Protectt.ai launches MCP security solution for BFSI
Thu, 10th Sep 2026 (Today)
Protectt.ai has launched an MCP Security Solution for the BFSI sector, aimed at risks linked to the rise of agentic AI in financial services.
The offering is designed for organisations using AI agents that connect to enterprise tools, internal systems and sensitive data. It is built around a "Scan, Test, Protect" framework that covers both pre-deployment checks and ongoing monitoring once agents are in use.
The launch reflects a broader shift in corporate AI use. Many businesses are moving beyond generative AI systems that answer questions to AI agents that can retrieve information, query databases and carry out actions across software environments.
That shift has created a new security concern around the links between AI agents and external tools. The Model Context Protocol, or MCP, gives agents a standard way to interact with those tools, but each connection can also create openings for attacks or accidental data exposure.
The new product is mapped to the OWASP MCP Top 10 and addresses issues including prompt injection, poisoned tool descriptions, tool squatting, information leakage and software supply-chain weaknesses.
Three stages
In the first stage, Scan, the product analyses MCP server packages, tool definitions and parameter schemas before they are linked to an AI agent. This is intended to detect hidden instructions and altered descriptions that could change an agent's behaviour, while also flagging typosquatted packages and vulnerable dependencies.
The second stage, Test, probes MCP servers before deployment. According to the company, it runs automated attack simulations to identify exploitable weaknesses related to tool squatting, injection and information leakage.
The third stage, Protect, uses an MCP proxy placed between AI agents and external tools. The proxy inspects tool calls and responses in real time, blocks unauthorised tools, removes personally identifiable information and credentials, and creates audit logs that can be exported to security information and event management systems.
The product has been tailored for sectors with strict compliance and data-handling demands, including banking, financial services, insurance and fintech. Those industries have become early adopters of AI systems while also facing heavy scrutiny over customer data, fraud controls and operational resilience.
For financial institutions, the main concern is not only whether an AI model can be manipulated, but whether an agent connected to internal systems can be steered into exposing data or taking unintended action. As firms give AI systems more autonomy, the security focus is moving from the model itself to the full chain of tools, integrations and permissions around it.
Manish Mimani, Co-founder and Chief Executive Officer of Protectt.ai, said the threat picture is changing as AI agents become more deeply connected to operational systems.
"The security conversation around AI has largely focused on the model. But as agentic AI becomes autonomous, it is potentially more exposed to threats when connected to tools and enterprise systems," said Manish Mimani, Co-founder and Chief Executive Officer of Protectt.ai.
He added that companies need to pay closer attention to those risks as adoption grows.
"Organisations must take cognizance of these evolving vulnerabilities as threats evolve. Our full-stack MCP Security Solution plugs this gap by providing unified protection across the agent's lifecycle," Mimani said.
Protectt.ai works with banks, financial institutions and other enterprises on mobile app and AI security. Its platform protects more than 570 mobile apps, covers more than 100 billion sessions and more than 1 billion unique devices, and has prevented more than 8 billion threats.
The group has offices in India, the UAE and the US. Its latest launch places it in a growing market for products aimed at securing how AI agents connect to software tools and enterprise data, rather than focusing only on the underlying model.