# Security | SealGate AI Agent Data Security

How SealGate secures agentic AI: zero-knowledge encryption at rest (AES-256-GCM, HKDF-SHA256), deterministic CEL policy enforcement, lethal-trifecta protection, per-user isolation, full audit trails with plan-based retention up to 365 days, and supply-chain pinning. Deploy as SaaS, VPC, self-hosted, or air-gapped.

Source: https://sealgate.ai/security

---

[Docs](https://sealgate.ai/docs/) [Product](https://sealgate.ai/product) By role

[Security teams See every agent, prove control](https://sealgate.ai/product#for-security-leaders) [IT & platform Kill shadow MCP, clear the ticket queue](https://sealgate.ai/product#for-it-teams) [Engineering teams Keep your agents, skip the blocks](https://sealgate.ai/product#for-developers) [Compliance & enterprise Govern to the standards you answer to](https://sealgate.ai/product#for-compliance)

By feature

[Discovery Find and quarantine shadow MCP](https://sealgate.ai/product#discovery) [MCP gateway One enforcement point for every call](https://sealgate.ai/product#mcp-gateway) [Supply chain security Pin tools, catch silent changes](https://sealgate.ai/product#supply-chain) [Detection and Response Stop data leaving in real time](https://sealgate.ai/product#detection-response) [Risk scoring Score every session Low to High](https://sealgate.ai/product#risk-scoring) [Agent inventory & records One control plane for the fleet](https://sealgate.ai/product#system-of-actions) [Audit-ready Forensic trail for every action](https://sealgate.ai/product#audit-ready) [Chrome extension Track ChatGPT and Claude tool calls](https://sealgate.ai/chrome) [Self-hosting Run it in your own VPC or air-gapped](https://sealgate.ai/self-hosting)

[Developers](https://sealgate.ai/dev) AI Data Leaks [Cursor/VSCode Data Leak](https://www.linkedin.com/posts/eito-miyamura-157305121_cursor-github-mcp-can-lead-to-private-keys-activity-7383899320326160384-tMCX) [ChatGPT Gmail/Outlook Data Leak](https://www.linkedin.com/feed/update/urn:li:activity:7372306174253256704/) [Perplexity Comet Bankruptcy](https://www.linkedin.com/feed/update/urn:li:activity:7386434090901671936/) [Postgres Data Exfiltration](https://www.youtube.com/watch?v=cqvC7hGXy8Y) [Claude Desktop Data Leak](https://gatlingx.notion.site/Calendar-only-exfiltration-23e89dcc2f088029ade9e81e7d1c275f) [Claude Code Outlook Data Leak](https://www.youtube.com/watch?v=Wldae7-SN5E) [Confluence Insider Threat](https://www.youtube.com/watch?v=SpXUPto90IA)

[Blog](https://sealgate.ai/blog/) [Pricing](https://sealgate.ai/pricing) [Book a demo](https://cal.com/eito80/demo) [Start Free](https://dashboard.sealgate.ai/?utm_source=sealgate.ai&utm_campaign=seo-site&utm_content=security)

[Docs](https://sealgate.ai/docs/) [Product](https://sealgate.ai/product) [Developers](https://sealgate.ai/dev) [Pricing](https://sealgate.ai/pricing) [Self-hosting](https://sealgate.ai/self-hosting) AI Data Leaks [Cursor/VSCode Data Leak](https://www.linkedin.com/posts/eito-miyamura-157305121_cursor-github-mcp-can-lead-to-private-keys-activity-7383899320326160384-tMCX) [ChatGPT Gmail/Outlook Data Leak](https://www.linkedin.com/feed/update/urn:li:activity:7372306174253256704/) [Perplexity Comet Bankruptcy](https://www.linkedin.com/feed/update/urn:li:activity:7386434090901671936/) [Postgres Data Exfiltration](https://www.youtube.com/watch?v=cqvC7hGXy8Y) [Claude Desktop Data Leak](https://gatlingx.notion.site/Calendar-only-exfiltration-23e89dcc2f088029ade9e81e7d1c275f) [Claude Code Outlook Data Leak](https://www.youtube.com/watch?v=Wldae7-SN5E) [Confluence Insider Threat](https://www.youtube.com/watch?v=SpXUPto90IA)

[Blog](https://sealgate.ai/blog/) [Book a demo](https://cal.com/eito80/demo)

Security

# Security you can verify

Auth, RBAC, and data security for agentic AI. Deterministic controls, not probabilistic guardrails. Every claim links to the docs, so you can check it yourself.

## Shadow MCP discovery

Find unapproved tool servers, quarantine them by default.

- A background daemon on every managed device finds MCP servers as they come and go
- New servers are quarantined until an admin approves them
- Closes the gap between an agent appearing and your team noticing
- Layers onto existing shadow AI tooling such as Island Browser [MCP quarantine ↗](https://sealgate.ai/docs/admin-guide/mcp-quarantine/)

Admin No visibility Full visibility SealGate ? notion ? github ? web-scraper ? shadow-tool ? gdrive ? slack

## Zero-knowledge encryption at rest

Your key never reaches our servers.

