Latest release

Yashigani

v2.24.4

What it is

A proxy for MCP and AI tools calls.

Yashigani is a security enforcement gateway purpose-built for Model Context Protocol (MCP) servers and agentic AI systems. It operates as a proxy, sitting between MCP's, AI agents — even human and non-human clients — and the upstream MCP, API, tools or servers they call.

An LLM or AI Agent that can call tools is an potential threat that can be manipulated. MCP defines the protocol, not the security, data privacy or costs envelope around it. Yashigani fills that gap.

  • Authentication, fine-grained authorisation via RBAC and OPA
  • Full compliance and assurance for LLM/AI
  • Three-tier budget governance
  • DLP and sensitive data detection via OPA
  • 4D checks via OPA - PII, HIPAA, PCI, IP / RBAC / Cost / Data Sovereignity
  • ML-assisted prompt injection detection
  • Credential exfiltration prevention
  • Full audit trails and alerts with SIEM integration
  • SSO / SCIM identity integration
The problem it solves

Eight risks agentic AI creates.
One enforcement point.

Agentic AI systems are not just chat interfaces. They call real tools, manipulate real data, and execute real operations.
Traditional API gateways and bolt-on AI wrappers were not designed for this.

Yashigani is

Unmonitored AI access

Bidirectional inspection of every prompt and response. ML pre-filter (under 5ms) plus configurable LLM deep inspection. Fail-closed by default.

Identity sprawl

One unified identity model for humans, agents, services, and integrations.
Same RBAC, same audit, same trail - full compliance.

Uncontrolled AI spend

Three-tier budget enforcement - organisation / group / user - when the cap hits Yashigani routes to local inference — it never rejects requests.

Data leakage to cloud

Three-layer sensitivity pipeline. Run as many open-soource models as you can. CONFIDENTIAL / SENSITIVE data routes to local models only — no override, no bypass. PII detection on both directions.

Routing opacity

Deterministic P1–P9 routing with a full reasoning trail. Every decision is reproducible and audited.

Multi-IdP complexity

Yashigani is the identity broker. Native OIDC and SAML v2. No external Keycloak. One fewer attack surface.

Agent data isolation

Container-per-identity. No shared filesystems, no shared context. Isolation is not a toggle — it's an architectural invariant.

Infrastructure fragility

The Pool Manager replaces broken containers from a warm pool before the user notices. Forensic evidence is preserved before cleanup.

Compliance

OWASP ASVS v5 Level 3: 92%.

Per-control compliance evidence published under docs/compliance/. PASS / PARTIAL / FAIL / N/A verdicts with file:line evidence. Coverage includes OWASP ASVS v5 L3 (all chapters), OWASP API Security, and the OWASP Agentic AI / LLM Top 10.

Pricing

Three zones. Seven tiers. Transparent pricing.

From a single developer on a laptop to a multi-region enterprise deployment. Every tier ships from the same single branch — features are gated by signed licence, not by separate builds.

Free

Open-source, plus free verified non-profit and education licences.

Community
Free

Yashigani Community

Apache 2.0 open-source. Up to 20 agents, 5 users, 2 admins, 1 organisation. Local auth only.

Non-profit / Edu
Free

Non-Profit & Education

Free for verified non-profits and educational institutions. Unlimited agents, users, admins, IdPs. SAML, OIDC, SCIM included.

SMB

From 6 friends in a garage to a full scale up or medium businesses growing from pilot to production.
All plans billed annualy

Igniter
£150/month

Igniter

Up to 200 agents, 50 users, 5 admins. 1 OIDC identity provider. For pilots and small production deployments.

Popular
Starter
£250/month

Starter

Up to 400 agents, 100 users, 10 admins. 1 OIDC IdP.
Expand with up to 5x 50-user bundles at £150/month each.

Professional
£1,000/month

Professional

Up to 2,000 agents, 500 users, 25 admins. 1 OIDC + 1 SAML IdP. SCIM provisioning. Bundles available.

Enterprise

For multi-org, multi-region, large-scale deployments.
Dedicated partner support and training.
Support Packages billed separatly and taylored to your needs

Professional Plus
From £ 6,750/month

Professional Plus

Up to 16,000 agents, 4,000 users, 100 admins, 5 IdPs, 5 orgs. Partial multi-tenant isolation.
Bundles of 250 users available.

Enterprise
Available soon

Enterprise

Unlimited everything. Full multi-tenant isolation. Unlimited IdPs and orgs.
For independent and isolated multinational deployments at scale.

Prices exclude VAT. Need help choosing? Talk to us. Or read the full README on GitHub.

Ready to see it in action?

A 30-minute demo, no sales pressure. We'll show you the inspection pipeline, the routing engine, and the audit trail.

Request a demo →