Share with your CISO
Salt Security is betting that Australian enterprises have a visibility gap in their AI deployments that local data residency requirements make it impossible to close with an offshore vendor. The company has stood up infrastructure in AWS’s Sydney region (ap-southeast-2) and hired an in-country sales and technical team, formalizing customer relationships it had already built through its global network. The platform targets agentic AI security, mapping the connections between AI agents, MCP servers, and enterprise APIs to give security teams audit trails and behavioral monitoring.
What this means for your business
The detail Salt’s CEO dropped is the one worth sitting with: organizations with significant MCP server deployments they didn’t know existed, and AI agents operating with access nobody reviewed. If that sentence describes your environment, you’re not in a niche situation. The recurring failure mode in enterprise AI adoption is that developer and line-of-business teams deploy agent-based tooling faster than security inventory processes can track it, and the blast radius of an unreviewed agent with broad API access is categorically different from a misconfigured SaaS app.
Salt is pitching what it calls an “Agentic Security Graph,” a map of the paths through which AI software can act inside a business, covering LLMs, MCP servers (the connectors that let AI agents interact with external tools and data sources), and internal APIs. The honest tension in that framing is that Salt, as a vendor selling into this exact fear, has an incentive to make the inventory problem sound more universal than it may be, which tilts the timeline on urgency. But the underlying dynamic is real: API security tooling was already a mature category before agentic AI, and adding autonomous agents that chain API calls without human review genuinely extends the attack surface in ways that conventional monitoring wasn’t designed to handle.
For Australian CISOs specifically, the data residency angle isn’t marketing softness. Financial services, healthcare, and federal government procurement in Australia carry hard requirements around where sensitive operational data is processed, and security telemetry, the continuous stream of behavioral data showing what your systems are doing and to whom, qualifies. A vendor without local hosting isn’t a procurement option for a meaningful slice of the market. Salt’s Sydney deployment removes that blocker. The question to weigh isn’t whether to monitor agentic AI, it’s whether your current security stack has any coverage of it at all, and if the answer is no, that’s the budget line to defend in the next planning cycle.
Concept deep-dive: MCP servers
MCP stands for Model Context Protocol, an emerging standard that lets AI agents connect to external tools, databases, and APIs, think of it as a universal adapter that gives a language model hands to reach into your business systems. The security problem is that each MCP server is effectively a privileged integration point: it can read data, trigger actions, and pass results back to an AI that may then take further steps. Organizations often deploy them quickly and informally, which is why they show up in security audits as unknown infrastructure.
Based on reporting from Salt Security launches Australian base for AI security, originally published 2026-07-21 17:30:00.

