Show HN: cMCP, deny an AI agent's tool call and get a signed receipt
cMCP is a new security runtime designed to enforce tool-call policies for AI agents within a hardware-based Trusted Execution Environment (TEE). It aims to prevent unauthorized data access by intercepting and validating agent actions against a secure policy engine.
Why it matters
As AI agents gain access to sensitive enterprise tools, secure governance and verifiable audit trails are becoming critical for corporate compliance and data security.
Enforce MCP tool policy inside a TEE, where the agent it governs cannot reach it
Quick Start · Architecture · Configuration · CLI · Changelog
Developer Preview - launched at the Confidential Computing Summit, June 23 2026. May have breaking changes before v1.0. See STATUS.md for exactly what ships today versus what is on the roadmap.
cMCP (Confidential MCP Runtime) is the secure, confidential way to run MCP: an open-source gateway that enforces MCP tool-call policy inside a hardware Trusted Execution Environment (TEE). Every tool call is intercepted, evaluated against a Cedar policy bundle, and enforced where the process it governs cannot reach it. Each session produces a signed TRACE Claim that a verifier checks without trusting the operator, hardware-attested when the gateway runs in a TEE and signed-only in software mode. If you are looking for a secure version of MCP, this is the AgenTrust runtime for it.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in