An open-source reference implementation a security team can read, fork, and sign — instead of a marketing PDF. Atomic Durable Objects rate limiting, WebAuthn perimeter, SLSA L3 provenance.
01 — Problem
As AI agents and MCP tools start calling edge APIs at scale, banks need a perimeter that survives autonomous traffic without trading away DORA-grade audit evidence. Existing CDNs offer either marketing language or opaque plans — neither produces the reference implementation a security team can read, fork, and sign.
02 — What I built
An open-source, zero-trust MCP gateway with 42 tools, atomic Durable Objects rate limiting, WebAuthn passkey perimeter, signed URLs, and SLSA Level 3 build provenance. 3,185 tests at 100 % coverage, mapped to DORA Article 5, BCBS 239 risk-data aggregation, and Basel III operational risk capital.
By the numbers
- 3,185 tests
- 100 % line, branch, function coverage
- SLSA L3
- Build provenance + Sigstore signing
- 42 MCP tools
- Every call audit-logged with structured evidence
- DORA / BCBS 239
- Mapped to Article 5 + risk-data aggregation
03 — Engineering rigour
Tests
3,185 tests at 100 % line, branch, and function coverage
Supply-chain provenance
SLSA Level 3 build provenance + Sigstore signing
MCP tools shipped
42 tools — every call audit-logged with structured evidence
Rate limiting
Atomic Durable Objects (no race conditions, no double-counts)
Authentication
WebAuthn passkeys + signed URLs
License
Apache-2.0 / MIT
04 — Independently verified
- Featured in the 2026-06-11 article: CloudCDN — An Open-Source Blueprint for the AI-Native Edge
- Mapped to DORA Article 5, BCBS 239, Basel III operational risk