FlowplaneBook a pilot

One gate for people and their AI agents.

Four products on one European platform: a zero trust tunnel into your network, one MCP endpoint for every agent, memory your agents keep per person, team or company, and a watchtower on the log. Same identity, same policy, same audit log for all of it. For one person, a team, or a company of five hundred. No VPN, no open ports, no US vendor in the path.

for your agentsmcp.flowplane.eu/acmeOAuth 2.1
for your peoplehr.acme.flowplane.euSSO + MFA

That is the whole integration.

Our product
One entryone MCP URL for your agents, one REST API for your code, both with the rights of the person behind it
agents
ClaudeCopilotCursorChatGPTGemini CLIyour own agents
your code
RESTOpenAPI specwebhooksn8nyour scripts
Peopleyou, your team, your company
Entra IDGoogleKeycloakSAMLpasskey
browser, SSO and MFA, no VPN
Flowplaneverifies who, checks policy, writes it down
allowed
Identitywho, on behalf of whom. SSO, MFA, agent bound to a person
PolicyRBAC per tool and per action. Read yes, delete no
Logwritten down, stored in the EU, exportable
Routetunnel or direct. Nothing exposed, no VPN
last decisionwaiting for the first request
Belgian company. EU data centres. No US vendor in the path.
Our product
Memorywhat your agents remember, per company, team or person, under the same rules
Optional add-on
Watchtowerour models read the log and alert on what looks wrong
APIsany API with a spec, theirs
SalesforceHubSpotExactTeamleaderOdooSAPMicrosoft 365
OpenAPI in, governed MCP tools out
MCP serversrun by the vendor, theirs
NotionGitHubSlackAtlassianLinearStripe
remote, with the scopes you set
Inside your networkreached through our zero trust tunnel
PostgresSQL ServerGrafanaWindows RDPOllamavLLMiPhoneAndroid
databases, apps, RDP, local LLMs, your phone
Zero trust tunnelour product

Third-party APIs and MCP servers stay theirs. We are the gate, the tunnel into your network, the one endpoint your agents talk to, the memory they keep, and the watchtower on the log.

Two access problems. One question.

Companies treat them as unrelated. The auditor will not. Watch the same request today, and then through the gate.

todaywith FlowplaneSofielaptop, anywhereSSO and MFAVPNlogin, then inFlowplaneverifies who, MFAchecks policy, logs itflat network, once ininside your networkIntranet, HR portalWindows RDP3389 open3389 closedPostgresfile shares, all of itnot for SofieNOTHING LOGGEDALLOWEDlogged: sofie → hr-portal

People

Staff, partners and contractors need the intranet, the HR portal, Grafana, a Windows server over RDP, a database. Today that's a VPN, an open port, or a US cloud that sees every request. The VPN is a flat network once you're in. The open port is a breach waiting to happen. NIS2 now says: MFA in front of everything, and a log of who got in. Behind the gate, Sofie reaches the one app she may use, the port is closed, and the access is written down.

todaywith FlowplaneClaudeagent for JanAPI tokenpasted in configmcp.flowplane.euOAuth 2.1, as Janper tool, per actionrights:everything Jan hasSalesforceall accountsread onlyMicrosoft 365mail, filesmail readThe ERPdelete, toodelete: noWHO READ WHAT?WRITTEN DOWNlogged: claude for jan → read

AI

The same companies are wiring Claude, Copilot, Cursor and their own agents to Salesforce, Microsoft 365, Notion, Postgres, the ERP. Each connection is a token somebody pasted into a config, with whatever rights that person had. Afterwards nobody can say which agent read which record. The AI Act, and the same NIS2 auditor, will ask exactly that. Behind the gate, the agent acts as Jan, reads what Jan may read, is refused the delete, and every call is in the log.

Both are the same question: who is asking, on behalf of whom, for what, and is that allowed right now? Nobody in Europe answers it once, for both.

Four products. One platform under them.

Your apps, tools and data stay where they are and stay yours. We are the gate in front, the tunnel into your network, the endpoint your agents talk to, the memory they keep, and the watchtower on the log.

PeopleAgentsFlowplane edgeEU, Belgiuminside your networkconnectordials outNO OPEN PORTSHR portalWindows RDPPostgresOllama
Product

Zero trust tunnel

One small connector inside your network dials out to our EU edge. From that moment your intranet, HR portal, Grafana, a Windows server, Postgres, your self-hosted MCP servers and the Ollama box in the rack are reachable by the people and agents you allow, without a single inbound port. The VPN goes. The open RDP port goes.

