Define security requirements for MCP servers, proxy servers, and tool connectors, including authentication and authorization, least privilege, schema/input validation, secrets management, network isolation, sandboxing, logging and auditability, third-party server risk review. Architect and implement AI gateway controls that centralize security policy enforcement for model traffic, including prompt inspection, response filtering, PII/secret redaction, model access control, rate limiting / abuse prevention, audit logging and evidence generation.