The product · shipping today

One airlock connector.
For every AI client and agent.

Link Notion, GitHub, Slack or any MCP / API you can name, once. Set policy, package Agents and Skills, accumulate organization memory, audit every action. Expose to your preferred AI client.

●control-room.air-lock.ai / mcps
Approval requested
github.delete_branch
from Cursor · waiting on the engineering lead
ApproveDeny
Skill versioned
pii-redactor · v3
verified · attached to 3 agents
1.000+ connectors
EU-hosted · Frankfurt
Organization memory

Claude Desktop

Remote HTTP

Add airlock as a custom connector by URL.

https://mcp.air-lock.ai/org/your-org-slug
  1. Open Settings → Connectors.
  2. Click the + next to Connectors, then Add custom connector.
  3. Paste the URL above and click Add.
  4. Complete the sign-in in the browser when prompted.

Governed once. Wherever the work happens.

Every AI client your team uses talks to airlock: Claude, ChatGPT, Cursor, Copilot, Gemini, Claude Code and many others. Switch or add a client and nothing re-onboards.

  • Cross-vendor skills and agents: ship once, every connected client picks it up, including the ones that do not enforce Skills natively.
  • Credential vault: zero-trust. Agents never see your real API keys.
  • No lock-in: change vendors without losing setup, audit history, or memory.

Discovered on demand. Approved in the flow.

A real prompt through airlock inside Claude Desktop: connector added from the +  menu, tools discovered when the model asks for them, approval requested before any write.

Three honest steps. No hyperbole.

airlock is a connector, not a black box. Here's exactly what you do.

01 / Connect

Pick a connector or bring your own.

1.000+ connectors in the catalog. Anything missing? Upload an OpenAPI spec and airlock generates the MCP server. OAuth handled where supported.

02 / Configure

Set per-tool policy.

Tag tools Read-only or Destructive. Route writes for approval to Slack, Teams, or the Control Room. Set rate limits per team or key.

03 / Operate

Every action lands in the log.

Watch real-time analytics, roll back Skills, kill switch per server, export EU AI Act evidence on demand.

Start free →Team pricing →

Package your expertise. Ship it everywhere.

Your best agents live as pasted prompts. airlock turns them into versioned, verified objects. Build once, ship to every team, every client, every tool.

  • Governed objects, not prompt snippets: Agents and Skills sit in the library, not in someone’s Notion page.
  • Versioned + verified: diff, roll back, attest. Auto-injected into every connected client, no manual prompt work.
  • Fork + lineage: branch an Agent for a client engagement, trace every version’s origin.

One memory across every tool.

Entities, decisions, and context accumulate in airlock, not trapped in any single vendor. What you tell ChatGPT is what Claude Code sees tomorrow.

Entity graph, not chat log

Queryable as structure.

People, projects, decisions, accounts and the relationships between them, searchable and governed. One memory across Claude, ChatGPT, Cursor and Copilot. Distinct from conversation-log memories that sit at the chat layer.

Compounds with use

Survives tool churn and team rotation.

New hires inherit context. Client engagements carry forward without re-briefing. Nothing is trapped in a vendor account someone forgot to hand over.

Every action logged. Every action attributable.

Procurement-grade record of what every agent did, not just what was said. airlock sits on the action surface across vendors, so the audit log is cross-vendor by construction. The evidence trail an auditor signs off on, generated as you operate.

  • Every action, every vendor: tool call, approval, Skill invocation, stamped with the policy rule that allowed (or denied) it. A2A calls across heterogeneous runtimes included.
  • EU AI Act evidence pack: cross-vendor, article-mapped, exportable. EU-hosted on AWS Frankfurt. GDPR-aligned. ISO 27001 in progress.
  • SIEM-exportable and queryable from day one. Per-engagement scopes for consultancies available as an Enterprise engagement.

A route, not a roadblock.

Safe actions pre-approved. Destructive ones queued to the human who owns them, where they already work: Slack, Teams, or the Control Room.

  • Set rules once: tag tools read-only or destructive, route writes for approval, define who signs off on what.
  • Approvals where people already work: Slack, Teams, or the Control Room. No tickets.
  • Anomaly detection + kill switch per MCP server.

No engineers required. Not for the setup, not for the run.

An operations manager or an AI practice lead sets up a new integration in an afternoon. No pull request, no ticket, no waiting for a platform team.

Bring any API

From an OpenAPI spec to a governed tool.

Drop in an OpenAPI YAML or JSON. airlock generates the MCP server, surfaces the tools, routes auth through the vault, and applies per-tool policy from the moment it goes live.

Governance without a bench

Written by the person closest to the work.

Policies, approvals, and Skills are edited in the Control Room by the same people who know how the work is actually done. The engineering team is not the bottleneck, because it is not on the path.