Connectorone binary or container, outbound only, no firewall change
Reachesweb apps through an identity-aware proxy; RDP, SSH and databases over TCP; self-hosted MCP servers; local models such as Ollama and vLLM
Identityyours: Entra ID, Google, Keycloak, SAML or a passkey, with MFA, device and group checks set per app
Foryou, your team or your staff in a browser, and AI agents through the unified MCP endpoint
ClaudeCopilotCursormcp.flowplane.eu/acmeone URL, OAuth 2.1acting as jan@acme.beNotion MCPERP APIfrom its specPostgresbehind the tunnelteam vaultREADDELETEper tool, per action, every call logged
Product

Unified MCP endpoint

Claude, Copilot, Cursor or the agents you build get one URL. Behind it: every tool and data source you allow, from Notion's MCP server to your ERP's REST API to the database behind the tunnel. The agent always acts as the person it works for, and never gets more than that person has.

ProtocolMCP over HTTP with OAuth 2.1; the agent's identity is bound to a real user
Policyper tool and per action: read yes, write for some, delete for nobody
Sourcesremote MCP servers, any API with an OpenAPI spec, the MCP servers we build and run for you, the memory your agents keep per company, team or person, your phone's data through the Flowplane app, and everything inside your network via the tunnel
Modelsany. Sovereign EU models with zero retention by default, or bring your own: Ollama or vLLM on your hardware, Mistral, a US provider if you must
agent:opsfor louis@acme.becompany memory, acme.beteam vault, ops12 peoplepersonal vault, louisonly louis and agents acting for himper tool callscratch space, wiped when the call endsREAD WRITE
Product

Memory

Agents that remember across sessions, without a token in a config and without a vector database somebody has to secure. Every memory lives in a scope: the company, a team, one person, or a single tool call. An agent reads and writes with the rights of the person behind it, and the log records every access like any other.

Scopescompany memory, team vaults, personal vaults, and a scratch space per tool call that is wiped when the call ends
Rightsan agent sees exactly what its person may see; leave the team and the team vault is gone for you and your agents
Storageencrypted, in the EU, exportable and deletable per scope, retention you set
Forany agent on the unified endpoint, and your own code through the unified API
audit logevery login, every tool call09:41 sales-assistant read09:42 jan hr-portal09:50 read 4,120 rows09:51 cursor github list09:52 n8n invoices listWatchtowerour own modelsrun in the EUread the log where it livessecurity@acme.beSlack #securitySUSPICIOUSoff by default. The log never leaves the EU to be read.
Product

Watchtower

The log is only useful if someone reads it. Switch on the Watchtower and our own models read it as it grows, learn what is normal for each person and each agent, and alert you when something is not: an agent reading four thousand records in nine minutes, a login from a device nobody registered, a tool that suddenly writes where it only ever read.

Readsthe audit log as it grows, nothing else. Arguments stay hashed.
Modelsour own, run in the EU on our own infrastructure. Nothing goes to a third party.
Alertsmail, Slack or a webhook, with the record attached and a one-line reason
Defaultoff. When on, the log is read where it lives and never leaves the EU.

Under both

Identity brokerBrokers the identity provider you already have. Never becomes the source of your users.
Policy engineOne set of rules for people and machines: who, on behalf of whom, what, allowed right now.
Audit logWho, what, arguments hashed, decision, policy. Stored in the EU, exportable for the auditor.
ConsoleOne console for every app, agent, policy and log. A first app and a first agent take an afternoon.

Hand us an API spec. Get governed MCP tools.

Most business software in Belgium and the Netherlands will never ship an MCP server. It doesn't have to.

Upload the OpenAPI spec of your ERP, your practice software or your own API. Every operation becomes one MCP tool on your unified endpoint, under the same policy and in the same log as everything else. Nobody writes a connector.

erp-invoices.yamlOpenAPI 3.1, as published by your ERP vendor
Flowplanepolicy, log
tools on your endpointas agent:finance for an@acme.be
GET/invoices
invoices.listFinance group only
readallowed
POST/invoices
invoices.createtwo named finance staff
writeallowed
GET/invoices/{id}
invoices.getinvoice id hashed in the log
readallowed
DELETE/invoices/{id}
invoices.deleteno agent, ever
deletedenied
one operation in, one tool out
read yes, write for some, delete for nobody. Every call written down.

One log for people and machines. And something watching it.

