Golf is an AI governance and security platform that operates at the Model Context Protocol (MCP) layer to manage interactions between AI agents and organizational data. The platform provides an MCP Control Plane to discover, enforce, and audit AI tools and MCP servers without routing the underlying LLM traffic or altering developer workflows. It enables organizations to automatically inventory agent connections, apply granular data access policies, and maintain continuous compliance monitoring.
By sitting at the MCP layer, the platform identifies shadow infrastructure and secures data flows before they reach external AI models. Key technical capabilities include real-time Personally Identifiable Information (PII) redaction, prompt injection detection, and the generation of a 90-day immutable audit trail of all agent actions. The system integrates with existing Identity Providers (IDP) and Security Information and Event Management (SIEM) platforms to stream logs and enforce role-based access controls.