Skip to main content
Use cases

One primitive, five operating postures.

Every vertical runs the same two knobs — MCP band cap and OWS signing mode. Pick the posture that matches how your team already operates.

Primitive
MCP_BANDS at server startup
Signer
Yours for read/prepare. Bundled OWS for sign on your infra.
Keys
OWS vault on your infra. Non-custodial by architecture.
Audit
Hash-chained JSONL on your infra
SHARED

What every page answers

Server-side key isolation

MCP server holds no private keys. Signing happens via your OWS vault.

Band filtering at startup

Out-of-band tools never enter the registry — agents cannot see what was never registered.

Policy gates before signing

Chain allowlist, expiry, declarative rules — evaluated before the vault decrypts.

Tamper-evident audit

Every sign and broadcast is a SHA-256 hash-chained JSONL event on your disk.

Self-hosted, non-custodial

Runs in your environment. AES-256-GCM at rest. Decrypted in-memory only during signing.

MCP-compatible

LangChain, CrewAI, Pydantic AI, Claude Agent SDK, or custom MCP runtimes in Python or TypeScript.

Design partner program

Now reviewing a limited number of design partners.

Reference-customer pricing. Contact us to discuss fit.