1
0 Comments

Launched ThornGuard for safer MCP client and server connections

I recently launched ThornGuard.

The short version is that MCP is getting real adoption, but the security layer around it still feels pretty under-built. A lot of current setups basically assume you’re fine pasting secrets into local config, pointing an AI client at a remote server, and trusting the rest of the path.

That felt fragile to me, so I built ThornGuard.

It sits between MCP clients and upstream MCP servers and adds a protection layer without requiring changes to the upstream server. The goal is to make MCP setups feel more operable once they move beyond demos and local experiments.

Right now it gives you a safer launch path for clients, inspects requests before the upstream sees them, redacts sensitive data in both directions, and gives operators audit logs, dashboard visibility, activations, rate limits, approvals, policy controls, IP allowlisting, and webhook integrations.

What I’m really curious about is whether other people here are feeling the same gap.

If you’re building with MCP right now:

  • Are you mostly using it for local/personal workflows, or for anything production-ish?

  • What are you doing today for inspection, auditability, or access control?

  • If you’re not using MCP yet, is the security/control story part of what’s holding you back?

Would genuinely love feedback from people building agent tooling, AI workflows, or MCP servers.

posted toAvatar for product ThornGuard
ThornGuard