Introducing Zilla Plus 2.0: Enterprise Infrastructure for Real-Time Data and AI
Production MCP infrastructure, advanced Kafka governance, and a new management experience, built on the same streaming-native gateway.



Last month, we introduced Zilla 2.0 and a major expansion of what Zilla is built to do.
Zilla started as a Kafka-native gateway, giving applications, services, partners, devices, and developers a secure and governed way to access real-time data.
With Zilla 2.0, we added a new kind of client: the AI agent.
Native support for the Model Context Protocol (MCP) made it possible to connect agents to APIs, existing MCP servers, and real-time Kafka data through the same gateway architecture already used to govern application traffic.
Today, we're announcing the next step: Zilla Plus 2.0.
Zilla Plus 2.0 takes that architecture into enterprise production, with major new capabilities for both AI and Kafka platform teams.
It also arrives alongside a completely overhauled Zilla Console, bringing the gateway and its management plane together as the new Zilla Platform.
One gateway, two rapidly converging worlds
Kafka infrastructure and AI infrastructure can look like two separate problems.
Increasingly, they aren't.
Applications need governed access to real-time data. AI agents need governed access to tools, APIs, and increasingly that same real-time data.
Both need identity.
Both need authorization.
Both need schema and data controls.
Both need observability.
And both need to connect across systems and protocols without every team building another layer of custom middleware.
Zilla Plus 2.0 extends a common gateway architecture across these workloads.
For AI teams, that means production infrastructure for MCP and agent access.
For Kafka teams, it means stronger identity, isolation, and protection of the data flowing through Kafka.
Taking MCP beyond the demo
Zilla Community 2.0 introduced native MCP support, including the ability to aggregate existing MCP servers, generate MCP capabilities from APIs, and expose Kafka directly to agents.
Zilla Plus 2.0 builds on that foundation for larger, production deployments.
Agents can now access Kafka, Kafka Connect, Schema Registry, OpenAPI, and HTTP backends as MCP tools through Zilla.
That means enterprises don't need to build and operate a separate MCP server for every API, data source, or Kafka capability they want an agent to use.
Zilla Plus 2.0 also tackles a problem that becomes increasingly important as MCP deployments grow: tool discovery at scale.
Instead of loading an entire tool catalog into an agent's context, Zilla can expose a configurable set of frequently used tools while allowing agents to search, describe, and execute additional tools as needed.
Tool search can use relevance ranking or semantic search backed by embedding providers including AWS Bedrock, IBM watsonx.ai, and OpenAI.
And because production gateways need to scale horizontally, Zilla Plus 2.0 adds support for stateful MCP sessions across multi-node gateway deployments.
The result is an MCP gateway designed not only to connect an agent to a few tools, but to govern how agents discover and use capabilities across an enterprise.
We'll take a deeper look at these capabilities in an upcoming post focused entirely on MCP in production.
More control at the Kafka edge
Zilla Plus 2.0 is also one of our most significant updates for Kafka governance.
A major focus is giving platform teams finer control over who sees what data and under which identity.
New field- and payload-level protection allows sensitive data to be governed directly at the gateway.
Individual fields can be:
- Redacted
- Omitted
- Masked
- Hashed
- Encrypted with AES-GCM
These policies can be applied to JSON, Avro, Protobuf, and raw values, with access determined per field.
This makes it possible, for example, to encrypt sensitive information before it reaches Kafka and selectively decrypt, mask, or remove it depending on the authorization of the consumer reading it.
Zilla Plus 2.0 also adds SASL/OAUTHBEARER support for Kafka and expands identity-driven topic aliasing across the Kafka protocol.
That allows different users, applications, or tenants to see their own logical Kafka namespace while Zilla maps those identities to the appropriate underlying Kafka resources.
The model now extends across metadata, offsets, consumer groups, transactions, ACLs, configurations, and other Kafka operations, with corresponding per-subject aliasing available for Schema Registry.
New integrations including AWS Cognito, AWS IAM, X.509 identities, AWS KMS, HashiCorp Vault, KMIP, and Kubernetes Secrets further extend how enterprises can connect Zilla to their existing security infrastructure.
We'll cover the Kafka side of Zilla Plus 2.0 in detail in a separate post for Kafka and platform teams.
A new management experience
We're also introducing a completely overhauled Zilla Console.
As part of this release, we're simplifying how we talk about the Zilla product family.
Zilla Plus is the enterprise gateway runtime.
Zilla Console is the management plane for configuring, governing, and operating Zilla environments.
Together, they make up the Zilla Platform.
The new Console brings gateway management, API Products, applications and subscriptions, Kafka management, governance, and operational visibility into a unified experience.
We'll have much more to share about the new Zilla Console shortly.
Built on the same streaming-native runtime
What's important about Zilla Plus 2.0 isn't simply the number of features being added.
It's that these capabilities run on the same underlying architecture.
Zilla does not have one proxy architecture for Kafka, another for APIs, and another for MCP.
Kafka, HTTP, SSE, WebSocket, MQTT, gRPC, MCP, and other protocols are represented on a common streaming-native runtime.
Identity, authorization, schemas, routing, secrets, data protection, and observability can then be applied consistently at the gateway.
That becomes increasingly important as the line between application infrastructure and AI infrastructure disappears.
An application may consume Kafka directly.
A web application may access the same data over HTTP or SSE.
A partner may need its own isolated Kafka namespace.
An AI agent may discover that same data as an MCP tool.
The client changes.
The underlying enterprise systems often don't.
One platform for real-time data and AI
Zilla began by helping enterprises make Kafka easier to access without sacrificing the properties that make streaming powerful.
Zilla 2.0 expanded that model to AI agents.
Zilla Plus 2.0 brings the two together for enterprise production.
For AI teams, Zilla provides a governed path from agents to the APIs, tools, and real-time data they need.
For Kafka teams, it provides stronger control over identity, isolation, and sensitive data without requiring a new layer of application infrastructure.
And with the new Zilla Console, those capabilities can increasingly be managed as part of a single platform.
Over the next few weeks, we'll go deeper into what's new for MCP and AI teams, what's new for Kafka platform teams, and introduce the completely redesigned Zilla Console.
One gateway for real-time data and AI.
Get started


Ready to Get Started?
Get started on your own or request a demo with one of our data management experts.
Explore pricing
Straightforward, usage-based pricing with no per-connection surprises — start free and scale when you are ready.
Join the Community
Trade notes with the engineers running Zilla in production, and get help from the team in Slack or Discord.





