Install
$ agentstack add mcp-aegisgatesecurity-aegisgate-platform β scanned Β· β verified, works with Claude Code, Cursor, and more.
Security review
β PassedNo issues found. Passed automated security review. Β· v0.1.0 How review works β
- β Prompt-injection patterns
- β Secret / credential exfiltration
- β Dangerous shell & filesystem operations
- β Untrusted network calls
- β Known-malicious package signatures
What it can access
- β Network access No
- β Filesystem access No
- β Shell / process execution No
- β Environment & secrets No
- β Dynamic code execution No
From automated source analysis of v0.1.0. βUsedβ means the capability is present in the source β more access means more to trust, not that itβs unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work βAbout
π‘οΈ AegisGate Security Platform
Secure every AI interaction. Six pillars. One gateway. Zero external dependencies.
[](https://github.com/aegisgatesecurity/aegisgate-platform/releases/tag/v3.5.0) [](LICENSE) [](https://golang.org/) [](https://github.com/aegisgatesecurity/aegisgate-platform/actions) [](https://github.com/aegisgatesecurity/aegisgate-platform/actions) [](docs/compliance/eu-ai-act.md) [](https://github.com/aegisgatesecurity/aegisgate-lens)
π Website Β· π Live Demo Β· π Pricing Β· π Docs Β· [π Security](SECURITY.md) Β· π¬ Discussions
> π§© Using AI without enterprise protections? AegisGate Lens is our free browser extension that brings 153 detection patterns to everyday AI conversations β for the 95% of users who don't have a security gateway. Install Lens β
Why AegisGate?
Every AI interaction is an attack surface. Prompt injections leak secrets. MCP servers exfiltrate context. A2A agents escalate privileges across trust boundaries. A single misconfigured LLM response can expose PII, violate compliance, or hand an attacker a credential.
AegisGate sits in front of all of it β one binary, zero dependencies, fail-closed by default.
- Sub-millisecond overhead. 3.2ms p95 at 24K+ RPS. Your users won't notice it's there.
- Fail-closed. If AegisGate can't scan a response, it blocks it. No silent failures, no pass-through on error.
- Self-hosted. No API keys to rotate, no third-party to trust. Your data stays in your infrastructure.
- 6 pillars, one gateway. HTTP, MCP, A2A, ACP, RESPONSE, and Trust β no patchwork of point products.
- 153 detection patterns. Secrets, XSS, PII, and compliance β wired into every response, every time.
- Red-team hardened. 26/27 adversarial tests pass. TRACE methods rejected. All security headers present. No
unsafe-evalin CSP.
Security Posture
| Metric | Value | |--------|-------| | CVEs | 0 | | Red team tests passed | 26 / 27 | | Fail-closed by default | β | | TRACE/CONNECT/TRACK blocked | β | | Security headers (CSP, CORP, COEP, COOP, HSTS) | β | | Private keys in git | 0 (rotated, gitignored, pre-commit blocked) | | Code-scanning alerts open | 0 | | Dependabot alerts open | 0 |
Request Flow
flowchart LR
Client["π€ Client / Agent"] -->|"HTTP Β· MCP Β· A2A"| Gateway["π‘οΈ AegisGate"]
subgraph Pillars["6 Protection Pillars"]
direction TB
HTTP["HTTP APIpkg/response/"]
MCP["MCPpkg/mcpserver/"]
A2A["A2Apkg/a2a/"]
ACP["ACPpkg/acp/"]
RESP["RESPONSEpkg/response/detectors/"]
TRUST["Trustpkg/attestation/"]
end
Gateway --> Pillars
Pillars -->|"Scanned β
"| LLM["π€ LLM / AI Service"]
Pillars -->|"Blocked β"| Client
LLM -->|"Response"| Gateway
Gateway -->|"Clean"| Client
Gateway -->|"Sanitized / Rejected"| Client