- AES-256, encrypted at rest
- Key derived from a secret only you hold
- We store a hash, never the key
- A DB breach leaks only unreadable ciphertext [Read the security model ↗](https://sealgate.ai/docs/security/self-serve-security/)

GITHUB_TOKEN SLACK_TOKEN AWS_SECRET_KEY $SEALGATE$1$a3B... $SEALGATE$1$k7P... $SEALGATE$1$mN2... Personal Encryption Key SealGate Databases $SEALGATE$1$a3B... $SEALGATE$1$k7P... $SEALGATE$1$mN2... Your Device SealGate cannot read encrypted credentials

## Lethal-trifecta protection

Three risks at once, and we pause it.

- Private data access
- Untrusted content in the session
- A channel to send data out
- All three present: a human approves before anything leaves [The lethal trifecta ↗](https://sealgate.ai/docs/ai-security-threats/lethal-trifecta/)

The AI leaked sensitive data ! SealGate blocked the leak Your AI Agent Attacker Malicious Email with jailbreak instructions Malicious Email with jailbreak instructions

## Full audit trail, streamed to your SIEM

Every tool call logged, streamed to your SIEM.

- Splunk or any SIEM endpoint
- Metadata and parameters logged
- Raw files and conversations never stored
- Retention set by plan, configurable up to 365 days [SIEM integration ↗](https://sealgate.ai/docs/enterprise/siem-integration/)

Your Infrastructure (VPC / On-Prem) SealGate Gateway MCP MCP MCP SIEM CEF:0|tool_call|read_file|5|ok CEF:0|security|trifecta_flag|8|block CEF:0|tool_call|send_msg|5|ok CEF:0|admin|config_change|3

## Compromised connectors, severed on report

A poisoned connector gets cut, fast.

- Every connector runs through the gateway
- A reported compromise severs that route
- Every other connector keeps working [Dependency pinning ↗](https://sealgate.ai/docs/security/mcp-dependency-pinning/)

AI agent SealGate Gateway MCP servers Attacker An attacker compromises one MCP server Blocked the moment the compromise is reported

Also built in

### Deterministic policy enforcement

Rules in a CEL engine, not a probabilistic guardrail.

- Every tool tagged PUBLIC, PRIVATE, or SECRET
- One-way lattice: SECRET never flows down to PUBLIC [How enforcement works ↗](https://sealgate.ai/docs/ai-security-threats/)

### Per-user isolation

One isolated gateway per user.

- Its own connector processes
- No shared state between users

## Deploy where your policy requires

SaaS VPC Self-hosted Air-gapped

SaaS, your own VPC, self-hosted, or fully air-gapped. Self-hosted means SealGate never processes or accesses your data.

## Want the deep dive with your security team?

Book a walkthrough of the threat model, controls, and deployment options, or read the full security documentation.

[Book a demo](https://cal.com/eito80/demo) [Read the security docs](https://sealgate.ai/docs/security/)

### Contact Us

SealGate (GPU-EVM LTD)

3rd Floor, 86-90 Paul Street

London EC2A 4NE

Email: hello@sealgate.ai

### Legal

[Terms of Service](https://sealgate.ai/terms-of-service) [Privacy Policy](https://sealgate.ai/privacy-policy) [Subprocessors](https://sealgate.ai/subprocessors) [Delete your account](https://sealgate.ai/account-deletion) [Data Processing Addendum](https://sealgate.ai/dpa)

### Quick Links

[Home](https://sealgate.ai/) [Product](https://sealgate.ai/product) [Pricing](https://sealgate.ai/pricing) [For developers](https://sealgate.ai/dev) [Self-hosting](https://sealgate.ai/self-hosting) [Chrome extension](https://sealgate.ai/chrome) [Security](https://sealgate.ai/security) [Comparison](https://sealgate.ai/comparison) [For your team](https://sealgate.ai/for) [About](https://sealgate.ai/about) [Contact](https://sealgate.ai/contact) [Brand](https://sealgate.ai/brand) [Press](https://sealgate.ai/press) [Docs](https://sealgate.ai/docs/) [Developer docs](https://sealgate.ai/docs/developers) [Guides](https://sealgate.ai/guides/) [MCP gateway guide](https://sealgate.ai/guides/mcp-gateway) [Blog](https://sealgate.ai/blog/)

### Connect

[Connect AI to messaging](https://sealgate.ai/connect) [WhatsApp](https://sealgate.ai/connect/whatsapp) [iMessage](https://sealgate.ai/connect/imessage) [Telegram](https://sealgate.ai/connect/telegram) [LinkedIn DMs](https://sealgate.ai/connect/linkedin) [Signal](https://sealgate.ai/connect/signal) [Instagram DMs](https://sealgate.ai/connect/instagram) [Messenger](https://sealgate.ai/connect/messenger) [X DMs](https://sealgate.ai/connect/x) [Discord DMs](https://sealgate.ai/connect/discord) [LINE](https://sealgate.ai/connect/line) [Beeper](https://sealgate.ai/beeper)

### Follow Us
