The Sovereign MCP Control Plane

Compliant AI access to the systems you already run.

Loopthink connects SAP, Dynamics and Salesforce to ChatGPT and Claude over MCP, with SSO, audit and EU sovereignty on by default.

Get your AI strategy on track, EU-compliant and board-ready.

RUNNEROUTBOUND-ONLYAI CLIENTSChatGPTClaudeLangdockOpen WebUIloopthink.aiSOVEREIGN MCP CONTROL PLANEMCP GatewayPolicy · SSO · Access (ZTNA)Masking · PseudonymizationAudit · DLPINTERNAL SERVICESSAP · ERPMicrosoft Dynamics · NavisionDatabases & data warehousesSAAS MCP SERVERSSalesforceSlackJiraServiceNowGitHubPayPal

The Loopthink Runner inside your network dials out, never in. No inbound ports, no VPN, no firewall changes.

40%+
of agentic AI projects cancelled by 2027 due to weak governance and unclear ROI (Gartner)
~47%
of deployed AI agents run ungoverned, the new shadow IT
€35M
maximum EU AI Act fine. Deployer duties apply the moment you ship an agent
72%
of German organizations actively seeking sovereign AI (Accenture)
Product demo

Watch ChatGPT reach an internal system.

No slides: we build an MCP server on an internal database, mask the sensitive fields, connect it to ChatGPT, and follow the request through the control plane.

Press play to load the video. Until then, nothing is requested from YouTube or any other Google server.

Why now

Shadow AI is already inside your systems.

MCP made connecting any AI to your data trivial. Convenient for employees. A board-level risk for you.

Shadow AI everywhere

Employees wire agents into internal systems without SSO, logging or approval, creating far more connections than IT expects.

Data leaves your control

Plaintext credentials, over-permissioned agents, and PII flowing to US AI providers under the CLOUD Act.

Compliance blocks rollout

EU AI Act, DORA and BSI C5 apply the moment an agent goes live. Without audit trails, legal says no.

Native by default

No new app. Just the AI they already open.

Loopthink lives inside the assistants your teams already use, and adds a sovereign UI for everyone else. Built on MCP, so every system that offers an MCP source is compatible out of the box.

ChatGPT

Governed access to your systems inside ChatGPT, via native connectors.

Claude

Plug your data into Claude's enterprise connectors with per-user permissions and audit.

Langdock

EU

A fully European stack: from interface to data path, sovereign end to end.

Open WebUI

Self-host

Governed access in your self-hosted UI, ideal for air-gapped, regulated setups.

One policy across every client. Same access rules, DLP and audit everywhere. For regulated data, requests route to EU-hosted models, so nothing leaves your jurisdiction.

Flagship capability

Ask your systems. In plain language.

Your systems hold the answers, but only a few power users know how to get them. Loopthink puts a governed chat layer on top, so anyone can just ask.

SAPDynamics / NavisionSalesforceServiceNowYour databases & APIsAny MCP source

Every question runs through the same control plane: the user's own permissions, full audit, DLP and EU-sovereign hosting.

Loopthink UI · Financegoverned
Show me overdue invoices over €10k for DACH.
7 invoices over €10k overdue in DACH, totalling €312,900. Oldest is 41 days. SAP FI · read-only · audit logged
Draft a follow-up for the top 3.
Done. Drafted for Huber AG, Meier GmbH and Nord Logistik, grouped by owner. DLP applied · no PII exported
Ask your systems anything…
Integrations

Connected to the systems you already run.

Your line-of-business systems, databases and SaaS tools — reachable inside ChatGPT and Claude. Same Runner, same policy, same audit log.

ERP & Finance

  • SAP
  • Dynamics 365
  • Navision
  • DATEV

CRM & Sales

  • Salesforce
  • HubSpot
  • Dynamics CRM

Service & ITSM

  • ServiceNow
  • Zendesk
  • Jira Service Management

Collaboration

  • Microsoft 365
  • Slack
  • Jira
  • Confluence
  • SharePoint

HR

  • Personio
  • SuccessFactors
  • Workday

Commerce & Payments

  • Shopify
  • Stripe
  • PayPal

Engineering

  • GitHub
  • GitLab

Databases & Warehouses

  • PostgreSQL
  • MySQL / MariaDB
  • MS SQL Server
  • Oracle
  • MongoDB

Every REST API. Every MCP server.

If it has an API, we connect it. Anything that speaks MCP works without extra work.

