Compare ยท MCP gateways

PrivacyFence and other MCP gateways: different jobs.

Most MCP gateways sit between many AI agents and many MCP servers, and give a platform team one place for sign-in, access rules, rate limits and logs. PrivacyFence is an MCP gateway with a narrower job: it governs its own connectors to business systems, and puts the person whose data it is in front of each sensitive read and write. The FAQ has the short version.

Checked against each project's documentation on 29 September 2026. The sources are at the end of this page.

Two jobs

Routing tool traffic, or deciding on each request.

A general MCP gateway

Puts any MCP server behind one endpoint. It handles sign-in and roles, chooses which tools each team sees, limits rates, and sends logs to your monitoring. Several also scan traffic for personal data or secrets. It treats a tool as a name and a set of arguments, so it works with any server.

PrivacyFence

Brings its own connectors for Gmail, Drive, Slack, Salesforce, Jira, Confluence and more, and knows what each operation means. That is what lets it show a person the actual email, document or change before it happens. It is not a proxy for arbitrary MCP tools.

Side by side

Typical MCP gateway and PrivacyFence.

Typical MCP gatewayPrivacyFence
Which toolsAny MCP server you registerIts own eleven connectors and their tools, each with a fixed gate
Built forPlatform and security teams running many agents and serversThe person whose mailbox or drive it is, with admins setting policy in an organization deployment
Sign-inOAuth, SSO and role-based accessA local token and companion-app sign-in on a personal install; your OpenID Connect identity provider and OAuth 2.1 in an organization deployment
Human approval of a single callRare. Where offered, an approver role reviews the tool name and its argumentsEvery gated call no always-allow rule covers, decided by the user on a card that shows the content or change in business terms
Reads reviewed before releaseNot typical: a result passes through, possibly scannedYes: the result is held, previewed, and released only on approval
Personal dataSeveral redact or mask it automatically, for example with Microsoft Presidio or pattern pluginsA local pattern check that forces a review and a second confirmation, plus per-category redaction and blocking
Where it runsContainers or Kubernetes you run, or a hosted serviceAn installer on each computer, or one Linux server
AuditCentral logs and traces, often exported to a SIEMA chained per-person log of every decision; organization mode forwards it to syslog or an HTTP endpoint

Examples

Gateways we looked at.

What each project's documentation describes. "Not described" means we did not find it there, not that it cannot be built.

GatewayModelPersonal dataHuman approval of calls
Docker MCP GatewayOpen source; runs MCP servers in isolated containers, locally or self-hostedNot describedNot described
IBM ContextForgeOpen source, self-hosted; auth, roles, rate limits and a plugin systemA PII filter plugin that detects and masks itNot described
Microsoft MCP GatewayOpen source (MIT), on Kubernetes; Entra ID sign-in, roles, routingNot describedNot described
Lasso MCP GatewayOpen source (MIT), self-hosted; plugins and audit loggingPresidio-based detection and secret maskingNot described
agentgatewayOpen source, Agentic AI Foundation (Linux Foundation), self-hosted; policy-based access and tool scopingPII redactionNot described
Cloudflare MCP server portalsHosted by Cloudflare; sign-in, tool allowlists, logsData loss prevention rulesNot described
TrueFoundry AI GatewayCommercialNot describedYes: gated calls are held for designated approvers, who see the tool, requester and arguments

Which one

Often both, for different traffic.

A general gateway fits when

  • you run many internal MCP servers and need one place to route, authenticate and rate-limit them;
  • automatic scanning and central logs are the controls you need;
  • a platform team, not each user, owns the decisions.

PrivacyFence fits when

  • assistants work with personal mailboxes, drives, chats and customer records;
  • a person should see the content and approve before it is released or changed;
  • credentials and the record of decisions should stay on computers you control.

PrivacyFence governs only its own connectors, so tools from your other MCP servers keep going through whatever gateway you use for them.

Sources

Where the comparison comes from.

Spotted something out of date? Write to [email protected] and it will be corrected.

Next

See a request go through the gate.

Follow one read and one write from the assistant to your decision, or compare PrivacyFence with Claude's own connectors.