WireCanalby Qualiteg
smart_toy MCP & Generative AI

Connect Claude or ChatGPT to your internal data, safely.

Let AI use your in-house MCP server or database without opening a single inbound port. You choose which tools AI can see, the allowlist stays inside your company, and the relay runs on servers in Japan. "We want AI to use our internal data, but opening the door makes us nervous" — this solves exactly that.

0 inbound ports Per-tool exposure Allowlist stays in-house Relay servers in Japan Verified (Bestllam · Claude · ChatGPT · Grok)
You decide what AI sees! Canalun, the official WireCanal mascot
Challenges

Three hurdles when connecting internal data to AI

Many teams get as far as standing up an MCP server, then stall at "making it reachable from an outside AI". The reasons are usually these three.

door_front

We don't want to open our network

Reaching internal systems from a cloud AI normally means opening an inbound port or setting up a new VPN. Both need heavy sign-off from the network team and take time.

visibility_off

Every tool on the MCP server is exposed

A generic tunnel only passes a port. If your MCP server has 20 tools, all 20 — including delete and update — become visible to the outside AI.

gavel

We can't explain who approved what

If the decision about which tools AI may use lives on the cloud side, it won't pass internal review. The source of truth has to be in-house, and there has to be a record.

How it works

One path: AI → WireCanal → your MCP server

An agent inside your network opens a single outbound tunnel, and WireCanal stands guard in front of it. To the AI it looks like a remote MCP server, but only calls to allowed tools get through.

WireCanal connection diagram: from AI services such as Bestllam and claude.ai, through WireCanal on servers in Japan and an outbound tunnel, to the in-house MCP server and database. Only allowed tools are exposed.
The AI's question travels through the tunnel to your MCP server and real data comes back. No inbound port is opened.
Three boundaries

Decide "who", "what" and "which path" — each one in-house

How safe an AI integration is comes down to whether your company controls these three boundaries. WireCanal keeps all three in your hands.

badge

Who — connection approval and your IdP

Every time an AI connects, it passes WireCanal's approval screen, and only the canal owner can approve. Connect your organization's IdP such as Google Workspace to restrict use to members of an allowed domain.

rule

What — a per-tool allowlist

Default deny. Only allowed tools can be called, and denied tools don't even appear in the list. The allowlist in your local wirecanal.json is the single source of truth and cannot be rewritten from the cloud (two-key).

route

Which path — servers in Japan and a fixed destination

The relay runs on servers in Japan, TLS end to end, and traffic bodies are not stored. The agent never connects anywhere except the configured destination, so the tunnel can't be repurposed as a corridor into your network.

Compare approaches

Build it yourself, a generic tunnel, or WireCanal

Three ways to make an in-house MCP server usable from AI, compared on the entry point, what is visible, who controls permissions, authentication with AI, and effort.

CriteriaBuild it yourself (VPN / reverse proxy)Generic tunnel serviceWireCanal
Entry into your networkRequires opening an inbound port or a new VPN. Network-team sign-off and work.No inbound port (outbound connection).
Tools visible to AIDepends on the MCP server. Narrowing it means modifying the server.Passes a port, so every tool on the MCP server is visible.
Where the allowlist livesIn-house (but the mechanism is home-made).No such mechanism.
Authentication with AI services (OAuth)Run your own authorization server.Provide it yourself.
Restricting users to your organizationImplement IdP integration yourself.No such mechanism.
Record of who used it, when, from whereProvide it yourself.Depends on the service.
Time to deployOften weeks of design, build and review.Short, but everything above still has to be arranged separately.

"Generic tunnel service" describes the general nature of services that expose a port or host to the internet. WireCanal's column matches what is stated on the MCP & AI, Security and Pricing pages.

Three steps. Your existing MCP server stays as it is

1

Create an MCP canal

In the dashboard, choose the "MCP" type and answer "Which AI will use this?". You get a remote MCP server URL (for example https://<hostname>/mcp) and the connection settings for that AI.

2

Place the agent inside and choose the tools to show

Put the agent on the machine running the MCP server (or one on the same network) and list the tools you want to expose under tools.allow in wirecanal.json. Anything not listed is denied and hidden from the list. Install commands are in the Setup Guide.

3

Paste the URL into the AI

Paste the canal URL into a Claude custom connector or a ChatGPT developer-mode connector, and WireCanal's approval screen appears. Once the owner approves, you're connected. Step-by-step guides with real screens: Claude, ChatGPT, Grok.

rocket_launch Start with one canal, free

MCP integration is available from the Free plan

The Free plan has no time limit and includes one canal, MCP integration and all eight access protections. No credit card required. For department- or team-wide use, talk to us about the Enterprise Plan with seat-based licensing and invoice payment.

FAQ

Common questions about MCP and data handling

Does AI connect directly to our internal database?

No. AI connects to your in-house MCP server, and it reaches the database only through that server's tools. WireCanal shows AI only the tools you allow, so what AI can touch is limited to what your company decided.

Does WireCanal store the content of the traffic?

No. WireCanal does not record request or response bodies; it pipes them through as-is over TLS end to end. The per-canal access log records who, when, from where, and the result. Tool-call arguments and results are exchanged between you and the AI service you use.

Which AI services can use it?

Verified with Bestllam, Claude (claude.ai), ChatGPT and Grok. For Claude and ChatGPT you just paste the canal URL and OAuth is configured automatically. Claude Code, Gemini CLI and similar tools can be combined by issuing an access key.

Can the cloud side quietly add tools to the allowlist?

No. The only allowlist that decides which tools are visible is the wirecanal.json file on your own machine. It cannot be rewritten from WireCanal's dashboard or public servers. If the allowlist is empty, every tool starts out denied even after connecting.

Can we limit use to members of our organization?

Yes. Connect your organization's identity provider (IdP) such as Google Workspace, and only members of the allowed domain can use the canal from AI. When an account is disabled, for example when someone leaves, their access stops too. See the organization IdP guide.

How much does it cost?

MCP integration is available on every plan. You can try one canal for free on the Free plan, which has no time limit. For department- or team-wide use, the Enterprise Plan offers seat-based licensing and invoice payment.

No open ports. Connect from anywhere.

Sign-up is free. No credit card required — create your first canal right now.

Sign up free and get started