Tumiki MCP
Patented — MCP management platform

Every MCP server,
under one gateway

Who called which tool, from which AI client. Every call is logged. Out-of-policy calls and PII stop before they land.

Your data
Never leaves your network
Authentication
Connects to your IdP
Audit logs
Stored in your environment

No sign-up required.

↓ It's live

CursorCursor
ChatGPTChatGPT
ClaudeClaude
CopilotCopilot
GitHubGitHub
NotionNotion
SlackSlack
FigmaFigma
VercelVercel
Google DriveGoogle Drive
SentrySentry
PostgreSQLPostgreSQL
CursorCursor
ChatGPTChatGPT
ClaudeClaude
CopilotCopilot
GitHubGitHub
NotionNotion
SlackSlack
FigmaFigma
VercelVercel
Google DriveGoogle Drive
SentrySentry
PostgreSQLPostgreSQL

MCP servers keep multiplying.
The controls to manage them don’t exist yet

Few companies can say what their AI connects to.

40%Enterprise apps carrying AI agentsPredicted for end of 2026
25%GenAI apps hitting 5+ incidents a yearPredicted for 2028
40%+Agentic AI projects that get canceledPredicted by end of 2027

Live demo

Don't read about it —
try it right here

Change a permission and the log updates on the spot.

Step 1 / 3

Which MCP servers are connected

Connected servers and the ones you can add, side by side. Click a card to see its tools.

tumiki — MCP connectors
Connected

MCP connectors

Click a card to add an MCP server

Auth:20

Architecture

Three layers that keepMCP traffic under control

FIG 1.0

PII masking

Masked before it reaches an MCP server.

FIG 1.1

Fine-grained permissions

Read / write / execute rights per server and per tool.

FIG 1.2

Everything on record

Every call stored in your own environment.

Monitor. Control. Record.
MCP management in one place.

Monitor

Monitor every MCP call

Who called which tool, from which AI client — recorded line by line.

342,800
Total requests
1,247
Blocked
99.6%
Success rate
8,420
PII masked
MCP tool call log
Real time
17:22:43
T
Tanaka
CursorCursor
GitHubGitHub
create_pr✓ Success1.2s
17:22:25
S
Suzuki
ChatGPTChatGPT
NotionNotion
search_pages✓ Success0.8s
17:21:34
Unknown
ClineCline
Internal DBInternal DB
export✕ Blocked
17:21:00
Y
Yamada
CursorCursor
FigmaFigma
get_design✓ Success2.1s
17:20:45
S
Sato
ChatGPTChatGPT
SlackSlack
send_message✓ Success1.5s
17:18:30
S
Suzuki
CursorCursor
Microsoft TeamsMicrosoft Teams
schedule_meeting✓ Success0.9s
17:16:05
T
Tanaka
CursorCursor
GitHubGitHub
merge✕ Blocked
Export:CSVJSONSIEM

Control

Control MCP tools down to the call

Define what each role can do, tool by tool.

Switch a tool off and the log above turns to “blocked”.

Full access · 3members
GitHubGitHub
4/4
NotionNotion
3/3
FigmaFigma
3/3
Google DriveGoogle Drive
3/3
SlackSlack
3/3
Internal DBInternal DB
3/3
SentrySentry
3/3
Microsoft TeamsMicrosoft Teams
3/3
OneDriveOneDrive
3/3
PlaywrightPlaywright
3/3
Developer tools only · 12members
GitHubGitHub
3/4
NotionNotion
2/3
FigmaFigma
0/3
Google DriveGoogle Drive
0/3
SlackSlack
3/3
Internal DBInternal DB
0/3
SentrySentry
3/3
Microsoft TeamsMicrosoft Teams
0/3
OneDriveOneDrive
0/3
PlaywrightPlaywright
3/3
Design tools only · 5members
GitHubGitHub
0/4
NotionNotion
0/3
FigmaFigma
3/3
Google DriveGoogle Drive
2/3
SlackSlack
1/3
Internal DBInternal DB
0/3
SentrySentry
0/3
Microsoft TeamsMicrosoft Teams
1/3
OneDriveOneDrive
2/3
PlaywrightPlaywright
0/3
Business tools only · 8members
GitHubGitHub
0/4
NotionNotion
1/3
FigmaFigma
0/3
Google DriveGoogle Drive
2/3
SlackSlack
2/3
Internal DBInternal DB
0/3
SentrySentry
0/3
Microsoft TeamsMicrosoft Teams
3/3
OneDriveOneDrive
2/3
PlaywrightPlaywright
0/3
Policy change historyLast 3
14:32Admin ADev → GitHub/mergeOFF → ON
14:28Admin ASales → Internal DBON → OFF
13:55Admin BDev → Notion/exportOFF → ON

