Cedar policies

Policy Enforcement and Tamper-Evident Audit Chains | ​Imran Siddique | MCP Release Party - Seattle

Policy Enforcement and Tamper-Evident Audit Chains | ​Imran Siddique | MCP Release Party - Seattle

Imran Siddique introduces cMCP, an open-source gateway that enhances Modular Control Plane (MCP) servers with policy enforcement and tamper-evident audit trails. It achieves this by running Cedar policy evaluation within Trusted Execution Environments (TEEs), ensuring that agent actions are governed securely and verifiably. The talk delves into the concept of "beyond governance" towards verifiable AI, the 'trace' standard for auditable logging, and the importance of confidential computing for regulated industries.