MCP Security

Discover, govern, and protect every MCP server

Noma secures MCP servers across the full lifecycle: discovery, supply chain assessment, access governance, and runtime protection.

How Noma MCP server security works

Noma enables organizations to discover, govern, test, and protect AI and agents across the enterprise.

01

MCP discovery

Noma discovers every MCP server across your organization: which servers are installed, which agents they connect to, which tools they expose, and how they're configured. Shadow MCP servers that employees installed without approval are surfaced alongside sanctioned ones, so security teams see the full picture.

Diagram showing HR Tickets creation with high priority and connection to a toolset of four integrated tools.
02

Supply chain risk assessment

Each MCP server is assessed for AI-specific supply chain risks that code scanners don't cover: unpinned versions that auto-download the latest package on every invocation (rug pull exposure), excessive tool permissions (root or sudo access), low-trust packages with minimal community adoption, known vulnerabilities, and secrets exposure. Noma flags toxic combinations where multiple risks compound, like a low-health package with unpinned versions connected to production systems.

AWS MCP registry showing tools, user groups, risks, capabilities, and actions for pricing and access keys.
03

MCP registry and access governance

Define which MCP servers are approved, which require review, and which are blocked. Policies are scoped by server, by individual tool, and by user group. An approved MCP server doesn't mean every tool it exposes is approved: Noma lets you allow the server but disable specific tools for certain agents or users. When someone connects to an unapproved server, it gets flagged or blocked before any data flows.

Learn More
Diagram shows AWS access key creation approved and deletion blocked by Noma Access Control for invoice processor setup.
04

Runtime detection of tool poisoning

MCP-specific attacks happen at runtime, inside tool responses that static scanners never see. A compromised server embeds instructions in its responses that hijack agent behavior, redirect tool calls, or exfiltrate data through the agent's own actions. Noma monitors tool call responses in real time and detects embedded prompt injection, exfiltration patterns, and cross-server shadowing before the agent acts on them.

Learn More

Noma research: ContextCrush

Noma's research team discovered ContextCrush, a vulnerability in Context7, one of the most widely used MCP servers (50,000+ GitHub stars, 8M+ npm downloads). Anyone could register a library on the Context7 platform and set "Custom Rules" that were served verbatim to every developer querying that library. The full attack chain, from registration to credential exfiltration, took minutes.

Dashboard showing four file sources with user names, permissions, and file status like Read Only, Delete, Update.
BUILT FOR THE ENTERPRISE

Security that adapts to your environment

Comprehensive coverage

Cover endpoint AI agents, SaaS agents, and homegrown AI from one platform, and ingest data across 80+ connectors to data platforms, EDR, model registries, version control, and more.

Open enforcement

Decouple governance from any single control point and enforce policy through AI gateways, MCP gateways, agent hooks, agent SDKs, and direct APIs, using the infrastructure already in the environment. Security should not force architecture decisions, it should adapt to them.

Multiple deployment options

Support for both on-prem and SaaS deployments ensuring your unique requirements are met so that no model, training data or security events leave your environment.