BASTET / SERVICES

MCP Security Assessment

Review the trust boundary between an AI agent and the systems its MCP tools can reach.

What we review and deliver

01

Authentication and authorization

Review server access, token audience and scope, delegated authority, and whether permissions are enforced for every operation.

02

Tool and server trust

Inspect tool discovery, descriptions, update paths, secret handling, and the consequences of trusting a compromised integration.

03

Execution and data exposure

Map filesystem, network, cloud, and business-system access. Review approval boundaries and the evidence produced by tool calls.

Starting scope

One MCP deployment, up to five tool operations, one authentication flow, and an agreed client integration. Additional servers and test scenarios are scoped separately.

Availability, access, integrations, and complexity are confirmed before engagement.

What you receive

  • Documented decisions and priorities
  • Actionable recommendations with owners
  • Technical and executive summary
  • English or Spanish handover session
View an illustrative report format →

Before we begin

We agree the authorized systems, test scenarios, deliverables, and acceptance criteria in writing. An architecture assessment is not an exhaustive penetration test. Production testing, implementation, and continuous monitoring are included only when explicitly scoped.

Read the assessment method →
NEXT STEP

Define the scope before you commit.

Tell us about your environment, risk concerns, and target date.

Request a scoping call ↗