subgraph Infra["Infrastructure"]
PG[("PostgreSQLpersistence")]
Redis[("Redisrate limiting")]
end
Gateway --- Infra
Detection Engine
The pkg/response/detectors/ package provides 153 regex patterns with full Lens parity:
| Category | Patterns | What it catches | |----------|----------|-----------------| | Secrets | 45 | AWS keys, GitHub PATs, Stripe keys, JWTs, GitLab tokens, Twilio, SendGrid, private keys | | XSS | 12 | `, event handlers, javascript:`, SVG-based, encoded variants | | PII (US Core) | 15 | SSN, phone, DOB, MRN, ZIP+4, full names with context | | PII (Extended) | 13 | Email, IP addresses, passport numbers, driver's licenses | | PII (International) | 9 | National IDs (NHS, SIN, TFN, IRD, BSN, CF, SSN-IT, NRIC, MyNumber) | | PII (Financial) | 24 | Credit cards, IBANs, SWIFT/BIC, routing numbers | | Compliance | 35 | GDPR data types, HIPAA PHI indicators, PCI-DSS card data, CCPA personal info |
import "github.com/aegisgatesecurity/aegisgate-platform/pkg/response/detectors"
// Scan all 153 patterns
matches := detectors.DetectAll(text)
// Scan by category
secrets := detectors.DetectSecrets(text)
xss := detectors.DetectXSS(text)
pii := detectors.DetectPIIUSCore(text)
compliance := detectors.DetectCompliance(text)
// Wired into ResponseGuard (default: enabled)
guard := response.NewResponseGuard()
result, _ := guard.Scan(ctx, text)
// result.DetectedXSS, result.DetectedCompliance, result.DetectedPII, result.DetectedSecrets
How AegisGate Compares
| Capability | AegisGate | Generic AI Firewalls | |------------|-----------|----------------------| | HTTP API scanning | β Native | β | | MCP guardrails | β Native | β Plugin or missing | | A2A protocol security | β Native | β Not supported | | ACP enforcement | β Native | β Not supported | | Response scanning (153 patterns) | β Built-in | β οΈ Limited or external | | Cryptographic attestation | β Native | β Not available | | Self-hosted, zero dependencies | β Single binary | β Requires external services | | Fail-closed by default | β | β οΈ Often fail-open | | 15+ compliance frameworks | β | β οΈ 3β5 typical | | PostgreSQL + file persistence | β | β οΈ Cloud-locked | | HA clustering | β Native | β οΈ Enterprise add-on | | Open source (Apache 2.0) | β | β Proprietary |
v3.5.0 Highlights
| Feature | Description | |---------|-------------| | FedRAMP 151/170 Automated (88.8%) | Compliance Engine v2: 69 controls promoted from manual/stub to real CheckFuncs. 19 remaining are customer-responsibility. | | gRPC Service Layer | 7 services, 50 RPCs with health checking, reflection, and TLS | | Trust API Attestation | Cryptographic attestation generation and verification (RFC 3161 TSA) | | SIEM Promotion | Real event forwarding to Splunk/Datadog/ELK (no longer a stub) | | SSO Persistence | PostgreSQL-backed OIDC session storage with TTL and ACR value mapping | | Token Analytics | Per-request token usage metrics wired into the request pipeline | | PDF Export | Questionnaire results export to formatted PDF with scoring and evidence citations | | 153-Pattern Detection Engine | Full Lens parity: 45 secrets, 12 XSS, 15+13+9+24 PII, 35 compliance patterns | | PostgreSQL Persistence | 6 integration test suites (107 tests) via testcontainers-go | | HA Clustering | Multi-node deployments with distributed rate limiting, instance identity, and health checks | | Security Hardening | 5 auth bypass fixes, localhost-only metrics, CSP hardening. 26/27 red team tests pass |
