JetStream launches a verified MCP catalog to tame the agent tool supply chain
The MCP registry is past 6,000 servers and the stateless spec lands July 28. The unsolved problem is trusting a third-party server, and this is an app-store-style answer.
- JetStream Security launched a Verified MCP catalog and an AI Hub, giving enterprises one place to verify and govern MCP and model traffic through a common control point.
- The catalog offers the broad third-party MCP ecosystem alongside more than 100 JetStream Verified server images that are analyzed, hardened, and cryptographically attested before an agent can call them.
- The AI Hub authenticates, authorizes, and inspects every MCP and model call, discovers shadow MCP servers running outside oversight, and maps approved servers to sanctioned agents.
As the MCP ecosystem crosses into app-store scale, someone had to build the trust layer. JetStream Security launched two integrated offerings, a Verified MCP catalog and an AI Hub, per the launch coverage, giving enterprises a single control point to verify and govern the tools their agents call.
Attested images and a runtime broker
The catalog offers access to the broad third-party MCP ecosystem alongside more than 100 "JetStream Verified" server images that are analyzed, hardened, and cryptographically attested before an agent can invoke them, with semantic scanning for risks like credential leakage, unicode smuggling, and obfuscated malware. The AI Hub is the runtime half: it authenticates, authorizes, enforces policy, and inspects content before and after every MCP and model call, discovers "shadow" MCP servers running outside central oversight, and maps approved servers to sanctioned agents with tool-level access controls. As co-founder and CTO AJ Anand put it, a server directory without inspection "is not a control." JetStream, founded by veterans of CrowdStrike, Wiz, and SentinelOne, emerged in March with a $34 million seed.
The supply chain is the next battleground
The timing is not subtle. The official MCP registry is past 6,000 servers, and the stateless spec lands July 28, which makes servers easier to run at scale but does nothing to make a random third-party server trustworthy. That is the gap: an agent that will call any tool in a catalog is one squatted or poisoned server away from an incident, exactly the attack surface documented in HalluSquatting and Ghostcommit. JetStream's verified-images-plus-broker model is a different answer than a network gateway or an identity layer, and the fact that three of them shipped inside a week says the market has decided the tool supply chain, not the model, is where agent security gets won or lost.