Tool review · Checked against vendor sites, September 2026
Lasso Security review (2026): MCP gateway and coding-assistant controls
The verdict
Lasso Security is the pick for teams that want to route MCP traffic through a gateway, including an open-source one, and inspect each Claude Code tool call through the agent's own hooks. Its device-level inventory is less detailed than endpoint-first tools, and it has several components to deploy.
What does Lasso Security do?
- Open-source MCP gateway; discovers MCP servers connected across Claude, Cursor and Windsurf; controls which users and teams can connect to which MCP servers; actions block, alert or sanitize.
- For AI coding assistants, connects to Claude Code's lifecycle hooks through the enterprise management platform and inspects every tool call before it is executed; detects injected instructions in files, web responses and MCP outputs.
- AI usage control: monitors browser chatbots and local desktop agents, masks sensitive data before prompts reach third-party models, applies role-based permissions and DLP.
- Discovery and AI-BOM, AI-SPM, automated red teaming, runtime enforcement at the proxy, API or AI gateway layer, and AIDR.
- Keeps a history of inputs, policy decisions and enforcement actions for audit reports.
Source: lasso.security · Lasso MCP security · Lasso AI coding assistants · Lasso AI usage control · Reviewed Sep 2026
How does Lasso Security deploy?
Lasso offers a browser extension, proxy integrations, its MCP gateway and Claude Code hook integration, and says it works with existing stacks such as Palo Alto Networks or CrowdStrike.
Source: lasso.security · Lasso MCP security · Lasso AI coding assistants · Lasso AI usage control · Reviewed Sep 2026
How does Lasso Security score?
Discovers MCP servers across Claude, Cursor and Windsurf and AI tool use; device-level inventory is not detailed.
Inspects every tool call before it is executed through Claude Code lifecycle hooks; open-source MCP gateway with block, alert or sanitize.
Intent-aware policies, role-based permissions and DLP with masking.
Detailed audit history of inputs and decisions; agent vs human attribution not described.
Browser extension, proxy, gateway and Claude Code enterprise hooks; several components to run.
AI apps, agents, red teaming and usage control.
Pricing and company backing not published on the pages we reviewed.
Where is Lasso Security strongest?
- Concrete tool-call inspection for Claude Code.
- Open-source MCP gateway.
- Audit-ready records of policy decisions.
What should buyers check before choosing Lasso Security?
- Endpoint inventory of agents and credentials is not described in detail.
- Several components to run.
- Pricing and company backing are not published on the pages we reviewed.
Who should shortlist Lasso Security?
Shortlist Lasso Security if your developers standardize on Claude Code and you want MCP traffic to pass through a gateway you control.
What does Lasso Security cost?
Contact sales. Pricing is not published.
Frequently asked questions
Is Lasso's MCP gateway open source?
Lasso describes it as an open-source MCP gateway.
Related
Head to head
Sources
- lasso.security · Reviewed Sep 2026
- Lasso MCP security · Reviewed Sep 2026
- Lasso AI coding assistants · Reviewed Sep 2026
- Lasso AI usage control · Reviewed Sep 2026