The Model Context Protocol (MCP) was supposed to be the great connector, a universal language allowing AI agents to talk to our data. It has succeeded in that mission, with over 17,000 servers deployed. But as the agent economy scales, we are discovering that connecting everything to everything else is a security nightmare waiting to happen.
The deeper issue is that we have been treating MCP servers like harmless plugins, when they are actually third-party code execution engines. If you wouldn’t run an unvetted container image in your production environment, why are you letting an agent pull down an unverified MCP server to query your database?
On July 13, 2026, JetStream Security launched its Verified MCP Governance Layer, formalizing MCP governance as a distinct infrastructure category. With a $34M seed round from Redpoint Ventures and the CrowdStrike Falcon Fund, JetStream is betting that the bottleneck for enterprise AI adoption is not capability, but trust.
The numbers support this anxiety. Research from BlueRock Security in March 2026 found that 36.7% of MCP servers were vulnerable to Server-Side Request Forgery (SSRF), while 43% contained command injection flaws. When you consider that only 17% of organizations are currently using AI at production scale, according to UBS Evidence Lab, it becomes clear that these security gaps are the primary friction point.
AJ Anand, co-founder and CTO of JetStream, puts it bluntly: “Enterprises are no longer asking whether AI agents can be useful; they are asking whether they can trust what those agents do once they are connected to the systems that matter. MCP raises the stakes because every server an agent uses is third-party code, wired into tools, data, and workflows.”
JetStream’s approach moves beyond simple token passthrough. Their platform acts as an OAuth-aware governance broker, offering semantic scanning for credential leakage, unicode smuggling, and obfuscated malware. It provides over 100 hardened, cryptographically attested MCP server images and an AI Hub for runtime governance. As Anand notes, “A directory of servers you have never inspected is not a control. We analyze the code, remove the vulnerabilities, attest the result, and let the teams control which tools an agent can call.”
This is not a solo endeavor. The Futurum Group identified MCP governance as the 2026 production gate for AI agents, and the capital markets are responding accordingly. Beyond JetStream, a cohort of players including Stacklok, Operant AI, Runlayer, Helmet Security, and Manufact have collectively raised over $74M to solve this specific problem. Whether it is Kubernetes-native GitOps registries or runtime brokers, the industry is converging on the same realization: MCP needs a supply chain security model.
JetStream’s “AI Blueprints” feature, which maps approved servers to sanctioned agents, enforces policy-driven infrastructure. It is no longer enough to just have an agent; you need to know exactly what that agent is allowed to touch and how it is allowed to touch it.
The era of “plug-and-play” agent connectivity is ending, replaced by a requirement for rigorous, attested governance. If you are building for the agent economy, your security stack must now account for the MCP layer as a first-class citizen.
JetStream will be showcasing these capabilities at Black Hat USA in August at Booth 4705, where the conversation will likely move from “what can agents do?” to “how do we safely constrain them?” The infrastructure to answer that question is finally being built.
