Same Governance, Different Boundary
Hybrid and self-hosted modes differ by trust boundary, not by governance intent.
Why it mattersTeams can reason about deployment without relearning the control model.
Same Governance Kit
Identity, policy, credentials, sessions, and audit remain the core kit.
Why it mattersThe same primitives should govern agent access wherever the gateway runs.
Hybrid Runtime Customer-Side
Managed admin and registry metadata can sit apart from the customer-side data plane.
Why it mattersHybrid mode can keep private payloads inside the customer boundary while still enabling managed coordination.
Private Traffic Stays Inside
Private servers and connector paths stay inside the customer runtime boundary.
Why it mattersA credible gateway story does not require exposing private MCP or API endpoints publicly.
Cached Policy During Bounded Outage
Cached policy can keep enforcement bounded until an expiry limit.
Why it mattersCustomers need clear behavior when connectivity is degraded: enforce, expire, and fail closed.
Self-Hosted Everything Inside
In self-hosted mode, control plane, data plane, registry, policy, and audit all live inside the customer boundary.
Why it mattersSome customers need operational ownership more than managed convenience.
Customer-Owned Substrate
Self-hosted deployment can attach to customer-owned Postgres, cache, IdP, secrets, and SIEM systems.
Why it mattersEnterprise adoption often depends on fitting into existing platform responsibilities.
No Outbound Runtime Dependency
Normal operation can stay local, with telemetry and export under customer control.
Why it mattersTrust-boundary decisions are often about runtime dependency, not only data location.
The Call Still Gets Governed
Calls still authenticate, evaluate policy, broker credentials, route privately, and emit audit evidence.
Why it mattersDeployment mode should not weaken the runtime governance path.
API Adapter Stays Bounded
The adapter still exposes selected operations through local checks and upstream status receipts.
Why it mattersAPI-to-MCP conversion remains bounded even when the gateway is deployed differently.
Sessions And Revocation Match
Session ID, affinity, drain, revoke, and audit behavior should match across modes.
Why it mattersOperators need predictable controls when they move from pilot to production.
Choose By Trust Boundary
The deployment decision starts with the customer boundary map.
Why it mattersHybrid and self-hosted are choices about ownership, dependency, and risk appetite.
Deployment model
Prove governed MCP inside your trust boundary
We are looking for teams who want to prove governed MCP inside their real trust boundary.
The first pilot should choose the boundary deliberately: hybrid where managed coordination helps, self-hosted where customer ownership is required. Then connect one server, run one policy test, and inspect one audit proof.
The goal is not to debate deployment in abstract. It is to test the boundary with a real workflow.
Discuss your deployment