Golf
Production-Ready MCP Server Framework • Build, deploy & scale secure AI agent infrastructure • Includes Auth, Observability, Debugger, Telemetry & Runtime • Run real-world MCPs powering AI Agents
Last verified:
What is Golf?
Golf is an agentic AI security and governance platform that provides enterprises with visibility, control, and audit trails for AI agents and MCP (Model Context Protocol) servers running in their organization. It operates at the MCP layer rather than the LLM layer, allowing security teams to discover every AI agent and data connection—including shadow AI they didn't know existed—without controlling the LLM or changing how engineers work.
Key features include real-time threat detection that blocks prompt injections and redacts PII before reaching systems, identity integration through Okta/Azure/IdP for per-user access policies, centralized dashboard for managing all AI agents and MCP servers, and SIEM integration that streams structured logs to Sentinel, Splunk, or other SIEM tools for SOC 2 compliance. The platform offers both an open-source GolfMCP framework for building production-ready MCP servers and a hosted Golf Gateway for observation and management.
Golf is designed for enterprise security teams who need to uncover shadow AI and stop threats, AI governance teams who need to know what agents are running and enforce policies, and IT teams who want to enable AI adoption without building auth, routing, and logging from scratch. It maps to major compliance frameworks including SOC 2, ISO 27001, NIST AI RMF, and FINRA.
The platform deploys fully in your VPC or uses a hosted control plane, ensuring your data never touches Golf's servers. It provides sub-millisecond enforcement latency and plugs natively into existing enterprise identity and security stacks.
Golf pricing
Pricing model: Freemium
Hobby: $0/month for 1 MCP server, 50k requests/month, 3 days trace retention, 1 Agentic Test run/month, and community support. Startup: $299/month for up to 10 MCP servers, 10M requests/month, 7 days trace retention, 5 Agentic Test runs/month, and email support. Scale: $999/month for up to 50 MCP servers, 100M requests/month, 30 days trace retention, 100 Agentic Test runs/month, and Slack support. Enterprise: Custom pricing for unlimited MCP servers, custom request cap, 90 days trace retention, and 99.99% uptime SLA.
Golf pros
- Provides complete visibility into shadow AI and unknown MCP servers
- Real-time threat blocking for prompt injections and data leaks
- Automatic PII redaction before data reaches systems
- Identity integration with Okta, Azure, and any IdP for per-user policies
- SOC 2 ready out of the box with structured log streaming to SIEM
- Open-source GolfMCP framework with no decorators or boilerplate
- Deploy production-ready MCP server in under 60 seconds
- File-based structure for defining agent capabilities
- No need to control the LLM or change engineer workflows
- Single dashboard to manage all AI agents and MCP connections
- VPC deployment option ensures zero data exfiltration
- Sub-millisecond enforcement latency
- Maps to SOC 2, ISO 27001, NIST AI RMF, and FINRA frameworks
- Built-in telemetry, error reporting, and routing handled automatically
- Real-time traces and tool usage monitoring in Golf Gateway
Golf cons
- Enterprise-focused pricing may be expensive for small teams
- Requires IdP integration for full identity-based access control
- Learning curve for teams new to MCP architecture
- Hosted Gateway adds cost compared to self-hosted only
- Primarily targets enterprises, limited small business features
- SIEM integration required for full audit trail benefits
- Open-source framework requires Python knowledge
- Limited documentation for advanced custom configurations
Frequently asked questions about Golf
What is Golf and what problem does it solve?
Golf is an agentic AI security and governance platform that gives enterprises visibility into what AI agents and MCP servers are running in their organization, policy control over what they can access, and audit trails for compliance. It solves the problem of shadow AI where employees use AI tools and teams build agents without central oversight, leaving security teams unaware of what's connected to production data.
How does Golf differ from traditional AI security tools?
Golf operates at the MCP (Model Context Protocol) layer rather than the LLM layer, meaning it governs where agents connect to your data without interfering with how engineers work or requiring control over the LLM itself. This allows teams to keep using ChatGPT, Claude Code, Cursor, and their own agents while Golf provides the security layer.
What threat protection does Golf provide?
Golf scans every interaction in real-time to block attacks including indirect prompt injections, data leaks, tool poisoning, rug pulls, tool shadowing, authentication bypass, and credential exposure. It also redacts PII before sensitive data reaches your systems.
How does Golf handle identity and access control?
Golf ties every agent action to a real identity through Okta, Azure, or your existing IdP, solving the problem of shared API keys that make it impossible to trace actions back to a person. This enables per-user, per-tool access policy enforcement.
Is Golf compliant with enterprise standards?
Yes, Golf is audit-ready from day one and maps to major compliance frameworks including SOC 2, ISO 27001, NIST AI RMF, and FINRA. It streams structured logs to Sentinel, Splunk, or your SIEM, giving you full data lineage and SOC 2 readiness out of the box.
Can I deploy Golf in my own infrastructure?
Yes, you can deploy Golf fully in your VPC or use their hosted control plane. Either way, your data never touches Golf's servers, ensuring zero data exfiltration and giving you complete control over your infrastructure.
What is GolfMCP and who is it for?
GolfMCP is an open-source framework that gives developers a clear, file-based structure to define what their agent can call without decorators, spec knowledge, or boilerplate. It's for teams building MCP servers who want to ship production-ready servers in under 60 seconds without worrying about routing, auth, telemetry, error reporting, and deployment plumbing.
What is the Golf Gateway?
Golf Gateway is the hosted layer that runs and observes your GolfMCP server. Using 'golf deploy' gives you a live server in under 60 seconds with real-time traces, tool usage monitoring, and error monitoring built in. You can observe and manage your server through the gateway dashboard.
How quickly can teams get started with Golf?
Teams can deploy Golf in minutes with sub-millisecond enforcement latency. Using golf deploy, you can get a live MCP server running in under 60 seconds with built-in monitoring. The platform is designed to plug into your existing identity and security stack without extensive setup.
Who is the ideal customer for Golf?
Golf is ideal for enterprises with security teams that need to uncover shadow AI and stop threats, AI governance teams that need to know what agents are running and enforce policies from one place, and IT teams that want to enable AI adoption without building authentication, routing, and logging infrastructure from scratch. It's particularly valuable for companies rolling out agent products that need architectural assurance for security and customer trust.