Control What Data Reaches an Agent
DLP detectors mask sensitive data in real time, before it reaches an agent's context or a tool response — and trust boundary rules decide what's even allowed to cross between security zones in the first place.
One Recognizer Catalog, Six Categories
Every built-in recognizer is grouped into a category so policies can target a whole class of sensitive data by name, not by maintaining a list of individual pattern IDs.
PII
SSN, ITIN, driver's license, passport, and person-name detection — masked before it leaves the gateway.
Financial
Credit card numbers, bank account and routing numbers, IBANs, expiration dates, and CVV/service codes.
Contact
Email addresses, phone numbers, IP addresses, domains, URLs, and physical locations.
Health
Medical license numbers, Medicare Beneficiary Identifiers, diagnoses, and treatments (ICD-10 aware).
Crypto
Cryptocurrency wallet and account identifiers, flagged before they can be relayed to an external tool.
Custom
Bring your own regular expression to detect and mask data specific to your business — proprietary IDs, internal codenames, contract numbers.
Detector or Policy — Whichever Fits Your Workflow
Turn on a category-level DLP detector for always-on coverage, or attach a MASK policy condition to a specific recognizer when you only want masking on a particular tool, alias, or agent tag. Both paths run through the same real-time masking engine.
Masking happens before the response reaches the agent's context — not as an after-the-fact audit finding. What the agent sees is already redacted.
A MASK policy scoped to one alias's PII detectors, and a tenant-wide "Financial" DLP detector for every other request — both active, both real-time, no code required.

Trust Boundaries: Control the Flow, Not Just the Content
Masking protects individual values. Trust boundary rules go a level up: they decide whether a given data category is even allowed to move from one security zone to another — say, from an internal database server to a public-facing tool.
Two enforcement modes
- •Observe — logs and counts every crossing without blocking, so you can validate a rule before it enforces anything.
- •Enforce — actively applies the rule's action to matching crossings in production.
Four boundary actions
- •Block the crossing outright
- •Mask the data in transit
- •Alert without interrupting the request
- •Require approval before the crossing proceeds
Rules are scoped by data type, source and destination zone, and even the specific server alias — so you can allow a data category to flow freely inside a trusted zone while blocking the exact same category the moment it tries to cross into a lower-trust one.
Mask It Before It Leaves
Get real-time DLP masking and trust boundary enforcement for your MCP infrastructure.
Join the Waitlist