Agent Builder

Combine MCP tools into
a purpose-built agent

Tools and descriptions prepared for you. A virtual MCP server, without code.

Pick a job and the tools and descriptions change with it

1Pick the job
Y

“Look at our GitHub, Notion and Slack so I can check progress and tidy up tasks”

2Tool selection & description tuning
3 tools selected
GitHubGitHub/list_issues
List issues in a repository
Call this for progress and open work. Return a completion rate.
NotionNotion/search_pages
Search for pages in the workspace
Call this to confirm specs and decisions. Search “meeting notes” first.
SlackSlack/send_message
Send a message to a channel
Call this to share updates. Post to #dev only.
3Agent ready → delivered to your AI clients
Virtual MCP
project_manager
list_issuessearch_pagessend_message
CursorCursor
ChatGPTChatGPT
ClaudeClaude
CopilotCopilot

Foundation

A foundation you canhand the keys to

FIG 2.0

Patented protection

MCP traffic protected by our own patented technology

FIG 2.1MCPAPIA2AAP2+

Protocol coverage

MCP first, with upcoming protocols added as they land

FIG 2.2

Split-plane design

MCP payloads and other sensitive data never leave your network

Your data stays in.Management moves up.

Tumiki
Local Environment
Protected
Proxy MCP
Auth, audit and access control
stdio MCP
Files / Git / local databases
Audit log
Every trace stored encrypted
OIDC auth
Entra ID / Okta / Google
MCP payloads never leave your network
Prompts ✕API keys ✕PII ✕
Audit log →
HTTPS
Policy sync ✓
MCP config ✓
Credential ref ✓
← Config sync
Tumiki Control Plane
On-Premises / VPC
Private
Access control
Group × MCP permissions in one UI
MCP management
Server registry, connections, credential vault
Audit & insight
Usage, blocked calls, SIEM export
Only policies and metadata are managed here
Payload storage ✕Audit log storage ✕

FAQ

Questions we get
while you evaluate

How is this different from the security tools we already run?

It watches MCP calls, not network destinations or files. The monitored surface does not overlap with your existing tooling, so it sits alongside it.

Do prompts or internal data ever leave our network?

No. Prompts, API keys and personal data stay inside your network. The cloud plane only handles policy and metadata.

Can we keep the MCP servers we already use?

Yes. Register them in the console — nothing has to be rebuilt on the MCP server side.

Can we authenticate with our own identity provider?

Yes. OIDC is supported, so you can sign in through Entra ID, Okta or Google.

How granular do permissions get?

R/W/X permissions per tool, not just per server. Every policy change is kept in a change history.

Can audit logs feed into our own monitoring stack?

Yes. The trail is stored encrypted, with SIEM forwarding and export available.

What is the easiest way to start?

The demo on this page is the real console UI. To run it yourself, download the desktop build — no sign-up required.

Start managing MCP today

From first questions to a PoC, a dedicated team walks with you.

  • We reply within 2 business days
  • Nothing is charged at this point
  • A demo walkthrough is fine too

Exploring OEM, white-label or a partnership? Get in touch here