Zero Trust AI Enclaves

Govern Every AI Interaction at Machine Speed.

See exactly what each agent, LLM, and MCP server is doing.

  • Give every AI agent, LLM, and MCP server a cryptographic identity
  • Control what each one can reach, spend, and access
  • No shared API keys, no open ports, no firewall changes
Identity-first AI Enclave AI agents, LLMs, and MCP servers each carry a cryptographic identity. No routable path to protected resources exists until identity and policy authorize the connection. IDENTIFIED WORKLOADS AI Agent id: agent-07 LLM id: llm-prod MCP Server id: mcp-tools POLICY authN + authZ before connect ZERO TRUST ENCLAVE Private Models self-hosted Tools & APIs policy-scoped Data Sources least-privilege No routable path exists until identity and policy authorize it. Unauthenticated traffic sees nothing — the enclave is invisible from the internet.
100% of AI interactions carry an identity — every one authorized, logged, and accountable
Invisible attack surface — no ports, endpoints, or services for attackers to discover, scan, or exploit
0 inbound ports, firewall changes, or shared API keys required
The challenge

AI Moves at Machine Speed. Your Governance Can’t Keep Up.

You can’t govern what you can’t see or control. Legacy tools authorize by IP address, share API keys across every workload, and can’t tell you what any single agent is reaching, calling, or costing. Every new agent, model, or tool widens that gap — and adds another round of firewall, routing, and NAT changes.

  • No per-agent visibility into which model, tool, or data source each workload is calling
  • No way to cap or attribute the cost and token spend of individual agents and teams
  • Open inbound ports expose LLMs and MCP servers to attack
  • Security reviews delay deployment; teams default to shadow AI
68% of employees already use shadow AI because of deployment delays1 — every workaround is another ungoverned path into your data.
Data path sprawl without governance A single AI agent spawns many separate data paths, each requiring its own firewall, NAT, and DNS change, with no unified visibility or cost control. 68% of employees already use shadow AI because of deployment delays. AI Agent no identity Firewall change NAT rule DNS entry Firewall change Open port LLM (exposed) Tools / APIs Data source
The NetFoundry solution

One Identity-First Enclave for Every AI Interaction

Identity Builds a Private, Invisible Overlay

NetFoundry’s Zero Trust AI Enclave gives every agent, LLM, and MCP server a cryptographic identity, then uses that identity to build a private, policy-governed overlay that is invisible to the internet. It authenticates and authorizes each identity before a connection ever exists. No open ports. No API keys. No routable path until you’re cleared.

Authenticate First. Connect Second. Always.

Traditional networks make you reachable before you’re authenticated. NetFoundry’s AI Enclave flips that: it verifies identity and evaluates policy before any routable path exists. If identity and policy don’t authorize the interaction, no connection is made.

  • Every workload gets its own cryptographic identity, not a shared key
  • Service-level least-privilege access — each workload reaches only what policy explicitly permits
  • Full end-to-end encryption
  • Outbound-only connections from every component — no inbound ports, no firewall holes
  • Agent connectivity optionally embedded via the NetFoundry SDK
How it works

Govern an AI Interaction in Five Steps

No shared keys to distribute, no inbound ports to open, and no firewall changes to request. Give each workload an identity, let it dial out, and authorize every connection before a path exists.

  1. 1

    Give each workload a cryptographic identity

    Each component gets its own certificate identity, bound to the workload rather than a shared key.

  2. 2

    Every component dials out — nothing listens

    Every component dials out and authenticates mutually, which leaves no inbound port open and no public endpoint exposed.

  3. 3

    Policy authorizes each connection before a path exists

    Policy evaluates identity before any routable path exists, granting an agent only the models, tools, and data it explicitly permits.

  4. 4

    Every interaction is logged and metered by identity

    Because the same identity authorizes and records each connection, you see which agent reached which model or tool and what it consumed.

  5. 5

    You govern access, spend, and models through one console

    Grant or revoke access, cap spend, and steer requests between public and private models by editing policy in one place, effective immediately.

Want the architecture in depth — tunnelers, SDKs, the control plane, and enforcement? Explore the platform →

Control and visibility

See Every AI Interaction. Control What Each One Can Do.

Governance is visibility plus control: seeing what your AI does, and deciding what it’s allowed to do. The AI Enclave gives you both under one identity model — plus the cost and token data finance and security need to keep AI spend accountable.

