Compatible with every major AI agent and IDE
What is the Pangea (Security APIs) MCP Server?
Integrate Pangea into your AI workflows to provide a robust security layer for LLM interactions and organizational data. This server provides a unified interface to Pangea's cloud-native security services.
Key Capabilities
- AI Security & Guarding — Use
ai_guard_textandai_guard_promptto detect prompt injections, PII, and malicious content before they reach your model or user. - Data Privacy — Automatically redact sensitive information from plain text or structured JSON objects using
redact_textandredact_structured. - Secure Auditing — Maintain a tamper-proof record of activities with
audit_logand perform natural language searches through your security history viaaudit_search. - Threat Intelligence — Check for embargoed locations with
embargo_ip_checkand scan files for threats withsanitize_file. - Identity & Access — Manage authentication flows, user sessions, and authorization tuples directly from your agent.
How it works
- Subscribe to this server
- Enter your Pangea Token and Domain from the Pangea Console
- Start securing your AI agents in Claude, Cursor, or any MCP-compatible client
Who is this for?
- Security Engineers — Automate audit log analysis and threat intelligence checks within your existing tools.
- AI Developers — Implement safety rails and PII redaction for LLM inputs and outputs without building custom middleware.
- Compliance Officers — Quickly search and verify audit trails using natural language queries.
Built-in capabilities (40)
Analyze and redact content in LLM inputs/outputs
Scan text for PII, malicious content, and prompt injections
Guard LLM chat completions with integrated logging and tracing
Create a single secure audit log entry
Create multiple secure audit log entries
Search the audit log using natural language queries
Paginate through audit search results
Finalize the flow and receive session tokens
Start a sign-up or sign-in flow
Update flow state (e.g., submit password, OTP)
List active user sessions
Invalidate sessions
Programmatically create a user
Check if a subject has permission for an action on a resource
List all resources a subject can access
Define relationships for AuthZ
Get WHOIS details for a domain
Check if an IP originates from an embargoed country
Check a 2-character ISO country code against embargo lists
Scan a file for malware
Retrieve reputation scores for domains, URLs, or file hashes
Retrieve location data for an IP
Detect if an IP is a proxy
Get reputation score and verdict for an IP
Detect if an IP is a VPN
Check if a password hash prefix appears in breach data
Redact specific fields in a JSON object using JSONPath
Redact sensitive data from plain text
Apply sanitization rules to a file and receive a cleaned version
Delete files or folders
Create folders in Secure Share
Download a file or retrieve metadata
List objects in a bucket or folder with filtering
Decrypt data previously redacted using FPE
Check if an email, phone, or username appears in known data breaches
Perform cryptographic decryption
Perform cryptographic encryption
Retrieve item details or secret values from Vault
Generate symmetric or asymmetric keys in Vault
Store a secret or token in Vault
Why Mastra AI?
Mastra's agent abstraction provides a clean separation between LLM logic and Pangea (Security APIs) tool infrastructure. Connect 40 tools through Vinkius and use Mastra's built-in workflow engine to chain tool calls with conditional logic, retries, and parallel execution. deployable to any Node.js host in one command.
- —
Mastra's agent abstraction provides a clean separation between LLM logic and tool infrastructure. add Pangea (Security APIs) without touching business code
- —
Built-in workflow engine chains MCP tool calls with conditional logic, retries, and parallel execution for complex automation
- —
TypeScript-native: full type inference for every Pangea (Security APIs) tool response with IDE autocomplete and compile-time checks
- —
One-command deployment to any Node.js host. Vercel, Railway, Fly.io, or your own infrastructure
Pangea (Security APIs) in Mastra AI
Pangea (Security APIs) and 4,000+ other MCP servers. One platform. One governance layer.
Teams that connect Pangea (Security APIs) to Mastra AI through Vinkius don't need to source, host, or maintain individual MCP servers. Every tool call runs inside a hardened runtime with credential isolation, DLP, and a signed audit chain.
Raw MCP | Vinkius | |
|---|---|---|
| Server catalog | Find and host yourself | 4,000+ managed |
| Infrastructure | Self-hosted | Sandboxed V8 isolates |
| Credential handling | Plaintext in config | Vault + runtime injection |
| Data loss prevention | None | Configurable DLP policies |
| Kill switch | None | Global instant shutdown |
| Financial circuit breakers | None | Per-server limits + alerts |
| Audit trail | None | Ed25519 signed logs |
| SIEM log streaming | None | Splunk, Datadog, Webhook |
| Honeytokens | None | Canary alerts on leak |
| Custom domains | Not applicable | DNS challenge verified |
| GDPR compliance | Manual effort | Automated purge + export |
Why teams choose Vinkius for Pangea (Security APIs) in Mastra AI
The Pangea (Security APIs) MCP Server runs on Vinkius-managed infrastructure inside AWS — a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts. All 40 tools execute in hardened sandboxes optimized for native MCP execution.
Your AI agents in Mastra AI only access the data you authorize, with DLP that blocks sensitive information from ever reaching the model, kill switch for instant shutdown, and up to 60% token savings. Enterprise-grade infrastructure, zero maintenance.

* Every MCP server runs on Vinkius-managed infrastructure inside AWS - a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts optimized for native MCP execution. See our infrastructure
How Vinkius secures
Pangea (Security APIs) for Mastra AI
Every tool call from Mastra AI to the Pangea (Security APIs) MCP Server is protected by DLP redaction, cryptographic audit chains, V8 sandbox isolation, kill switch, and financial circuit breakers.
Frequently asked questions
How can I protect my LLM from prompt injections or malicious content?
You can use the ai_guard_prompt tool to analyze LLM messages. It scans for prompt injections, PII, and other security risks, providing a safety score and redaction suggestions before the data is processed.
Can I search through my security logs using natural language?
Yes! The audit_search tool allows you to query your secure audit logs using natural language or structured queries, making it easy to find specific events without complex SQL.
How do I automatically redact PII from a block of text?
Use the redact_text tool. Simply provide the text, and Pangea will identify and mask sensitive information like emails, phone numbers, and names based on your configured rules.
How does Mastra AI connect to MCP servers?
Create an MCPClient with the server URL and pass it to your agent. Mastra discovers all tools and makes them available with full TypeScript types.
Can Mastra agents use tools from multiple servers?
Yes. Pass multiple MCP clients to the agent constructor. Mastra merges all tool schemas and the agent can call any tool from any server.
Does Mastra support workflow orchestration?
Yes. Mastra has a built-in workflow engine that lets you chain MCP tool calls with branching logic, error handling, and parallel execution.
createMCPClient not exported
Install: npm install @mastra/mcp
Explore More MCP Servers
View all →
Corsizio
12 toolsSell event tickets and manage class registrations with a lightweight booking platform that handles payments and attendees.

Pipedrive Mail
4 toolsBrowse email threads, read messages, and view deal-linked emails — manage your Pipedrive mail integration through conversation.

Maropost
11 toolsAutomate marketing and commerce via Maropost — manage contacts, campaigns, and workflows.

Couchbase (Vector & NoSQL)
7 toolsManage vector search and NoSQL via Couchbase — execute N1QL queries, perform KNN vector searches, and audit documents directly from any AI agent.
