Back to home
MCP gateway, AI security and access control: a glossary.
Vordix sits in a corner of the industry that invented a lot of vocabulary. This page explains all of it, in the order the words tend to come up rather than alphabetically, so the ones that explain each other stay together.
How AI tools connect to yours
- MCP Model Context Protocol
- The open standard AI tools use to call software outside themselves. An assistant that speaks MCP can read a Jira ticket or open a pull request without anyone writing custom glue for it. Claude, Claude Code, Cursor and VS Code all speak it.
- MCP client
- The AI-side program that makes those calls — your chat tool, your editor, your own agent. It connects to one governed Vordix endpoint instead of to a dozen separate tool servers.
- MCP gateway
- A single door that every request has to pass through. Because nothing routes around it, the gateway is the one place where a rule can be applied to every call, and the one place where every call can be written down. Learn more
- REST API
- The ordinary web interface, spoken over plain HTTP. Vordix offers one alongside MCP so scripts, CI jobs and older systems that will never speak MCP get exactly the same controls.
- Connector
- The piece that knows how to talk to one specific tool — what Jira calls an issue, what GitHub calls a pull request, and which of those actions read versus write.
Who is allowed to do what
- Authentication
- Establishing who is calling. Every request to Vordix carries a key tied to one identity, so there is no such thing as an anonymous call.
- Operation
- One specific action on a tool — read an issue, search a project, delete a page. Vordix governs at this level, so "can use Jira" is never the whole answer. Learn more
- Scoping
- Narrowing an operation to particular resources: this project, these repositories, that Slack channel. Without it, permission to read one issue is permission to read every issue. Learn more
- Least privilege
- The principle that every identity gets the minimum access its job requires, and nothing kept "just in case". It is what keeps a leaked key from becoming a breach.
- Ceiling
- The organisation-wide maximum an administrator sets. Each project then selects from inside that ceiling and can never exceed it, so a project lead cannot widen their own access. Learn more
- API key
- The secret a caller presents to prove its identity. Vordix issues one per identity, shows it exactly once, and stores only a hash — so even Vordix cannot hand your key back to anyone, including you.
Protecting the data that comes back
- PII Personally identifiable information
- Anything that identifies a real person: a name, an email address, a phone number, sometimes a user ID. It is the category most likely to travel inside an ordinary tool response without anyone intending it to. Learn more
- Masking
- Replacing a sensitive value with a stand-in that keeps the answer usable — a real name becoming user_4471. The agent can still tell two people apart without learning who either of them is. Learn more
- Redaction
- Removing a value altogether rather than substituting it. Used where even a placeholder would say too much, or where the field simply is not needed for the task. Learn more
- Response field
- One named value inside a tool’s answer — the assignee on an issue, the author of a page. Governing at this level is what makes "read this project, but never show email addresses" expressible. Learn more
- Prompt injection
- Text planted in ordinary data — a ticket description, a code comment — written to be read by a model as an instruction rather than as content. Vordix treats tool output as data, never as commands, so injected text cannot widen what an agent is allowed to do.
Running it, and proving what happened
- Self-hosted
- Software that runs on hardware you control, rather than as a service someone else operates. Your data, your credentials and your logs stay inside your own network, and no vendor sits in the request path. Learn more
- Docker Compose
- The standard way to start a set of connected services with one command. It is how Vordix is deployed, which is why installing it is an afternoon rather than a project. Learn more
- Audit log
- The permanent record of who called what, when, and whether it was allowed. Denials are recorded as carefully as successes, because the attempts that failed are usually the interesting ones. Learn more
- Rate limiting
- Capping how many requests an identity may make in a given window. It contains both the runaway agent stuck in a loop and the caller working through your data faster than any human would. Learn more
See it on your own stack.
A short walkthrough on your tools, your rules, your audit log. Nothing leaves your network.