Introducing Ultra
The easy and secure way for everyone to use agents and MCP.
Give an AI agent one tool and it will use it. Give it fifty, running unattended, with reach into your files, your databases, and your production systems, and you have either your most productive new teammate or your largest unmonitored attack surface. Most teams cannot tell which, because nothing is watching the agents.
AI agents can now connect to almost anything through the Model Context Protocol (MCP): databases, internal tools, and critical infrastructure. That reach is what makes agents useful and powerful. It is also what makes them dangerous without controls. Tool poisoning, context injection, credential exposure, rug pulls, and uncontrolled MCP sprawl are real threats, and the security tools most companies already run were not built to see them.
Today we are introducing Ultra, the first purpose-built MCP security platform, backed by $10M+ in seed funding to solve exactly this problem. Ultra is autonomous runtime security for AI and MCP: real-time visibility and enforcement for AI systems and agents that act on their own.
Agents take action. Agents can be sneaky. Ultra secures them.
Why we built Ultra
Ultra was founded in 2025 by Chase Lee, founder of Trustpage (acquired by Vanta), and a team of security and compliance professionals, machine-learning researchers, and engineers who saw a security gap opening in the AI ecosystem. As MCP began letting agents reach tools and sensitive data, it was clear that traditional security was not built for this paradigm.
The teams adopting agents fastest kept hitting the same wall. Their AI clients were powerful but opaque: when Claude Desktop or Cursor called a tool, no one knew exactly what happened. Connecting clients to servers had become an N×M mess, with posture drifting on every new addition and additional permissions being granted on each call. And security teams had no answer to the question that matters most in a regulated environment: what did the agent do, when did it do it, what data did it touch, and how did it do it? Ultra closes that gap as the secure universal bridge and firewall that all agentic traffic already flows through.
What Ultra does
Ultra sits between your agents and the upstream connectors they call. Every tool call, resource read, and prompt request passes through Ultra, which is what makes the following possible. In practice, it is a firewall for your agents and their connectors: one enforcement point that every action flows through, so nothing dangerous gets through unseen. Three value pillars anchor the platform.
1. Policies translated into guardrails
Ultra does not just monitor, it enforces. Whether it be via built in guardrails or custom guardrails you can define your security policy and Ultra translates it into Guardrails that run in real time on every tool call: blocking credential and secret access, redacting PII, protecting PHI, rate-limiting abuse, and preventing data read on one connector from being written to another. Guardrails ship with pre-configured defaults, run in block, monitor, alert, or redact modes, and can be scoped to your whole organization, a workspace, or a single device.
2. Full observability and governance over every tool call
See everything. Who did what, when, how, did it work or not, and what data was pulled. Every agent-to-tool interaction is logged, traced, and queryable, so you know exactly what your agents are doing, when, and with whose authorization. Anomaly detection adds an AI-native layer on top, scoring traffic for suspicious patterns like enumeration, privilege escalation, data exfiltration, injection, and credential abuse, then surfacing findings as actionable alerts. If you are a 100 person organization or a 5,000 person organization, it is critical to know what your people and their agents are doing.
3. Connectivity that makes MCP simple
Ultra is one universal bridge for every agent and every connector. Connect multiple agents to Ultra once and it reaches every upstream connector behind it, with native AI-to-MCP integration across stdio, HTTP/SSE, and Streamable HTTP, and new connectors hot-loaded without a restart. Add a connector in one place and every agent can use it immediately, with no per-client setup: connect once, deploy everywhere. This is what lets a single agent pull context from one system, take action in another, and log all of it along the way, and it is what makes AI and MCP simple to connect and use for the whole organization, not just engineers. Ultra is vendor- and model-agnostic by design: any agent, any connector, any transport. As models and agents continue to change, Ultra makes vendor-agnostic connectivity a concern of the past, so adopting a new model or swapping a tool never means re-plumbing your stack.
We prioritize one thing, on purpose
A lot of companies in this space are getting pulled in every direction at once: AI infrastructure, agent orchestration, model tooling, whatever the roadmap of the week demands. Ultra is not. We are a security company, first and foremost. Every feature we ship exists to make agentic AI and autonomous systems safe to run, and that focus is intentional and product-led.
To be clear, this is a choice about focus, not a knock on the upside. Connecting to MCP servers and agents through Ultra does make AI genuinely easier to adopt, and it unlocks and enables real workflow automation along the way. We are glad it does. Our vision is to democratize AI for all. But that is a welcome byproduct, not the mission: security is why Ultra exists, and everything else follows from securing the future of AI.
