When AI agents can act inside internal systems, governance becomes an infrastructure problem: knowing which connections exist, what they can touch, and what they did. For a regulated business, those answers also matter for audit and oversight.
MoonPay met that problem early. The payments platform moves funds between fiat and digital assets for more than 30 million customers and 900+ partner businesses, and adopting AI across the company could not come at the cost of their security controls.
Securing the AI rollout
As MoonPay employees began integrating AI into their work, the security team started with browser-level controls, the conventional approach to governing AI use. But AI quickly moved beyond the browser. Employees were connecting assistants directly to internal systems, including messaging platforms, productivity suites, email, and calendars, through MCP-based connectors. Through those connectors, agents could do more than retrieve information. They could act inside sensitive systems, sending messages, editing documents, and changing records. And once a connector was approved for a single use case, visibility often ended there.
“The browser-based approach we relied on just doesn't see this layer anymore.” - Thierry Dang, Security Operations at MoonPay
The security team had no reliable inventory of which MCP servers employees were running, and no audit trail of what agents were doing through them. The tools themselves were sanctioned, but they could make connections nobody was tracking.
Closing that gap meant finding a governance layer that could sit between every agent and the systems it touched. MoonPay’s security team went to market with a specific set of requirements:
- Visibility first. Full visibility into AI tool and MCP usage, with detection and active response layered on top.
- Cross-agent coverage. One platform spanning Claude (both Code and the desktop Cowork experience), Codex, Cursor, and Gemini.
- Active enforcement. The ability to block unsanctioned shadow MCP servers at the point of use.
And everything had to work in production immediately.
MoonPay evaluated Speakeasy, an AAIF member, against those requirements. The Speakeasy AI control plane went through a 30-day proof of concept against MoonPay’s real AI agents, with success criteria written up front. The criteria covered technical compatibility across developer and desktop AI tools, accurate detection of PII, cardholder data, and PHI, and enforcement of MCP policies. They also required SSO and RBAC integration through the company’s identity provider and an exportable audit trail that could feed into the organization’s SIEM.
SSO went live, custom MCP servers to key workplace systems were brought under a centralized control plane, and audit logs began recording tool calls, users, prompts, and results handled through the control plane. Within weeks, MoonPay had visibility into AI agent sessions across every AI tool employees were using, and most employees barely noticed the change.
A cross-agent control plane
The Speakeasy control plane brought agent usage into one place, in line with a visibility-first, then-control approach.
- Connect everything, safely. An MCP gateway brokers every MCP connection using OAuth 2.1 with PKCE, tied into MoonPay's existing identity provider. Role-based permissions are scoped per server, per tool, and per team. Client registration started on DCR. When the MCP specification deprecated DCR in favor of Client ID Metadata Documents (CIMD), the deployment moved with the spec, and nobody at MoonPay had to plan the migration or even notice it. CIMD gives each AI client a durable, verifiable identity, which MoonPay uses to allowlist approved clients. Speakeasy keeps unsanctioned MCP servers blocked by default.
- Observe agent sessions. Session observability across all the AI tools MoonPay uses made it possible to see who used which tool, what they asked, what the agent did, and what it returned, with risk activities exported to the company’s SIEM for investigation.
- Enforce in real time. Policy-based detection for PII, cardholder data, secrets, prompt injection, and destructive commands, with the option to start in log-only mode to understand the environment before turning on blocking.
The coverage matched the AI tools employees were already using, including desktop chat applications and AI coding tools. That meant a single control point could span both technical and operational workflows, making secure AI deployment across the company a practical possibility.
Live across the whole org
What began as a proof of concept turned into a full production deployment across the company in a single rollout. Observability was extended into the AI tools employees were already using, while the security team brought multiple custom MCP servers behind the control plane and deployed them organization-wide. To date, MoonPay’s deployment has brought 200+ MCP servers under governance and covered 60,000+ agent sessions across 5,000+ brokered MCP connections.
Because the control plane sat behind the company’s existing identity infrastructure and did not change day-to-day workflows, it became MoonPay’s standard path for connecting AI tools to internal systems, and the security team moved from proof of concept to company-wide deployment without a disruptive migration.
Lessons for other teams
MoonPay’s path holds a few lessons for teams facing similar MCP and AI governance questions.
- Protocol-level controls can close gaps left by browser-only governance. For MoonPay, MCP provided a shared control point for agent connections to internal systems.
- Get visibility before enforcement. Starting in log-only mode can help build an accurate picture of legitimate usage before blocking is enabled.
- Anchor access in the identity provider you already have. SSO and RBAC scoped per server, per tool, and per team meant governance inherited the access model the company already trusted.
- MCP can provide a common control point across compatible clients. In MoonPay’s deployment, the same governance approach could be applied across Claude, Cursor, Codex, and Gemini because each was connected through MCP.
What’s next
MoonPay’s AI governance footprint continues to expand. The next phase is focused on broadening its library of custom connectors to cover more business needs, extend monitoring as additional AI tools are adopted, and implement detection and response policies on top of the observability layer already established. At the same time, internal demand for team-level sharing of skills and practices points to a broader maturation of AI use across the company.
MoonPay's deployment of Speakeasy shows that protocol-level controls can extend a regulated company's existing identity, policy, and audit practices to its AI workflows.
Share
Authors

Speakeasy
Speakeasy is the AI control plane for securely scaling AI. It gives enterprises visibility, security, and governance over every agent action inside an organization.

MoonPay
MoonPay is a financial technology company that simplifies access to buying, selling, and trading crypto using everyday payment methods, serving nearly 30 million customers across 180 countries.