Cost and token governance

  • Budget, cap, and attribute cost and tokens by agent, team, and project
  • Finance and security see the same numbers in one place
  • Policy stops a runaway agent before it lands on an invoice

Identity-based visibility

  • Every request tied to a workload identity, not an IP address
  • Auditable record of which agent reached which model, tool, or data source
  • One view across every environment and cloud

LLM Gateway

  • Manage external and internal LLMs from one place
  • Route across models with usage policies, load balancing, and failover
  • No exposed endpoints, no distributed API keys

MCP Gateway

  • Identity-based authentication to MCP servers
  • Agents discover and invoke only tools within their policy scope
  • Eliminates secret-based access entirely

LLM semantic routing

  • Route each query to a public or private self-hosted model automatically
  • Optimizes for cost and data privacy on every request

Instant policy changes

  • Grant or revoke access immediately
  • Policies defined centrally and updated programmatically
  • Control keeps pace with a fast-changing agent ecosystem
“We moved beyond the perimeter with NetFoundry. It delivers a strictly ‘least-privileged’ access model that is incredibly easy to deploy. The management console turns what used to be a tangle of firewall rules into a streamlined, visual command center.”

Viktor Szabó, Deputy CTO, Ominimo

See it in action

Watch the AI Enclave Govern a Live Interaction

See identity, policy, visibility, and cost control work together across every AI workload.

Outcomes

Full Governance. No Attack Surface Left to Manage.

💲

Accountable AI spend

  • Every dollar and token traces to an owning agent, team, or project
  • Finance and security stop reconciling separate numbers
  • AI budgets hold without buying another tool
🔒

Invisible attack surface

  • Nothing sits on the public internet for attackers to scan or reach
  • Models, tools, and data stay off every exposed surface
  • Exposure-based attacks have no target to aim at
🛡

No shadow AI

  • Teams have no reason to route around security
  • Every agent, model, and tool stays visible and governed
  • The ungoverned workaround loses its only advantage
🚀

Deployment without exposure

  • Workloads connect across clouds, data centers, and the edge
  • Outbound-only connections keep every environment free of inbound holes
  • New workloads join without firewall changes or network reconfiguration
AI Accelerator Program

Building AI agents right now?

Join the AI Accelerator Program and stand up a governed enclave for your AI workloads with hands-on help from our team.

“NetFoundry provides the secure network foundation Rhapsody needs to support private, policy-based access across distributed healthcare environments, including applications, APIs, workloads, and emerging AI-enabled workflows. That security layer complements our integration platform by helping customers modernize while protecting mission-critical data exchange.”

Kevin Day, CTO, Rhapsody

FAQ

Frequently Asked Questions About Zero Trust AI Enclaves

What is a Zero Trust AI Enclave?

NetFoundry’s Zero Trust AI Enclave is a private, policy-governed overlay network that gives every AI agent, LLM, and MCP server its own cryptographic identity and authorizes each connection before a routable path exists. The enclave stays invisible from the internet, requires no open inbound ports or shared API keys, and logs every AI interaction by identity.

How does NetFoundry secure AI agents, LLMs, and MCP servers?

NetFoundry secures AI agents, LLMs, and MCP servers by binding a certificate-based identity to each workload and evaluating policy before it creates any connection. Because every component dials out and nothing listens on an inbound port, models, tools, and data sources stay hidden from internet discovery, scanning, and exploitation.

Does deploying a Zero Trust AI Enclave require firewall changes or open ports?

No. NetFoundry’s Zero Trust AI Enclave uses only outbound, mutually authenticated connections and needs no inbound ports, no firewall changes, no VPN setup, or network reconfiguration. New agents, tools, and models join without opening the network or exposing an endpoint.

How does NetFoundry control AI costs and token spend?

NetFoundry attributes cost and token consumption to the identity of each AI agent, team, and project, and enforces budgets and caps through policy. Finance and security teams see the same numbers in one console, and policy stops a runaway agent before it appears on an invoice.

What is an MCP gateway, and how does NetFoundry’s MCP Gateway work?

NetFoundry’s MCP Gateway authenticates AI agents to Model Context Protocol (MCP) servers with workload identities instead of shared secrets. Each agent discovers and invokes only the tools its policy explicitly permits, which eliminates secret-based access and keeps MCP servers off the public internet.

Can NetFoundry route AI requests between public and private LLMs?

Yes. NetFoundry’s LLM Gateway manages external and internal models from one place with usage policies, load balancing, and failover, and its semantic routing directs each query to a public or a private self-hosted model automatically to optimize for cost and data privacy.

How does a Zero Trust AI Enclave differ from a VPN or firewall approach?

NetFoundry’s Zero Trust AI Enclave authorizes each connection by cryptographic workload identity rather than by IP address, and it verifies identity and policy before any routable path exists. Traditional networks make resources reachable first and authenticate second, which leaves open ports and shared credentials for attackers to find.

How does NetFoundry prevent shadow AI?

NetFoundry prevents shadow AI by making governed AI deployment as fast as the unofficial workarounds that create it. Because connecting a new agent, model, or tool requires no firewall tickets or exposed endpoints, teams gain no speed advantage from unauthorized connections, and every interaction stays visible and policy-controlled.

Get started

Secure Your AI Infrastructure Today

1 68% of employees already using shadow AI because of deployment delays. Source: NetFoundry internal survey data, 2025.