# MCP gateways compared: MintMCP, Cerbos, Datawiza and Lutril

> What an MCP gateway does, which products enforce policy on AI agent tool calls, and how MintMCP, Cerbos, Datawiza and Lutril differ on agent identity, audit, kill switch, DLP, human approvals and whether they also govern the employees behind the agents.

Source: https://www.lutril.com/fr/compare/mcp-gateways
Dernière relecture: 2026-09-02

---

## Réponse courte

The best MCP gateway to enforce policy on AI agent tool calls depends on what else you need governed. MintMCP is a dedicated gateway with programmable middleware, signed append-only audit records and an org-wide kill switch, and stops at MCP tool entitlements. Cerbos is an open-source authorization decision point that a gateway calls; it does not proxy traffic itself. Datawiza is an inline proxy with credential brokering for agents and legacy apps, with human approval routing. Lutril is an MCP proxy inside an access governance platform: every agent has an owner, every call is checked against the same role-based policy used for employees, prompts pass through DLP, calls land in a WORM log, one kill switch pauses any agent, and the same product runs access reviews, onboarding and offboarding for the humans who own those agents, with approvals in Slack, Teams or the app UI.

## D'où part chaque produit

**MintMCP.** MCP gateway and AI agent infrastructure: give your team AI everywhere while staying in control. A gateway that makes 10,000+ MCP servers enterprise-ready with hosted connectors, plus Agent Monitor for coding agents. Founded by early Google Brain members, backed by Coatue and angels including Andrej Karpathy and Jeff Dean; launched publicly in February 2026. SOC 2 Type II, cloud or self-hosted.

**Cerbos.** Authorize every identity, govern every action: an authorization management platform with an Apache-2.0 open-source policy decision point, Cerbos Hub as the managed control plane and Cerbos Synapse for identity enrichment. London, founded 2021, $11M raised. Integrates with gateways such as agentgateway through Envoy ext_authz to decide on each tool call.

**Datawiza.** Secure AI agents and critical apps with zero-trust, identity-aware runtime enforcement: an Access Proxy for legacy and on-prem applications and an Agent Gateway that sits between agents and the tools, APIs, MCP servers and SaaS systems they reach, brokering credentials and applying policy before tool calls. Campbell, California, founded 2021, Microsoft security partner.

**Lutril.** The MCP proxy is one part of an access governance platform for employees and AI agents. Agents are registered with an owner and scopes, every call passes through role-based policy, prompt DLP and a WORM log, one kill switch pauses any agent, and the same product runs shadow AI discovery, access reviews, onboarding and offboarding, with approvals in Slack, Teams and the app UI. Hosted in France.

