Skip to content

THE SECURITY LAYER FOR MCP

Let AI work.
On your terms.

Give your team’s AI assistants access to business tools—with precise limits on the records they read, the data they return, and the actions they take. Nectry enforces those limits outside the model.

Exactly the authority the task requires.

01 FINE-GRAINED ACCESS CONTROL

Go beyond
access to an app.
Define the boundary.

Decide more than whether an agent can use a tool. Define which records it can read, which fields it can return, and who it can send data to. Keep useful access within the boundaries your team sets.

THIS AGENTcanREADonlyASSIGNED RECORDS

Explore the policy model. Available scopes depend on the integration and deployment; we’ll map your requirements in a demo.

N / PERMISSIONSIllustrative policy model
Which data can they reach?

Permission to read has a boundary.

Limit which records and response fields can reach the model.

DEFINED SCOPERead customer records

Only records assigned to the agent’s team

Assigned recordsWithin record scope
✓ Allowed
Another team’s recordsOutside record scope
× Blocked
Explicit scope. A traceable decision.
N / CUSTOM TOOLSIllustrative tool composition
01
Read scoped data

Only the records the task needs

Scoped
02
Combine and transform

Express the logic between tool calls

Defined
03
Apply tool constraints

Keep inputs and actions within scope

Policy
04
Execute the permitted action

Within the workflow’s authority

Bounded
MULTIPLE OPERATIONS ONE GOVERNED MCP TOOL

02 CUSTOM TOOLS & WORKFLOWS

Build tools for the task.
Bound the authority.

Turn a workflow across your systems into a purpose-specific MCP tool. Define its inputs, operations, and permissions together, so an agent gets the capability the task needs with clear limits on what it can do.

  • Combine operations across your connected systems.
  • Constrain the inputs and data each tool can use.
  • Expose a reusable capability through MCP.

ILLUSTRATIVE TOOLLog a call outcome.Update the call notes and next step, with other CRM fields outside the tool’s scope.

Explore your workflow with us →

03 DETERMINISTIC ENFORCEMENT

Stop unauthorized actions.
Before they reach
your systems.

Give agents useful access without handing over unrestricted authority. Nectry checks each governed tool call against your policy and blocks out-of-scope actions before execution—even when the model asks for them.

THE AGENT REQUESTSRead. Write. Delete.

A model’s request is not authorization.

NECTRY ENFORCESYour policy has the final say.

Identity · data · action · context

Explicit rules. Checked before execution.
✓ WITHIN SCOPEWork moves forward.
× OUTSIDE SCOPEExecution stops here.
IN SCOPEOUT OF SCOPEEXECUTEBLOCKED

Keep sensitive data in bounds.Limit which resources an agent can reach.

Protect consequential actions.Constrain writes, deletions, and other changes.

Keep authority outside the model.A generated request cannot grant itself permission.

Illustrative request path

Enforcement applies to calls routed through Nectry’s governed connection.

Understand the architecture ↗

04 FORMAL METHODS, PRACTICAL CONTROL

Built to reason
about behavior.
Before it runs.

NectryCore uses a restricted language that makes supported security properties decidable. The compiler can check what a program may access, which tools it may invoke, and where authorization is required.

Formal verification applies to supported properties of compiled NectryCore programs. MCP runtime checks enforce requests on the governed path; they do not prove the entire behavior of an external agent.

NECTRYCORE / VERIFICATIONDocumented property classes
01

Information flow

What data can reach which output

02

Capability boundaries

Which systems may be contacted

03

Tool-use scope

Which calls and argument shapes are permitted

04

Workflow integrity

Where human authorization is required

Two decades of MIT CSAIL research.

Chief Scientist Adam Chlipala

05 FITS THE WAY YOUR TEAM WORKS

Your AI stack.
A shared control layer.

Keep the assistant experience familiar. Bring supported tools and workflows through Nectry, with an integration and deployment approach matched to your environment.

AT THE DESK

MCP-connected assistants

Expose your connected tools and defined workflows to compatible AI clients through MCP.

ACROSS YOUR SYSTEMS

Business tools and data

Bring supported integrations together and define the operations your workflows need.

IN YOUR ENVIRONMENT

Enterprise deployment

Discuss Docker-based deployment, local-model requirements, and the governance controls your organization needs.

ENTERPRISE EVALUATION

Advanced governance is evolving with enterprise partners. We’ll distinguish available capabilities from planned controls when mapping your requirements.

MAKE ROOM FOR AI. KEEP AUTHORITY WITH YOUR TEAM.

See Nectry
in your environment.

Bring one task your team wants to delegate. See the tools and permissions it would need.

Book a Demo