Create Security Policies for MCP Servers
Create security policies to control the data that passes through an MCP gateway, thereby reducing the risk of an AI agent or MCP server receiving data that it shouldn't.
Prerequisites for Security Policies
Establish a connection to the MCP servers that you want to manage.
Create a PII Detection Security Policy
Create a personally identifiable information (PII) detection security policy to detect sensitive data in MCP gateway traffic and block or redact it.
Next steps:
-
If needed, create additional security policies.
-
You can also create business policies. See Add Business Policies for MCP Servers.
-
Create the MCP gateway, if it doesn't exist yet. See Create an MCP Gateway.
Create a Tool Filter Security Policy
Not all tools in an MCP server need to be exposed and discoverable by AI agents. Use a tool filter for an MCP server to define the tools that are available through the MCP gateway.
Next steps:
-
If needed, create additional security policies.
-
You can also create business policies. See Add Business Policies for MCP Servers.
-
Create the MCP gateway, if it doesn't exist yet. See Create an MCP Gateway.