Skip to main content
The engagement

A supervised review of your MCP trust boundaries.

Fixed scope, agreed in writing before any testing: what's reviewed, what's excluded, what you provide, and what you receive. Analyst review combined with bounded telemetry evidence.

Scope

What is in and out of scope

Bounded on purpose. A defined review boundary beats a broad scan that confirms nothing.

In scope
  • The MCP systems, host paths, and connected capabilities named in the agreed scope.
  • Architecture and trust-boundary review.
  • Source, configuration, identity and authorization review.
  • Selected controlled tests, in an approved non-production environment.
  • Bounded telemetry analysis with five inspectable rule families plus normalized and correlated checks.
  • Analyst validation, prioritization and remediation guidance.
Out of scope
  • A full source-code audit of the entire application.
  • Comprehensive identity, IAM or SSO assessment.
  • Runtime enforcement, monitoring, or real-time blocking.
  • Business-context or compliance certification.
  • Production access, credentials, or raw customer data.
  • Multiple servers or a whole fleet in a single engagement.
What you provide · what you get

What you provide and what you receive

You provide

  • Read access to the MCP server source and configuration for the integration in scope.
  • A minimized telemetry capture, produced and reviewed on your own network.
  • Written authorization for any controlled testing, and a non-production environment for it.
  • A named technical contact to answer questions during the review.

You receive

  • Prioritized findings with the evidence and reproduction steps behind each one.
  • Implementation-ready remediation written against your code and configuration.
  • A control-assurance matrix separating verified, failed, review-required and untested boundaries.
  • A written scope-and-limitations statement: tested, skipped, and out of scope.
Retest

Fixes applied within the agreed window are re-checked against the original evidence, so a resolved finding is verified rather than assumed. The retest covers the findings in the report, not a fresh, expanded review.

Fit

Who this is and is not for

A good fit if…

  • You're shipping a specific MCP integration and want it reviewed before it reaches customers.
  • Tools in that integration can touch credentials, customer data, or a filesystem.
  • You value a defensible, evidence-backed account of the agreed environment over shallow breadth.

Not the right fit if…

  • You need runtime protection, monitoring, or a product that blocks attacks live.
  • You want a whole fleet or platform certified in one pass.
  • You're looking for a compliance stamp rather than a technical review.
Design-partner offer

Early, limited, and evolving.

The current design-partner pilot is a fixed experimental $1,250. The price and customer demand have not been independently validated. The engagement covers one authorized MCP server and one host integration, with findings walkthrough and one focused retest.

  • One authorized integration.
  • You provide technical feedback on the review.
  • A reference is welcome but never required.
  • Scope, authorization, data handling, exclusions, and price are agreed in writing first.

This is a limited pilot, not a subscription or certification. Follow-on work is scoped separately.

Step 1 of 3

What are you integrating MCP into?

Step 2 of 3

How many host integrations are in scope right now?

Step 3 of 3

Which evidence path can you support?

Scope drafted

Here's what you told us.

Add an email and we'll reply to discuss written scope, authorization, and any experimental price. Nothing is booked by submitting this.

This form sends only your email and the three scope selections through the site's hosting and email-delivery providers so MCP Detect can reply. Do not send source, credentials, or telemetry here. It sets no cookies, books nothing, and the inquiry data is not used for model training or sold.

Request a review

Start a conversation

Tell us what your MCP environment can reach and what prompted the review. We'll reply with a clear scope and next steps.

Email ops@mcpdetect.dev See the review scope