It shows up in the architecture, too. Ultra is local-first: Ultra runs locally on your own machine, and your tool calls, payloads, and audit trails stay there by default. Many alternatives force every request through their cloud proxy, adding a network hop and putting a third party in the path of your most sensitive traffic. We do offer a remote-hosted option for teams that want it, but it is an option, not the only door in. Your data stays yours until you choose otherwise.
How Ultra is different
- Purpose-built, not retrofitted. Ultra was designed for MCP from day one. We are not a legacy security vendor adding an AI checkbox, a new product offering, or trying to keep up with the trends.
- Free to start, easy to deploy. One-click deployment with pre-configured policies. No sales friction, no lengthy configuration.
- AI-native architecture. We use AI to secure AI, with real-time intelligence that adapts as threats evolve.
- Full-stack, not point solution. Guardrails, governance, observability, runtime protection, alerting in one platform, not just monitoring or just access control.
- Built for everyone. Engineers get security and depth, and non-technical teams get a visual, code-free Hub. Vendor agnostic to support teams no matter which agents or models they use. Democratizing AI means democratizing the security that makes it safe.
Against traditional tools retrofitting MCP support, Ultra was built for the protocol. Against proxy-only solutions, Ultra goes well beyond routing. Against enterprise-only AI security, Ultra starts free with developer-first distribution.
Enterprise-ready from day one
Trust is not a later milestone or a nice to have for us, it is the founding team's background and priority. This is a team that has spent its careers building trust, security, and compliance products, so making Ultra secure and audit-ready from day one was the natural result rather than an afterthought. That shows in the posture: Ultra is SOC 2 Type II, ISO 27001, ISO 42001 certified, all by one of the premier auditors in the world in A-LIGN and aligned to NIST AI RMF, with tamper-proof audit trails and one-click compliance reports, all shared openly at the Ultra Trust Center. And we are not stopping: FedRAMP 20x and AARM, which Ultra is an early contributor to, are in the works. Being secure, compliant, and AI-governance aligned this early is a differentiator few in the space can match and take as seriously as we do.
Built by security and compliance veterans
Ultra is built by a team that has spent its careers in security, compliance, and AI engineering. Security and compliance leaders who have worked at Coalfire, Secureframe, KPMG, and Schellman team up with engineers who built distributed systems and fintech infrastructure at AWS and Stripe and AI systems across Vanta, ZenBusiness, and Trustpage. It is a team that has shipped trust, compliance, and security products before, now focused entirely on securing MCP and the agents built on top of it.
Ultra is backed by $10M+ in seed funding from incredible investors including Ludlow Ventures, Entrée Capital, Detroit Venture Partners, Firedrop, Hidden Capital, and FDVC, along with angels from Vanta, Secureframe, and the broader security and SaaS community.
Where this is going
We think we are close to the start of something big. Within a few years, working alongside AI agents will be as ordinary as sending an email or opening a spreadsheet. Within ten years, agents will be actively present in our homes and on all of our devices. Agents will help build products, run operations, and make decisions, with real access to real systems with real impact. That future is only safe if there is a security layer built for it, and building that layer is the entire reason Ultra exists.
None of it happens alone. Thank you to the investors who backed this conviction early, to the design partners and first users who pointed Ultra at their own agents and told us what was important to them, to the security community who share our vision, and to the team shipping this every day. You are the foundation this is built on, you are a key part of our future, and you are why we are confident about what comes next.
The agentic era is here, and it will only accelerate. Ultra is how people and organizations act securely in this next era.
Get started
Ultra installs in seconds and works with the agents and MCP servers your team already uses, so you can get started today and ship your first guardrail in minutes. Pricing is refreshingly simple: you pay for security, not seats, with transparent plans that scale from a single developer to a regulated enterprise.
- Free. For individuals, open-source maintainers, and teams evaluating Ultra.
- Pay as you go. For teams running agents in development and production.
- Enterprise. For regulated industries and high-volume deployments.
An action is a single MCP tool call. Reads, writes, and blocked calls all count the same, retries inside 60 seconds are free, and guardrail complexity is never metered. Ultra cost typically lands around 1 to 3 percent of your LLM spend. See the pricing page for the full breakdown.
When autonomy acts, Ultra secures. The easy and secure way for everyone to use agents and MCP. Your agents are already taking action, so start securing them. Get started today.