Skip to content
Rush Commerce
AI & Automation3 min read

Anaconda buys Enkrypt AI. Go audit your MCP servers.

Enkrypt scanned 25,000 MCP servers and flagged issues in 73% of them. If you wired MCP into your business tools, that number is your inventory problem.

The interesting part of this acquisition isn't the acquisition. On August 4, 2026, Anaconda announced it acquired Enkrypt AI, folding AI security and compliance into its platform. Buried in the announcement is a scan result that should make anyone running MCP servers open a terminal: across roughly 25,000 MCP servers, Enkrypt flagged vulnerabilities affecting 73% of them.

What actually happened

Per Anaconda's own announcement, Enkrypt provides pre-deployment red-teaming, runtime guardrails against jailbreaks and data leakage, and audit-trail generation for compliance. Terms weren't disclosed.

The numbers Anaconda published: in the two months before the deal, Enkrypt scanned more than 268,000 tools across 25,000 MCP servers and found over 143,000 vulnerabilities, hitting 73% of those servers. Anaconda frames the whole thing around enterprises running near a trillion tokens a month, with the compliance hook pointed at the NIST AI Risk Management Framework and the EU AI Act, whose transparency obligations went live August 2.

Read that stat with the appropriate squint. It's the acquirer's number, published on the day it needed the security layer to look essential, using its own definition of "vulnerability." We'd treat 73% as directional, not gospel.

Directional is still bad. MCP servers are the connective tissue between your AI assistant and your actual business — your CRM, your database, your file store, your ticketing system. The reason a scan finds that much is structural: MCP servers are small, they get written fast, they're often a weekend project someone published, and installing one grants a language model a set of tools with your credentials behind them.

Why MCP server security matters for your business

You probably added three MCP servers this quarter and didn't write any of them down. That's the whole problem.

Inventory first. List every MCP server your team has connected — in Claude, in Cursor, in whatever agent harness you're running. For each one: who wrote it, what version is pinned, what credentials it holds, and what it can write to. Most teams cannot answer question one. The teams that can usually discover a server nobody remembers adding.

Scope the credentials, not the prompt. An MCP server that reads orders does not need a key that can refund them. We give every server its own scoped credential with the narrowest possible permission set, so a compromised or badly written tool caps out at the damage its own scope allows. That's the same discipline as scoping agent network egress — different layer, identical logic.

Pin versions and read the diffs. An MCP server that auto-updates is a supply-chain dependency with tool-calling privileges attached to it. Treat it like any other package: pin it, review upgrades, and know who's on the other end of the repo.

Separate the tool from the vendor buying it. Anaconda now owns the scanner that produced these numbers. That's not a knock — consolidation is how this market works — but it's a reminder that the security layer you adopt today may report to a different company next year. Prefer controls you can run yourself over controls you rent from whoever gets acquired next.

Key takeaways

  • Anaconda acquired Enkrypt AI on August 4, 2026; financial terms were not disclosed
  • Enkrypt reports scanning 268,000+ tools across ~25,000 MCP servers, finding 143,000+ vulnerabilities across 73% of servers
  • That's the acquirer's own figure on announcement day — treat it as directional, not audited
  • Enkrypt adds pre-deployment red-teaming, runtime guardrails, and compliance audit trails aimed at NIST AI RMF and the EU AI Act
  • Your actual homework: inventory every connected MCP server, pin its version, scope its credential, and know who can write what

Every MCP server you install is a tool your AI can call with your credentials attached. We build agent integrations with per-server scoped credentials, pinned versions, and a written inventory of what each one can touch. See how we build, or have us audit the MCP servers you've already connected.

Sources: Anaconda.

  • #mcp
  • #ai-security
  • #ai-agents
  • #vendor-risk
  • #governance
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.