Authentication and authorization
Review server access, token audience and scope, delegated authority, and whether permissions are enforced for every operation.
Review the trust boundary between an AI agent and the systems its MCP tools can reach.
Review server access, token audience and scope, delegated authority, and whether permissions are enforced for every operation.
Inspect tool discovery, descriptions, update paths, secret handling, and the consequences of trusting a compromised integration.
Map filesystem, network, cloud, and business-system access. Review approval boundaries and the evidence produced by tool calls.
One MCP deployment, up to five tool operations, one authentication flow, and an agreed client integration. Additional servers and test scenarios are scoped separately.
Availability, access, integrations, and complexity are confirmed before engagement.
We agree the authorized systems, test scenarios, deliverables, and acceptance criteria in writing. An architecture assessment is not an exhaustive penetration test. Production testing, implementation, and continuous monitoring are included only when explicitly scoped.
Read the assessment method →Tell us about your environment, risk concerns, and target date.