An MCP gateway and capability broker — one small tool surface in front of every downstream MCP server, with deny-by-default policy, credential isolation, and audit.