SOC integration on day one.

Forty-four event categories (30 response-side, 14 request-side), structured for SIEM ingestion, with a live coverage dashboard — your security team sees agent traffic the same way they see network traffic.

What CheckedAgent is not.

CheckedAgent is a layer in your stack, not a replacement for it. We're explicit about our scope so you can see exactly where we plug in — and where we hand off to the identity, hosting, networking, and orchestration partners we work alongside every day.

Not an identity provider.

NOT

We don't manage who agents are — that's Okta and Auth0. We manage what agents do once connected.

// "Okta tells you who. CheckedAgent tells you what they're doing."

Not an MCP hosting platform.

NOT

We don't host tools — that's Runlayer and MintMCP. We protect the communications that flow through them.

// They are the pipes. We inspect what flows through.

Not a general-purpose firewall.

NOT

We understand MCP at a semantic level — not just as network traffic. A firewall can't tell a benign tool call from a prompt injection disguised as one.

// L7 firewalls don't read intent.

Not an agent framework.

NOT

We don't build or orchestrate agents. We secure the communications of agents built by others. Every major platform can route through CheckedAgent.

// Build with anything. Inspect with us.

Drop-in. No code changes. The agent never knows we're there.

CheckedAgent runs as a transparent gateway between your agents and their tools. Point your agent's MCP endpoint at our gateway and you're protected. Self-hosted, single-tenant cloud, or full on-prem — your security review, your call.

  • [01]Compatible with Anthropic, OpenAI, Google, etc. and self-hosted MCP runtimes.
  • [02]Operates inside your VPC.
// REQUEST FLOW
AGENTclaude · chatgpt · gemini
GATEWAYCheckedAgent↓ INSPECT
VERDICTT1 · T2 · T3T4 · T5 · T6
RESULTPASS →BLOCK ✗
TOOLslack · github · postgres
— Request a demo

Every Agent action.
Checked.

30-minute walkthrough with a security engineer — not a sales rep. We'll show the full pipeline, run your suspected attack patterns through it, and answer the questions your auditor is already asking.