Security & automation for the agent economy
We scan the MCP ecosystem daily, publish what we find, and run the same engine against your fleet. AI agents pay per request over x402 (USDC on Base, no account, no signup — the HTTP 402 flow handles everything). Humans can order by email.
For agents & APIs — pay per call with x402
Machine-to-machine pricing on the x402 rail: your agent hits the endpoint, gets a 402 with payment terms, pays USDC on Base, retries with the receipt. Zero human in the loop.
Basic security scan
18-rule FlowSentry scan of any MCP or x402 endpoint: auth posture, header hygiene, transport config, known design-flaw patterns. Returns structured findings with severities.
Deep scan
Everything in Basic plus per-node risk rollup, overall risk score 0-100, prioritized remediation plan and attacker-perspective analysis when an exploit chain exists.
Agent trust check
Fast trust signal before your agent talks to a third-party MCP server: live handshake test, auth gate status, header hygiene, DNS liveness. Built for pre-call gating.
Whitelist feed
Daily machine-readable feed of vetted, scan-clean MCP endpoints for your agents to consume. JSON + RSS. Your agents only touch endpoints that passed yesterday's scan.
Compliance report
Human-readable report: findings mapped to severity, evidence for each check, remediation steps. Suitable for vendor security reviews of AI tooling.
Bulk scan
Scan your whole MCP fleet in one run: registry inventory, per-endpoint findings, fleet-level risk summary, re-scan on fix. The same pipeline behind our public reports.
For teams — custom work
Delivered by the same team that runs the scanner. Email us with scope; everything lands with a verification artifact.
Custom n8n / automation build
Custom workflow automation in n8n or your stack: spec to working automation in 24-48h. Security-first by default — secrets handling, least-privilege webhooks, audit trail.
24h security fix service
Found a hole in your MCP deployment or automation? We deliver a tested fix within 24 hours: patched config, verification scan, and a short postmortem.
MCP Security Report for your fleet
We scan your whole MCP fleet the way our published research scans the public registry — and give you a prioritized fix plan.
"44% of live MCP servers accept an unauthenticated handshake — and 86% ship no Content-Security-Policy. We found placeholder entries the official registry never validated. The deployment layer is the gap nobody owns."
How to order
- Agents: call the endpoint — the 402 response carries exact terms and the payee address. Humans: email the form below with what you need.
- Pay in USDC on Base: automatic via x402, or send to the wallet below and include the tx hash.
- Scans return immediately; reports and custom builds land in your inbox within 24-48h.
Why us
Our scanner runs daily against the public MCP registry — 44% of live servers accept an unauthenticated handshake, 86% ship no Content-Security-Policy. We found placeholder entries the official registry never validated. The same engine (18 rules, Python + in-browser JS) scans your endpoints.
Security-first, self-hosted-friendly, privacy-by-design: we store what you pay for and nothing else.
Order by email — fast path
Checkout — USDC on Base
Send payment to:
0xa1b8be63bde77ddc65d9ffe8a21a2a5f2c9ca6a8
Or scan the QR with any wallet (EIP-681, Base mainnet). Email the tx hash with your order.