## Capacité par capacité

| Capacité | MintMCP | Cerbos | Datawiza | Lutril |
| --- | --- | --- | --- | --- |
| Acts as an MCP gateway between agents and tool servers | Oui: Sits between AI clients and MCP servers, handling authentication [2] | Non proposé: A decision point the gateway calls; Cerbos states it is not the gateway [15] | Oui: Reverse proxy between MCP clients and servers, no server code changes [23] | Oui: One MCP endpoint for every connected SaaS tool |
| Per-tool-call policy, including parameters | Oui: Middleware blocks on tool name, argument values or prompt content [3] | Oui: Policy reads structured arguments joined with the calling identity [16] | Oui: Decisions on identity, role, resource, action, parameters, environment and risk [23] | Oui: Role, tool, parameters and rate limits checked before the call leaves |
| Agent identity with an owner and scoped credentials | Partiel: Named org-scoped principals with expiring keys; creator recorded, no ongoing owner field [4] | Partiel: Synapse passes the delegating user's identity; registry and credentials are not Cerbos features [17] | Partiel: Agents authenticate via IdP or per-agent virtual key; owner assignment not documented [25] | Oui: Owner, model and scopes on every agent; short-lived scoped credentials |
| Immutable or tamper-evident audit log of tool calls | Oui: Signed, append-only records with a published verification key; SIEM export [5] | Partiel: Decision logs with inputs and policy version; no immutability claim [18] | Partiel: Logs identity, agent, tool, parameters and decision; no immutability claim [25] | Oui: Prompts, calls and responses in a WORM log |
| Kill switch: pause one or all agents instantly | Oui: Org-wide switch rejects every call immediately; per-tool disables [6] | Partiel: A revocable task authority pattern, not a button [16] | Partiel: Per-agent key revocation; no documented all-agents switch [26] | Oui: Global kill switch across every connected tool |
| Human access governance: reviews, onboarding, offboarding | Partiel: SCIM groups drive MCP tool access; no access reviews; MCP scope only [7] | Non proposé: Application and API authorization; no reviews or lifecycle [14] | Non proposé: Access Proxy adds SSO, MFA and RBAC to apps; no reviews or lifecycle [27] | Oui: Same product runs reviews, HRIS onboarding and offboarding |
| SaaS discovery: shadow IT and shadow AI | Partiel: Agent Monitor sees coding agents' tool calls; vendor says it is not a discovery tool [8] | Non proposé: Discovery left to the gateway; no SaaS discovery [15] | Non proposé: Inline enforcement only; no discovery offering [28] | Oui: Sign-in logs, mailbox scanning, Chrome extension, code scanning |
| Prompt-level DLP and redaction | Oui: Mask action on arguments and results; DLP provider templates; prompt masking falls back to block [3] | Non proposé: Permission-aware filtering and log masking only [22] | Partiel: Data protection guardrails stated; redaction mechanism not documented [29] | Oui: Detect and redact PII and secrets before the model sees them |
| Exposes SaaS actions as MCP tools without a vendor MCP server | Partiel: Hosts open-source or custom MCP servers; wrapping an arbitrary API not documented [9] | Non proposé: Does not expose or host tools [15] | Partiel: Proxies REST APIs alongside MCP; API-to-MCP conversion not documented [24] | Oui: Connected SaaS integrations exposed as MCP tools through one endpoint |
| Self-hosted or on-prem deployment | Oui: Self-hosted on your infrastructure listed on the pricing page [10] | Oui: PDP runs anywhere; Hub self-hostable since January 2026 [20] | Oui: Cloud, on-premises, hybrid or Datawiza-hosted [29] | Non proposé: SaaS hosted in the EU |
| EU hosting | Oui: US and EU availability stated on the vendor blog [11] | Partiel: Self-host anywhere; no EU region documented for cloud Hub [20] | Partiel: Self-host in any region; no EU region documented for the hosted service [24] | Oui: OVHcloud, France |
| Human-in-the-loop approvals for sensitive calls | Partiel: Ask-user rule pauses the call for the same end user; Slack is alert only [12] | Partiel: Denials can name required approvers; no approval workflow [16] | Partiel: Sensitive actions can be routed for approval; channel not documented [29] | Oui: Approval in Slack, Teams or the app UI, logged with the call |
| Published pricing | Partiel: Pricing page, custom per-user licensing, no figures [10] | Oui: Open source free; development from $25 per month; production from $933 per month [19] | Partiel: Pricing page, subscription customised, no figures [30] | Non proposé: On request |

## Choisissez MintMCP si

- You want a dedicated gateway for coding agents and hosted MCP connectors, with signed audit records and programmable middleware.
- Human access governance is handled elsewhere and SCIM group entitlements are enough.

## Choisissez Cerbos si

- You run your own gateway and want an open-source, self-hostable policy decision point with one policy language across apps and agents.
- Your team writes authorization policy as code and wants sub-millisecond decisions.

## Choisissez Datawiza si

- You need to put SSO and policy in front of legacy and on-prem applications as well as agents, with credential brokering so agents never hold secrets.
- You want inline deployment with no SDK and no agent code changes, in your own cloud or DMZ.

## Choisissez Lutril si

- The agents and the employees who own them should be governed by one policy, one review campaign and one audit log.
- Prompt DLP, a WORM log and a global kill switch must be in the base product, not integrations to assemble.
- Sensitive tool calls need a human approval in Slack, Teams or the app UI, with the decision logged.
- You also need to find the agents you do not know about, through sign-in logs, mailboxes, the browser and code.
- Your data has to stay in the EU, or your team works in French.

## Questions fréquentes

### What is an MCP gateway?

A proxy that speaks the Model Context Protocol to AI agents and sits in front of the tool servers they call. It authenticates the agent, applies policy to each tool call (which agent, which tool, which parameters), logs the call and can stop the agent. It replaces the pattern of handing an agent a raw API key that grants everything the key allows.

### What is the best MCP gateway to enforce policy on AI agent tool calls?

For a standalone gateway with deep middleware and signed audit records, MintMCP. For an open-source decision point behind a gateway you already run, Cerbos. For inline enforcement across legacy apps and agents with credential brokering, Datawiza. For a gateway that is part of access governance for the whole company, with agent owners, prompt DLP, a kill switch, human approvals in Slack, Teams or the app UI, and the same reviews for agents and employees, Lutril.

### How do I control what AI agents can access through MCP?

Register each agent as its own identity with an owner and a scoped role. Route its tool calls through a gateway that checks each call against policy before forwarding it. Log every call immutably. Keep a kill switch that pauses the agent everywhere. Include agents in access reviews so idle or over-scoped ones get tightened. Lutril's MCP proxy and agent registry do all five.

### Is Cerbos an MCP gateway?

No, by its own account. Cerbos is an authorization decision point that a gateway such as agentgateway calls before a tool runs. It decides; the gateway routes. If you already operate a gateway and want policy as code, that split works well. If you want one product that proxies and decides, look at MintMCP, Datawiza or Lutril.