An agent working for Jan gets Jan's rights and nothing more. A colleague without MFA does not get in. Both land in the same log, with the reason, exportable in a form your NIS2 or ISO auditor accepts. Switch on the Watchtower and our own models read that log as it grows, flag what looks wrong and alert you. They run in the EU, on our own infrastructure.

exported record1 of 41,207 this quarter
time
2026-09-14 09:41:07 UTC
principal
agent:sales-assistant
on behalf of
jan.peeters@acme.be
target
postgres.customers
action
read
arguments
sha256 9f3c2b71…41e2 never stored in clear
decision
allowed
policy
pol-017 sales agents may read customers, not write
stored in
eu-west, Belgium retained 24 months
The same record exists for every person's login and every agent's tool call.
watchtower alert, optional2 this quarter
time
2026-09-14 09:50:12 UTC
principal
agent:sales-assistant for jan.peeters@acme.be
pattern
4,120 customer records read in 9 minutes usual: about 30 a day
signal
suspicious
alerted
security@acme.be and Slack #security, 09:50:14
model
Flowplane Watchtower our own models, run in the EU
Off by default. When on, the log is read where it lives. It never leaves the EU.
Whoa user, or an agent on behalf of a user
Whatthe app or tool, the action, the arguments, hashed
Decisionallow or deny, and the policy that decided
Wherestored in the EU, never anywhere else
Watchtoweroptional: our models read the log and alert on what looks wrong

The alternatives do half of it, or do it from the other side of the ocean.

US zero trust vendorsSelf-hosted MCP gatewaysFlowplane
Access for people without a VPNYesNoYes
Access for AI agentsSeparate product, or noneYes, for engineering teamsYes, under the same policy as people
One policy and one log for bothNoNoYes
Data and logs stay in the EUUS parent, US subprocessorsWherever you host itBelgian company, EU only
Any REST API as governed MCP toolsNoSome, hand-builtUpload a spec
Memory per person, team and companyNoBring your own storeBuilt in, same policy and log
Anomaly watch on the audit logExport to a SIEMNoOptional, EU-hosted models
Runs without a platform teamEnterprise-firstYou operate itManaged, set up in an afternoon

We run the controls we sell.

Belgian company, EU data centres, no US parent or subprocessor in the path. Every control we ask you to pass, we pass first.

we are here
  1. In place

    GDPR processor agreement

    Signed with every pilot, from day one. EU staff, EU infrastructure, and a subprocessor list you can read in one minute.

  2. In progress

    CyberFundamentals Important

    The Belgian conformity path for NIS2: MFA everywhere, least privilege, segmented management, tested backups, incident procedure. Complete before we invoice the first customer.

CompanyBelgian BV, bootstrapped, no US parent
HostingEU data centres only. Data and logs never leave the Union.
SubprocessorsEU only, named in the processor agreement
Scopean access layer and nothing else: no CDN, no chat product, no model hosting of our own. Small enough to certify and to explain to an auditor in one meeting.

Free for one person. Fair for a company.

Companies pay only for active users, the people who signed in that month. Every connector and every agent is included.

PersonalFor you and your agents
Free
  • Three connectors, one may be a tunnel
  • Five agents, passkey login
  • Memory: 1 GB, log: 30 days
  • Shared address, 60 requests a minute
Read Victor’s post
Personal ProFor builders and power users
€4a month
  • Unlimited connectors and agents
  • Your own tunnel, no shared limits
  • Memory: 10 GB, log: 12 months
Ask for early access
CompanyOnly active users count
€99a month for ten active users
  • Then €9, €7 and €5 per active user
  • Every connector and agent included
  • Your own EU IP addresses, no throttling
  • SSO, device checks, 100 GB company memory
  • 24-month log, auditor export, SLA
Read the Acme case

What would your company pay?

Only active users count. A company of 300 where 120 people signed in this month pays for 120.

€1,049a month€10,490 a year paid up front · about €8.74 per active user
first 10
€99 flat
11 to 100
€9 each
101 to 500
€7 each
501 to 2,000
€5 each
above 2,000
custom

Each rate applies only inside its bracket, so there is no jump at 100 or 500.

MemoryIn every plan. More storage is €5 per 10 GB a month.
WatchtowerOptional. About a quarter on top of your plan.
MCP servers built for youCompany-specific software with no MCP server? We build and run one for you, under the same rules and in the same log. Quoted per project.Talk to us

Transparency

Only active users count

Anyone who signed in that month. Agents, service accounts and shared mailboxes never count.

What is included

20,000 tool calls and 20 GB of tunnel traffic per active user a month, pooled across the company.

Beyond the pool

€1 per 100,000 calls and €0.02 per GB. We alert you first and never cut you off.

Runaway agents

An agent making ten times its usual calls is paused, and you get an alert.

Your own address

Paid plans get their own EU IP to allowlist anywhere. What a provider allows through it is up to you.

Fair use

One named person per login. The tunnel is for access, not for backups or media.

Prices without VAT. Monthly, cancel any time, or pay a year up front and get two months free. Indicative while we run the first pilots. Building a product on top of Flowplane? Talk to us.

Start with one app and one agent.

One app behind the tunnel for your people, or just for you. One agent on the unified MCP endpoint. An afternoon to set up, three months to prove. We do the setup with you.

Free for one person, €4 a month for Pro. Companies pay from €99 a month, only for active users, with every connector and agent included.