Now governing the agent era — MCP tool-call control

The control plane for enterprise AI. Glass box, not black box.

Sluice redacts sensitive data before it ever leaves your tenant, governs every MCP agent and tool call, and proves compliance — all self-hosted on your infrastructure. The modern alternative to $150k black boxes, for about $10k a year.

10x
cheaper than incumbents
18
built-in policy packs
0
data leaves your tenant
01

Glass box, not black box

Self-hostable in your own cloud. Your prompts and data never leave your tenant. Detection is transparent and auditable — no opaque vendor magic.

02

Agent-native

Built for the MCP/agent era. Govern tool calls, not just prompts — discover, score, and block MCP servers and individual capabilities.

03

Developer-first

A LiteLLM-compatible gateway, a clean SDK, and well-documented APIs. Drop it in front of Claude Code, Cursor, or any app in minutes.

The problem

Your company already runs on AI. You just can't see it.

Employees paste customer data into ChatGPT. Coding agents exfiltrate secrets through MCP servers nobody approved. And the only "governance" on offer costs a fortune and ships as a black box you have to trust blindly.

Shadow AI

Dozens of unmanaged AI tools in use across the org. No inventory, no policy, no idea what's leaving.

Prompt leakage

PII, PHI, financial records, and source code flow to third-party models — irreversibly, with no redaction at the edge.

Ungoverned agents

Autonomous agents call tools and external MCP servers with standing access. One poisoned tool and your data walks.

$150k black boxes

Legacy AI-security suites quote $100–150k/yr — opaque SaaS that wants your traffic routed through their cloud.

How it works

One brain. Three ways in.

Every prompt, response, and tool call — wherever it originates — flows through a single scanning and policy engine. Meet your traffic where it already lives with three interchangeable ingress adapters.

Gateway

LiteLLM proxy for Claude Code, Cursor & apps

Browser Extension

Intercepts chatgpt.com, claude.ai & more

SDK

Native calls from your own services

Scanning & Policy Brain
  • Redaction engine
  • Cedar policy eval
  • Risk scoring 0–100
  • Hash-chained audit
Redacted prompt → provider
Policy violation → blocked
Clean response → user
The platform

Everything you need to govern AI — in one engine.

Redaction before egress

PII, PHI, financial data, and secrets are tokenized out of prompts before they reach any provider. Reversible only inside your deployment.

Policy-as-code

Author Cedar policies in plain English with an NL→Cedar compiler. Ship 18 built-in, toggleable packs and version everything in git.

Risk scoring

Every event scored 0–100 on data sensitivity, intent, and context — rolled up per user and per tool to surface the riskiest activity.

MCP & agent governance

Discover MCP tools across endpoints, allow only marketplace-vetted servers, and block an entire server — or a single tool call — in real time.

Complete audit

An immutable, hash-chained log of every event. Inspect the exact redacted prompt and response — with an admin-gated "reveal original".

Compliance reporting

Map AI usage to SOC 2, HIPAA, GDPR, the EU AI Act, ISO 42001, and PCI — and export audit-ready reports on demand.

Enterprise-ready

SSO/SCIM, alerting to Slack, email, and SIEM (Splunk/Sentinel), streaming scan, redaction-map encryption, and FinOps spend tracking.

Self-hostable

Runs entirely in your own cloud or on-prem. No telemetry, no phone-home, no traffic routed through a vendor. Your tenant, your keys.

Injection & jailbreak defense

Detect prompt injection, jailbreak attempts, and hidden markers in both directions — inbound prompts and model output alike.

The differentiator

Govern the agents, not just the prompts.

Prompt scanning is table stakes. The real exposure in 2026 is autonomous agents wielding tools through MCP servers nobody vetted. Sluice is built for exactly this frontier — it treats every tool call as a governed event.

  • Discover. Inventory every MCP server and tool installed across your endpoints, gateways, and agents.
  • Allowlist. A marketplace of known-good servers with provenance — approve by policy, not by accident.
  • Score. Capability-level risk scoring: a tool that can read files or hit the network is rated accordingly.
  • Block. Kill an entire MCP server or intercept a single tool call mid-flight when it violates policy.
See agent governance live
MCP Governance · Tool Inventory
filesystemread_file · write_file · list_dir
Risk 22Allowed
githublist_repos · create_pr · read_issue
Risk 58Allowed
unknown-fetch-mcphttp_get · http_post · exec
Risk 91Blocked
postgresquery · schema
Risk 64Review
Intercepted unknown-fetch-mcp.exec — payload matched secret-exfil pattern. Call denied.
Inside the console

A control plane your security team will actually want to open.

Three views from the Sluice console — audit, policy, and risk — all rendered live in your browser, no screenshots.

Audit Log · Live hash-chained
EventUserSurfaceFindingRisk
14:02:11j.riveraGateway · Cursor API_KEY ▮▮▮▮ redacted61
14:02:09s.okaforExtension · chatgpt.com SSN ▮▮▮-▮▮-▮▮▮▮ redacted88
14:01:55agent:builderMCP · unknown-fetch exec call blocked91
14:01:48m.chenSDK · billing-svc clean — no findings8
14:01:30d.patelExtension · claude.ai PHI ▮▮▮▮▮▮ redacted79
Decryption key never leaves your KMS
Policy Packs · 18
cedar · compiled from English
permit(principal, action, resource)
when {
  resource.contains_pii == false
  && resource.risk < 75
};
Risk · by user (7d)
s.okafor84
j.rivera67
agent:builder61
d.patel43
m.chen12
2,481events scanned today
319redactions
7blocks
Sluice vs the black boxes

The same coverage. None of the lock-in. A tenth of the price.

Capability Sluice Legacy AI-security SaaS Cloud DLP proxy
Self-hostable in your tenantYesSaaSSaaS
Data never leaves your cloudYesNoNo
Transparent / auditable detectionYesPartialBlack box
MCP & agent tool-call governanceNativeLimitedLimited
Policy-as-code (NL→Cedar)YesUI onlyUI only
Gateway + Extension + SDK ingressAll threeProxyProxy
Immutable hash-chained auditYesLogsLogs
No telemetry / phone-homeYesNoNo
Typical annual cost~$10k$100–150k$100–150k
Pricing

Start free. Scale for a tenth of the incumbents.

Community

$0self-host, forever

For teams that want to see everything.

  • Self-hostable scanning & policy brain
  • Gateway, Browser Extension & SDK
  • Core redaction (PII, secrets, source)
  • Risk scoring 0–100
  • Hash-chained audit log
  • Community support
Deploy it yourself

Sovereign

Customair-gapped

For regulated & classified environments.

  • Everything in Enterprise
  • Air-gapped / on-prem deployment
  • Custom policy pack authoring
  • Dedicated solutions engineer
  • ISO 42001 & FedRAMP alignment
  • White-glove onboarding & SLAs
Talk to us

Map every AI interaction to the frameworks your auditors ask about.

  • SOC 2-ready
  • HIPAA
  • GDPR
  • EU AI Act
  • ISO 42001
  • PCI DSS

See your shadow AI in 30 minutes.

We'll stand up Sluice in your environment, point your traffic at it, and show you exactly what's leaving — and how to stop it. No traffic routed through us, ever.

Self-hosted. No telemetry. Your tenant, your keys.