Back to home

MCP gateway security and audit logs.

How Vordix authenticates, authorizes and audits every call your developers and agents make, in real time, on a log that is entirely yours.

What is an MCP gateway?

An MCP gateway sits between an AI client and the tools it calls. In Vordix, that boundary is where access rules, data policies and audit logging are applied. A connector provides access to a tool; the gateway checks how each caller may use it.

  1. 1. The client makes a request

    Claude, Cursor or an internal agent connects to Vordix using its own key. The client requests an operation on a connected tool.

  2. 2. Vordix checks the rules

    The gateway checks the caller and the permitted operation and resource. Requests outside the configured scope are denied.

  3. 3. The tool returns a result

    For an allowed request, Vordix calls the upstream tool and applies configured data policies before returning the result to the client.

  4. 4. The outcome is recorded

    The audit trail records the caller, operation and outcome, including denied requests. Review these records alongside configuration changes.

Why governance needs its own layer

When developers and AI agents hold raw keys to your tools, the only record of what they did belongs to someone else.

  • 01

    The AI vendor keeps its own records

    Model providers ship their own logs and connector tooling, but that leaves you trusting the vendor to keep honest and complete records about its own tools.

  • 02

    Raw keys leave no independent trace

    Hand an agent a direct API token and no one can see what it touched; the vendor’s own log becomes the only evidence you have.

  • 03

    Editable logs are not evidence

    A plain audit table that anyone with database access can silently change has no evidentiary value the day an auditor asks.

  • 04

    Regulators want traceable records

    The EU AI Act (Art. 12 / Annex IV) expects structured, per-system record-keeping, not a pile of raw application logs.

Your gateway and audit trail, on your infrastructure.

Vordix runs on your own servers, as a single deployment you control. Your AI tools talk to it, it talks to your tools, and the record of every call stays with you.

  • No Vordix-operated cloud service sits in the request path.
  • Your credentials stay encrypted, and are never handed back out.
  • Sensitive data is found and handled without leaving your network.
The tools your people and agents use
Claude Cursor VS Code Your own agents
every request
VORDIXnothing passes unchecked
  • Checks who is calling
  • Checks what they may do
  • Applies your data rules
  • Records the call
only what your rules allow
The tools it reaches on their behalf
Jira GitHub Confluence Slack Databricks

How Vordix solves it

  • 01

    One choke point for every call

    Every request is authenticated, authorized, rate-limited and logged. The REST proxy and MCP tool calls run through the same path.

  • 02

    Tamper-evident, append-only trail

    Audit rows are hash-chained; change any row and the chain breaks, so an integrity check can prove the record is intact.

  • 03

    One row per outcome, including denials

    Every allow, deny, error and rate-limit is written with who, what, when and result, plus a separate log for every configuration change.

  • 04

    The record is yours, not the vendor’s

    The audit trail lives in your own self-hosted database, independent of any AI provider.

  • 05

    Default-deny by design

    Access is allowed only when membership, enabled operation, scoped resource and admin ceiling all agree; any engine error denies rather than leaks.

  • 06

    Built for EU AI Act evidence

    Each audit row self-tags the Annex IV section it satisfies as it is written, folded into the same hash chain.

  • 07

    Regulator-ready German export Planned

    One-click, German-language PDF evidence bundles assembled for an Annex IV technical file.

See it on your own stack.

A short walkthrough on your tools, your rules, your audit log. Nothing leaves your network.

Request a demo