6 Pillars
| Pillar | Package | Description | |--------|---------|-------------| | HTTP API | pkg/response/ | Request/response scanning, PII redaction, secret masking | | MCP | pkg/mcpserver/ | Model Context Protocol guardrails | | A2A | pkg/a2a/ | Agent-to-Agent protocol security | | ACP | pkg/acp/ | Agent Capability Policy enforcement | | RESPONSE | pkg/response/detectors/ | 153-pattern detection (secrets, XSS, PII, compliance) | | Trust Framework | pkg/attestation/, pkg/trust/ | Cryptographic attestation, CISO posture digest |
Compliance Coverage
| Framework | Controls | Package | |-----------|----------|---------| | EU AI Act | 82 | pkg/compliance/eu-ai-act/ | | FedRAMP (NIST 800-53) | 170 (151 automated) | pkg/compliance/fedramp/ | | SOC 2 Type II | 5 | pkg/compliance/soc2/ | | ISO 27001 | 14 | pkg/compliance/iso27001/ | | HITRUST CSF | 6 | pkg/compliance/hitrust/ | | TISAX | 7 | pkg/compliance/tisax/ | | CMMC Level 2 | 14 | pkg/compliance/cmmcl2/ | | NIST 800-171 | 14 | pkg/compliance/nist800171/ | | FIPS 140-2 | 11 | pkg/compliance/fips/ | | NIST AI RMF | 8 | pkg/compliance/nist_ai_rmf/ | | CCPA | 7 | pkg/compliance/ccpa/ | | HIPAA | 11 | pkg/compliance/hipaa/ | | PCI-DSS | 12 | pkg/compliance/pci/ |
Quick Start
# Build
go build -o aegisgate ./cmd/aegisgate-platform
# Run with defaults (in-memory stores)
./aegisgate
# Run with PostgreSQL
export DATABASE_URL="postgres://user:pass@localhost:5432/aegisgate"
./aegisgate
# Run integration tests (requires Docker)
go test -tags=integration -timeout 300s ./pkg/ioc/... ./pkg/persistence/...
Architecture
cmd/aegisgate-platform/ # Binary entry point
pkg/
βββ a2a/ # Agent-to-Agent security
βββ acp/ # Agent Capability Policy
βββ attestation/ # Cryptographic envelope (Sign/Verify/VerifyWithKey/VerifyOnline)
βββ audit/soc2/ # SOC 2 evidence collection
βββ compliance/ # 15+ framework modules
βββ cluster/ # HA clustering & distributed rate limiting
βββ correlation/ # Event correlation engine
βββ cve/ # CVE-for-AI feed
βββ detectors/ # 153-pattern detection engine
βββ evaluator/ # Adversarial benchmark suite
βββ ioc/ # IOC management
βββ mcpserver/ # MCP guardrails
βββ persistence/ # Storage backends (file + PostgreSQL)
βββ rbac/ # Role-based access control
βββ response/ # 6-pillar response guard
βββ trust/ # Trust Framework (6 sub-packages)
βββ testdb/ # Shared testcontainers infrastructure
Testing
# Unit tests (99 packages)
go test ./...
# Integration tests (6 PostgreSQL packages, requires Docker)
go test -tags=integration -timeout 300s ./pkg/ioc/... ./pkg/persistence/... ./pkg/rbac/... \
./pkg/license/... ./pkg/correlation/... ./pkg/attestation/...
# Coverage
go test -coverprofile=coverage.out ./...
go tool cover -func=coverage.out | grep total
License
Apache 2.0 β see [LICENSE](LICENSE).
Security
See [SECURITY.md](SECURITY.md) for vulnerability reporting. See [govulncheck.toml](govulncheck.toml) for the GO-2026-5932 suppression (openpgp transitive, not called).
π AegisGate Security Β· [βοΈ support@aegisgatesecurity.io](mailto:support@aegisgatesecurity.io) Β· π¦ X/Twitter Β· π Mastodon
Made with π€ by AegisGate Security developers to secure the AI attack surface.
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source β we do not rehost the code.
- Author: aegisgatesecurity
- Source: aegisgatesecurity/aegisgate-platform
- License: Apache-2.0
- Homepage: https://aegisgatesecurity.io/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.