Bundles
Grouped policies you can attach together on one gateway: compliance-framework bundles that support SOC 2, HIPAA, PCI DSS, GDPR/CCPA and SOX controls on the MCP path, and use-case bundles for CRM, Atlassian and messaging surfaces.
A bundle is a curated starting posture, not a single policy: attach it to cover a surface, then tune. Framework bundles group policies by the control they support and are candid about the boundary — they act on agent traffic through the gateway only, and no bundle makes an organization compliant on its own.
Compliance frameworks
SOC 2SOC 2 is not a law and not a data type — it is an attestation framework.HIPAAHIPAA governs how covered entities and their business associates use, disclose, and safeguard protected health information (PHI/ePHI) — the Privacy Rule (45…PCI DSSThe Payment Card Industry Data Security Standard (PCI DSS) v4.0.GDPR / CCPAThe General Data Protection Regulation (Regulation (EU) 2016/679) governs any processing of EU personal data; the California Consumer Privacy Act, as amended…SOXThe Sarbanes-Oxley Act of 2002 governs U.S. public companies and their auditors.
Use cases
CRMA curated bundle of policies for CRM MCP servers.AtlassianA curated bundle of policies for Atlassian MCP servers (JIRA today; Confluence and Bitbucket planned).SlackA curated bundle of policies for Slack MCP servers.IM messagingA curated bundle of policies for instant-messaging MCP servers (Slack today; Microsoft Teams and Discord planned).