Don't see your system?

We build connectors during customer projects — as part of onboarding, not as a roadmap promise. Tell us which system you need.

Request a system
The platform

One gateway. Every model. Total control.

A single governed layer between your people, their AI and your systems, on any cloud or on-prem.

Govern & secure

SSO, per-role and per-tool access, DLP and full audit of every action: who, what, which data, when.

Self-service, curated

Teams turn approved databases and APIs into governed AI tools in minutes, with approval workflows.

Discover & measure

Detect shadow AI, retire unauthorized connections, and show the board real adoption, usage and cost.

Nothing to open. Nothing to expose. The Loopthink Runner runs inside your network and connects outbound only: it polls the control plane for approved requests, executes them locally, and returns results over the same encrypted channel. Your systems stay behind the firewall, and their credentials never leave your intranet.

Deployment

Run the control plane our way, or entirely yours.

Same platform, same features. Start managed in the EU, or deploy fully on-prem for air-gapped and highest-regulation environments.

Loopthink Cloud

Fastest start
  • EU-hosted, fully managed. We run and update the control plane, audit-ready from day one.
  • Fastest path to live. Ideal for most teams: no infrastructure to stand up, live in weeks.
  • Runner stays yours. It runs inside your network. System credentials never reach the cloud.

Loopthink On-Prem

Maximum sovereignty
  • Your environment, entirely. The control plane runs in your cloud or your data center. Nothing routes through ours.
  • Built for the strictest workloads. Air-gapped, BSI C5 and highest-regulation environments.
  • Same feature set as Cloud. No capability trade-off for choosing sovereignty.

Same features either way. Both deployments share the outbound-only Runner, one policy engine, SSO, DLP and full audit. Choosing the sovereign option never means giving up capabilities.

Technical Whitepaper

Governing MCP Access to Enterprise Systems

Gateway architecture, field-level masking, and deployment topologies — written for architects, security engineers and CISOs. Deliberately explicit about what a gateway does not solve.

EU Sovereignty

Sovereign by architecture, not by region.

EU-region hosting alone doesn't make an AI platform sovereign. Loopthink is built so that your systems, your credentials and your data stay under your control — regardless of where the control plane runs.

  • No direct access to customer systems. SAP, database and other system credentials remain in the Loopthink Runner inside your network. The cloud control plane never needs to see them.
  • PII stays under your control. Predefined fields can be masked or pseudonymized in the Runner before data is sent to an AI model.
  • EU-hosted control plane. The Loopthink control plane is hosted and operated within the EU.
  • Compliance mapped to controls. GDPR, EU AI Act, DORA and BSI C5 requirements can be mapped to concrete technical and organizational controls.
  • Vendor-neutral. Apply the same policies across models and cloud providers without locking your governance into a single hyperscaler.
  • Managed or self-hosted. Run the Loopthink control plane in the EU, or host it entirely yourself for zero third-party cloud dependency. Your systems and credentials remain under your control either way.

"…an ungoverned sprawl of agents that expose their organizations to a range of risks."

Max Goss, Sr Director Analyst, Gartner

By 2028, an average global Fortune 500 enterprise is projected to run over 150,000 AI agents, up from fewer than 15 in 2025. Only 13% of organizations think they currently have the right AI agent governance in place.

Source: Gartner press release, 'Gartner Identifies Six Steps to Manage AI Agent Sprawl', 28 April 2026.

How it works

Live in weeks, not quarters.

01

Discover

We map where AI already touches your systems, including the shadow AI no one reported, and quantify the risk.

02

Govern

Every connection routes through Loopthink: SSO, least-privilege access, DLP and audit. The control plane runs managed by us in the EU or entirely in your environment. Internal systems attach via the outbound-only Runner, with zero firewall changes.

03

Scale

Teams safely self-serve new AI tools on approved data. You expand adoption and prove ROI.

Get in contact

Bring your AI strategy under control.

Tell us where you are, and we'll set up a focused executive briefing for your industry and compliance needs.

  • 30-min briefing: assess your setup, map compliance gaps, see if we fit. No pitch
  • For CIOs, CISOs, CDOs & CEOs
  • Your details stay in the EU

By submitting you agree to be contacted about Loopthink. No spam, ever.

Your teams already use AI. Govern it.

Turn ungoverned pilots into a sovereign, board-ready program, without slowing anyone down.

Book an executive briefing

Get your AI strategy on track, EU-compliant and board-ready.