One MCP proxy for org-approved tools. Policy on the tool call.
The Connector exposes the MCP servers your org approves, decides every tools/call before it reaches the server, and ties each one to a person, a device, and a session. Works with any standard MCP server, stdio or HTTP, no per-server integration to write.
Catalog & approvals
Request an approved MCP and it's installed, proxied, and scoped.
The catalog is the list of what your org trusts. Approval decides who gets it. The Lander delivers it.
Commercial and internal servers
Any standard MCP server, hosted by us or by you. No per-server integration to write.
Approval gates
Who may request a server, tool, or skill, by access group. Requests land in a queue, not a ticket.
Pushed by the Lander
Once approved, it's installed and proxied by default on every device that should have it.
The Lander →MCP Servers
org-approved · 42 devices
Servers your organization has configured. Install the ones you want on your client.
GitHub
http
Google Drive
http
Notion
http
Slack
http
Snowflake
http
Linear
http
Confluence
http
Postgres (read replica)
stdio
Tool-call policy
Govern the tool call.
Every tools/call is decided before it reaches the server. Allow the tools a person or team needs, filter the rest out of tools/list so the model never sees them, and start in report-only until you've seen what would change.
github.delete_repo
repo: payments
- Rule
- allowed_tools
- Person
- j.doe@acme
- Device
- MBP-2291 verified
- Agent
- Claude Code
- Session
- 8f3a…
- Tokens
- 1,204 / 88
Recent
tools/list filtering
The model never learns a disallowed tool exists. What it can't see, it can't be talked into calling.
Allowed tools and params
Per catalog entry: which tools, with which arguments. The same rules apply on stdio and HTTP.
Report-only first, then enforce
Per kind, per device, or fleet-wide. Unset fails safe to report-only, so nothing breaks before you've seen what would change.
Identity & audit
Every call carries a person. Every event is priced and logged.
The Connector holds the grant, so no token lives in a local config file. Each event records the session, person, device, agent, tool, result, and tokens, and ships to the pipeline you already run.
The Lander holds the grant
The call runs as the delegated user. No token is copied into a local config file.
Sign in once
Enterprise SSO, Auth0, or local accounts. From then on, every call carries a person and a verified device.
No standing credentials
Short-lived, scoped, and rotated by the Connector. The laptop stops being where secrets live.
Every event, fully attributed
Session, person, device, agent, tool, result, and tokens on each record, across every client.
Ships with your pipeline
Splunk, Datadog, Databricks, or any OpenTelemetry endpoint. No new console to watch.
Cost, defaults, and caps
Model defaults and token caps by team. Tokens priced from public pricing datasets, attributed to the session.
Deployment
Runs in your cloud. We never see your data.
The control plane, the catalog, the policy engine, and the audit log run inside your infrastructure, on Kubernetes or as a standalone bundle.
Kubernetes
Deploy into the cluster you already run. Updates ship as new images; the data never leaves.
Standalone bundle
The control plane and the services it needs, on a host you own.
FAQ
Frequently asked questions
Get started
Start free. Grow into the fleet.
One developer, free and hosted, on a personal or business account. Teams and enterprises get the full platform and a team from us that works alongside yours to tailor policies, MCPs, and skills to your use case.
Personal
The Lander on your own machine, hosted by us. Inventory and native session telemetry for one developer. Sign up with a personal or a business account.
- 1 device, 1 user
- Inventory and session telemetry
- Personal or business account
Team & Enterprise
The Lander on every device plus the Connector, on our SaaS or in your cloud. We don't hand over a license and leave: we work embedded with your team to tailor policies, MCPs, and skills to your use case, and to bring your engineers up to speed.
- Every device, every user
- Our SaaS, your Kubernetes, or your MDM
- Embedded with your team, tailored to your use case