The identity-native control plane for agent↔tool (MCP) traffic. Every MCP server runs on a private WireGuard mesh — zero open ports — behind an agent firewall: tamper-evident signed audit, policy learned from behavior, identity-gated secrets, and audited cross-org federation. One static Go binary.