### Can a gateway expose a SaaS tool that has no MCP server?

Only if the gateway itself wraps the vendor's API as MCP tools. Lutril does this for its connected SaaS integrations through one endpoint. MintMCP hosts open-source or custom MCP servers; Datawiza proxies REST APIs alongside MCP. Cerbos does not expose tools.

## Sources

1. [MintMCP homepage](https://www.mintmcp.com/) (consulté le 2026-09-02)
2. [MintMCP docs, introduction](https://www.mintmcp.com/docs/intro) (consulté le 2026-09-02)
3. [MintMCP docs, gateway middleware](https://www.mintmcp.com/docs/gateway-middleware) (consulté le 2026-09-02)
4. [MintMCP docs, agent identities](https://www.mintmcp.com/docs/agent-identities) (consulté le 2026-09-02)
5. [MintMCP docs, audit and observability](https://www.mintmcp.com/docs/security/audit-observability) (consulté le 2026-09-02)
6. [MintMCP docs, operational controls](https://www.mintmcp.com/docs/operational-controls) (consulté le 2026-09-02)
7. [MintMCP docs, RBAC](https://www.mintmcp.com/docs/rbac) (consulté le 2026-09-02)
8. [MintMCP docs, Agent Monitor overview](https://www.mintmcp.com/docs/agent-monitor-overview) (consulté le 2026-09-02)
9. [MintMCP docs, add a hosted connector](https://www.mintmcp.com/docs/add-hosted-connector) (consulté le 2026-09-02)
10. [MintMCP pricing](https://www.mintmcp.com/pricing) (consulté le 2026-09-02)
11. [MintMCP blog, agent gateways for healthcare organizations](https://www.mintmcp.com/blog/agent-gateways-healthcare-organizations) (consulté le 2026-09-02)
12. [MintMCP docs, Agent Monitor rules](https://www.mintmcp.com/docs/agent-monitor-rules) (consulté le 2026-09-02)
13. [MintMCP docs, Mint Guard](https://www.mintmcp.com/docs/mint-guard) (consulté le 2026-09-02)
14. [Cerbos homepage](https://www.cerbos.dev/) (consulté le 2026-09-02)
15. [Cerbos blog, what is an MCP gateway](https://www.cerbos.dev/blog/what-is-an-mcp-gateway) (consulté le 2026-09-02)
16. [Cerbos blog, governing AI agents at the gateway with agentgateway](https://www.cerbos.dev/blog/governing-ai-agents-at-the-gateway-with-cerbos-and-agentgateway) (consulté le 2026-09-02)
17. [Cerbos, Synapse](https://www.cerbos.dev/product-cerbos-synapse) (consulté le 2026-09-02)
18. [Cerbos docs, audit log collection](https://docs.cerbos.dev/cerbos-hub/audit-log-collection.html) (consulté le 2026-09-02)
19. [Cerbos pricing](https://www.cerbos.dev/pricing) (consulté le 2026-09-02)
20. [Cerbos blog, Hub available on premise](https://www.cerbos.dev/blog/cerbos-hub-now-available-on-premise) (consulté le 2026-09-02)
21. [Cerbos on GitHub](https://github.com/cerbos/cerbos) (consulté le 2026-09-02)
22. [Cerbos, dynamic authorization for MCP servers](https://www.cerbos.dev/features-benefits-and-use-cases/dynamic-authorization-for-MCP-servers) (consulté le 2026-09-02)
23. [Datawiza, MCP gateway](https://www.datawiza.com/mcp-gateway) (consulté le 2026-09-02)
24. [Datawiza, Agent Gateway](https://www.datawiza.com/products/agent-gateway) (consulté le 2026-09-02)
25. [Datawiza docs, Agent Gateway introduction](https://docs.datawiza.com/agent-gateway/introduction.html) (consulté le 2026-09-02)
26. [Datawiza blog, Agent Gateway for secure AI agent access](https://www.datawiza.com/blog/industry/datawiza-agent-gateway-for-secure-ai-agent-access-to-enterprise-apis/) (consulté le 2026-09-02)
27. [Datawiza, Access Proxy](https://www.datawiza.com/products/access-proxy) (consulté le 2026-09-02)
28. [Datawiza homepage](https://www.datawiza.com/) (consulté le 2026-09-02)
29. [Datawiza, AI agent security use case](https://www.datawiza.com/use-cases/ai-agent-security) (consulté le 2026-09-02)
30. [Datawiza pricing](https://www.datawiza.com/pricing) (consulté le 2026-09-02)

Cette page a été rédigée par Lutril. Les faits concernant MintMCP, Cerbos, Datawiza proviennent de leur documentation publique au 2026-09-02. Une erreur ? Écrivez à hello@lutril.com.
