Secure transport · MCPs · agents

Run software that couldn’t pass an audit — inside the most regulated VPC on earth.

Legation is a hardened platform for secure transport, secure MCP servers, and secure agents—placed inside your customer's environment and governed under your control, from commercial deployments to DoD-grade sovereign assurance.

No inbound vendor access · Customer-local enforcement · Commercial to DoD-grade assurance
LEGATION / REQUEST PATH
Vendor / operator
Existing productVendor Application
Choose your patternSDK · MCP · A2A · Workflow
OptionalOperator-side Agent
Customer VPC
Outbound-connectedLegation Embassy
Purpose-builtSecure A2A Agent
Purpose-builtSecure MCP Server
Protected boundaryCustomer Data & Systems

The compliance is in the envelope. The app is just cargo.

The governance envelope enforces access, encryption, audit, and residency—so the workload inside it doesn't have to.

See the trust model →
What the customer's security team is guaranteed

Three things the customer can verify—and the operator cannot override.

01

Can't exfiltrate

Data-flow inversion keeps raw customer data in place. Only redacted, structure-only projections cross the boundary—the workload never carries data out.

02

Can't exceed its mandate

Every action is checked inside the customer's VPC against a signed treaty and per-task mandate before it runs. Off-plan behavior is refused, not logged after the fact.

03

Instantly killable

A dual, asymmetric kill switch the customer holds unilaterally. Pull it and the embassy stops acting—and the operator cannot override the recall.

The thesis

Software vendors and customers should not have to surrender control to work together.

The vendor needs to operate and protect its product. The customer needs to keep data, policy, and enforcement inside its own boundary. Legation creates a governed operating relationship between them.

01

Build the workload

Package your software, agent, MCP server, or service as approved cargo with identity, policy, and operational constraints.

02

Deliver it inside

Land the workload inside the customer’s VPC through an outbound-connected Embassy—without opening the customer network to the vendor.

03

Govern it locally

Verify, authorize, observe, constrain, audit, and recall the workload from the customer-controlled enforcement boundary.

Two capabilities, one platform

The secure link, and the secure workloads that run on it.

Most vendors can hand you a tunnel. Legation is the governed link into the customer VPC and the means to build the MCP servers and agents that operate there—secure by construction, and controlled by one hardening dial from commercial deployments to DoD-grade sovereign assurance.

01 / The governed link

Secure delivery as a service

An outbound-only, mutually authenticated link lands approved workloads inside the customer boundary with identity, policy, projection, evidence, and dual recall—without opening the customer network to the vendor.

02 / The secure workloads

Custom MCP servers and agents

Legation builds purpose-built MCP servers and AI agents hardened to run under that same governance—so the components touching customer data are engineered for the boundary, not adapted to it. The flagship example is Preditor: a penetration test that runs inside the customer's environment and proves nothing left it.

Integration freedom

Your application does not have to become an agent.

Use a known tool call for deterministic operations. Add an operator-side agent only when the workflow needs planning or reasoning.

Compare the patterns →

Known tool call

Vendor AppLegationMCP ServerProjection

Your application knows the exact tool or operation. No operator-side agent is required — the tool runs in-VPC and only a governed projection returns.

Agentic delegation

Vendor AgentLegationA2A AgentMCP ServerProjection

The vendor agent delegates an objective. The agent reasons customer-local and uses approved MCP tools; only a projection of the outcome returns.

Native application service

Vendor WorkflowLegation APICustomer ServiceProjection

Legation can transport governed application operations without introducing agents or MCP at all — same projected return.

Hardened and monitored

A secure link is table stakes. The whole deployment is hardened—and watched.

Every element is engineered for a hostile-by-default environment: a hardened runtime, continuous monitoring, and an instant, customer-held kill switch.

01

Hardened runtime

Memory-safe Rust with unsafe code prohibited, compiled into a from-scratch, non-root, shell-less container (static musl, RELRO/NX, STIG-mapped), mutually authenticated mTLS transport, and a CNSA 2.0-aligned cryptography profile that dials up to a FIPS-oriented, sovereign posture.

02

Continuous monitoring

Metadata-only telemetry reports embassy liveness, seal integrity, treaty adherence, and behavioral anomalies—without carrying customer data across the boundary.

03

Instant recall

A dual, asymmetric kill switch: the customer can sever the deployment unilaterally, and the operator cannot override it. Tamper-evident evidence records every decision.

Compliance-aware by design

If a customer environment is regulated, Legation is built to run there.

One hardening dial maps to the control floors of commercial and public-sector frameworks—so the same platform serves a SOC 2 SaaS buyer and a DoD IL5 program, without inventing a new system for each. Host the operator side in AWS Commercial, AWS GovCloud, or AWS Europe—the customer Embassy always runs inside the customer's own boundary.

SOC 2HIPAAPCI DSSGDPREU AI ActFedRAMPNIST 800-53NIST 800-171CMMC L2DoD IL5CNSA 2.0

The hub coordinates. The Embassy enforces.

Plaintext customer data does not need to pass through the routing hub.

Review the trust model →
Designed for hard environments

One platform. Multiple operating boundaries.

Legation provides deployment patterns for commercial SaaS, regulated enterprise, public sector, EU-resident, and higher-assurance environments.

Commercial

Standard AWS

  • Multi-region hub
  • Customer VPC Embassy
  • SOC 2 / HIPAA / PCI-oriented workloads
FASTEST PATH
Public sector

US GovCloud

  • GovCloud deployment path
  • US-region boundary
  • FIPS-oriented configuration
CONTROLLED AVAILABILITY
Data residency

GDPR / EU

  • EU-only regional topology
  • Customer-local processing
  • Regional service boundaries
EU COMMERCIAL AWS
High assurance

Sovereign / HSM

  • Hardware-backed custody
  • PKCS#11 / HSM path
  • Stronger operator separation
DESIGN-PARTNER PROFILE
What it is

Secure operating infrastructure between two trust boundaries.

  • Customer-resident execution and enforcement
  • Outbound-only mutually authenticated connectivity
  • Workload identity and proof of possession
  • Signed policy and mandate enforcement
  • Projected and governed return data
  • Tamper-evident evidence and recall controls
What it is not

Not a VPN. Not a chatbot. Not a generic reverse proxy.

Legation is the hardened delivery, identity, routing, governance, and evidence layer for software operating inside infrastructure the vendor does not own.

Your software. Their VPC. Neither side surrenders control.

See how Legation fits your application and customer security model.

Request an architecture review →