# Metomic > Metomic is the unified MCP gateway for enterprise AI security. It discovers and governs Shadow AI, inspects every Model Context Protocol (MCP) request in real time, and redacts sensitive data before it reaches any external model or unauthorized user. Key facts: - An MCP Gateway sits between AI agents and the tools and models they call, enforcing least-privilege access at a single control point. - Metomic inspects the content of each request, not just metadata, and can allow, redact, hold for human approval, or block it in real time. - Shadow AI is the use of AI agents, MCP servers, copilots, and browser AI tools that were never approved by security. Metomic surfaces this layer so teams can govern it rather than block it. - Metomic keeps a full audit trail of every agent action, streamed to your SIEM. - Deployment is hosted and preconfigured, with no agents on endpoints. - Metomic is SOC 2 Type II certified (AICPA). ## Product - [Platform](/platform/): Full platform overview, from data discovery to real-time enforcement - [MCP Gateway](/solution/mcp-gateway/): Inspect every agent-to-tool MCP request in real time and allow, redact, hold, or block it - [Claude Inference Hooks](/solution/claude-inference-hooks/): The AI security server behind Anthropic's Claude Inference Hooks, returning real-time DLP verdicts on Claude Enterprise prompts - [Security for AI Tools](/solution/security-for-ai-tools/): Govern AI tools and agents that touch company data - [Data Loss Prevention](/solution/data-loss-prevention/): Content-aware DLP across SaaS and AI - [Data Security Posture Management](/solution/data-security-posture-management/): Find and fix sensitive-data exposure at rest - [All Integrations](/integration/all-integrations/): Salesforce, Slack, Jira, Google Drive, ChatGPT, and more ## Resources - [What Is an MCP Gateway?](/resource-centre/what-is-an-mcp-gateway/): Definition, core capabilities, and how it differs from an API Gateway, DLP, or CASB - [What Is Agent Governance?](/resource-centre/what-is-agent-governance/): The runtime controls that decide what an AI agent can access, do, and prove - [AI Agent Governance: The Company Harness](/resource-centre/ai-agent-governance-company-harness/): Metomic founder Ben van Enckevort on governing a company whose actors outnumber its people, and on the company harness that holds the rules - [What Is AI Data in Motion?](/resource-centre/what-is-ai-data-in-motion/): Why protecting data in transit through AI requests differs from data-at-rest tooling - [MCP Gateway vs. API Gateway](/resource-centre/mcp-gateway-vs-api-gateway/): Why the two solve different problems and most teams need both - [MCP Gateway vs. Inference Hooks](/resource-centre/mcp-gateway-vs-inference-hooks/): Two deployment paths for inspecting AI data in motion, their tradeoffs, and why most teams need both - [AI Gateway vs. Secure Web Gateway](/resource-centre/ai-gateway-vs-secure-web-gateway/): Why an SWG's browser-traffic visibility doesn't cover agent-to-tool traffic over MCP - [Agent Security vs. AI Security](/resource-centre/agent-security-vs-ai-security/): Why securing the model doesn't automatically secure what it's connected to - [MCP Security: A CISO's Guide to Agent-Tool Risk](/resource-centre/mcp-security-ciso-guide/): What MCP is, where it breaks, and how to secure it - [Shadow AI: What It Is and How to Control It](/resource-centre/shadow-ai/): Definition, risks, and a governance playbook - [Resource Centre](/resource-centre/): Guides, case studies, whitepapers, and reports - [Blog](/resource-category/blog/): Research and practical guidance on AI and data security ## Company - [About Metomic](/about/): Company background and team - [Security Centre](/security-center/): Certifications, subprocessors, and security practices - [Book a demo](/book-a-demo/): See the MCP Gateway on your own stack ## Optional - [Careers](https://apply.workable.com/metomic/): Open roles - [Partners](/partners/): Partner with Metomic - [Metomic on AWS Marketplace](/metomic-on-aws-marketplace/): Procure through AWS