42Crunch announced the general availability of MCP Security Governance on 23 September 2026. The company says the product discovers Model Context Protocol servers across an enterprise, scores exposure, maps findings to AI regulatory frameworks and tests MCP servers against agent-facing threats.
This is a security story because MCP servers increasingly sit between agents and business systems. They can expose APIs, databases, internal tools and files to model-driven workflows. If an organization cannot see which MCP servers exist, who owns them, what data they expose and what controls they enforce, it cannot prove that agent access is governed.
The launch is vendor-sourced, so claims about discovery coverage, scoring accuracy, regulatory mapping and attack testing should be validated in each buyer environment. The broader MCP risk is independently supported by the OWASP MCP Top 10, which identifies token exposure, scope creep, tool poisoning, command injection, weak authorization, audit gaps and shadow MCP servers as major concerns.
What 42Crunch launched
42Crunch says MCP Security Governance provides continuous discovery of MCP servers, including shadow deployments, internal servers and external agent-facing servers. It also says the product maps discovered servers to frameworks such as the EU AI Act, ISO 42001, NIST AI RMF, CSA AICM and OWASP MCP Top 10.
That framing is important. Many teams are still treating MCP as a developer integration detail. In practice, an MCP server can become an authorization and evidence boundary. It defines which tools an agent can call, what context it receives, what secrets it might touch and which logs exist after an action.
Why exposure evidence matters
Security teams are used to inventories of endpoints, identities, APIs and cloud assets. MCP adds another inventory problem: model-facing tool servers that may be created by developers, installed from open-source packages or connected to systems the security team does not normally inspect.
OWASP's MCP Top 10 describes this problem directly. Shadow MCP servers operate outside formal governance. Lack of audit and telemetry makes investigation difficult. Weak authentication and authorization can expose critical action paths. Those risks are not theoretical once an agent can call tools with inherited user access or long-lived tokens.
The Maetra guide to discovering AI agents applies here because MCP governance starts with knowing what exists. Discovery should capture server owner, repository, data reach, authentication method, permitted tools, connected agents, last review and evidence freshness.
What buyers should test
An MCP security product should be tested against real estate, not a demo server. Buyers should verify whether discovery finds local developer servers, containerized deployments, private repositories, internal hosts and externally exposed servers. They should also inspect how the score is calculated and whether the evidence can be exported for compliance review.
Regulatory mapping needs special caution. A dashboard can map findings to frameworks, but it cannot prove compliance by itself. Teams still need a control owner, business context, risk acceptance path, remediation evidence and periodic review. The Maetra AI audit evidence guide is useful because it separates a finding from the evidence that a control actually worked.
Maetra analysis
42Crunch is right to place MCP servers in the AI governance record. The server is not just plumbing. It is where agent intent turns into reachable tools and data. That makes it a natural place to ask security questions: is the server approved, is access scoped, are calls logged, are secrets protected, and can compliance teams show the current state?
The remaining caveat is evidence quality. A useful MCP governance layer should do more than list servers. It should connect each server to agent inventory, task scope, authorization rules, tool-call telemetry, risk decisions and remediation status. Without that, teams may have a new dashboard but still lack a defensible record of what their agents can do.