Back to the registry
Agent passport

MCP Audit & Compliance Gateway

WeldonWeb · Operations & Productivity

Azure ApplicationsNo attestation published

Certification per Microsoft Marketplace.

MCP ComplianceAI Agent AuditAI governance
Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 9 captures on record

User ratingNot rated0 reviews on the listing
Runs onAzure ApplicationsAzure application
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

MCP Audit & Compliance Gateway

As AI agents spread across your organisation, every tool call they make is a potential compliance gap. The MCP Audit & Compliance Gateway gives security, platform, and compliance teams full visibility and control over every Model Context Protocol (MCP) interaction, without modifying a line of agent code.

Show the rest of the publisher’s description (19 more lines)

How it works

Deploy the gateway into your own Azure subscription as a managed application. Point your agents at the gateway URL instead of your MCP servers. It intercepts every tool call, resolves the agent's identity from Microsoft Entra ID JWT claims (UPN, appid, OID), evaluates your policy, redacts sensitive data, forwards permitted requests, and writes a structured audit record of every decision.

Built for compliance, not just connectivity

A generic API gateway authenticates and rate-limits. This is built for regulated environments: boundary redaction of PAN and PII, a stable deny-reason taxonomy, tamper-evident audit, and per-identity, time-windowed policy. The audit evidence regulators ask for, ready before they ask.

Key capabilities

  • Structured, tamper-evident audit: Every call logged with agent identity, tool, masked arguments and response, decision, deny-reason code, and latency, each event SHA-256 hash-chained so any gap or rewrite is detectable. Streams to Azure Log Analytics or any OpenTelemetry stack.
  • Sensitive-data redaction: Built-in detectors for PAN (Luhn-validated), email, UK NIN, SSN, IPv4/IPv6, phone, and JWT, plus credentials and custom patterns, applied before truncation so no partial value leaks. One line of config meets PCI DSS Requirement 3.4.
  • Per-identity policy: Allow and deny rules per tool and identity with wildcards, regex argument scanning to block dangerous payloads, sliding-window rate limits, and time-windowed access.
  • Advanced controls: Claims-based authorization, strict deny-by-default allow-listing, tool-definition pinning, a human-approval workflow, inline DLP, and shadow mode.
  • Multi-server routing: Front multiple MCP servers through one endpoint, each with its own path prefix and policy. Routes hot-reload in 30 seconds, no redeployment.
  • Zero agent changes: Agents only need their MCP server URL updated. No SDK or code changes.

Deployment

Deploys entirely into your Azure subscription as an Azure Managed Application. Container App, Log Analytics workspace, and Managed Identity are provisioned automatically. Your data never leaves your environment, and the publisher has no access to it.

Intended audience

Security, platform, and compliance teams deploying AI agents in regulated or enterprise environments, that need an audit trail without waiting for MCP servers to add their own.

Requirements

  • Azure subscription with Container Apps and Log Analytics in your region
  • MCP servers reachable over HTTPS or within your Azure virtual network
  • Microsoft Entra ID tenant for JWT-based agent identity resolution

Preview

2 images
MCP Audit & Compliance Gateway preview 1MCP Audit & Compliance Gateway preview 2

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment

CompanyWeldon WebAutomated

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource

Publisher resources

3 links
Supportweldonweb.co.ukSource
Mcp Audit Information Pagewww.weldonweb.co.ukSource
Live tracking of MCP server requestswww.youtube.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Azure application
https://weldonweb.co.uk/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.