Know what's safe
to connect before you plug it in.
Your AI agents are reaching into tens of thousands of third-party tools and MCP servers, straight into your production data. Conformant is the independent trust registry that grades every one of them, cryptographically anchors the result, and re-verifies it weekly. SOC 2 for the things you let your AI touch.
It's no longer just exposed servers. The tools themselves became the weapon.
The last few weeks moved the attack surface under the ecosystem's feet. The injection is now inside the tool responses your agent already trusts and inside the SDK every server is built on. Neither is caught by watching traffic after you connect. Both are the reason to grade a tool before you plug it in.
Straight talk: a Conformant grade measures a server's posture: auth, scopes, transport, and the injection surface in its own tool descriptions (CFM-03). It does not sanitize the live content an authorized tool relays back; poisoned responsesare a frontier the whole ecosystem is still hardening, and we won't claim a grade stops them. What a grade gives you is the input procurement actually needs: a documented, anchored read on the tool before it reaches your data, plus a registry and a minimum-grade policy to decide which tools are even eligible to touch your agents.
Not a new product. The piece that was always missing.
The web got a certificate authority the moment enough traffic depended on trust nobody was verifying. AI agents are at that moment now: thousands of MCP tools reaching into production data, and no standing, public, tamper-evident record of which are safe to connect. Conformant is that record. A grade you read before you connect; an attestation the operator signs and anchors; a class like OX Security's MCP command injection mapped, not marketed around.
One prompt away from your database.
The agent gold rush was built on unlocked doors. Here's the whole problem, and the fix, in 90 seconds.
One credential. Five surfaces.
Everyone else governs agents at runtime, after you've already decided to connect. Conformant lives where the decision actually happens: procurement.
Grade any MCP server in seconds.
Paste a URL or upload a manifest. The Conformant Battery probes the live endpoint across 8 dimensions and returns a weighted A–F grade with line-item findings.
- Authentication & OAuth-flow correctness
- Tool-poisoning & prompt-injection surface
- Scope minimization & secret exposure
- Destructive-tool guardrails
- 2026-07-28 statelessness conformance
▸ CFM-01 AUTH ............ FAIL: no auth on /sse
▸ CFM-02 OAUTH ........... WARN: redirect_uri unvalidated
▸ CFM-03 POISON .......... WARN: 2 injectable descriptions
▸ CFM-04 SCOPES .......... FAIL: wildcard db creds
▸ CFM-05 SECRETS ......... PASS
▸ CFM-06 DESTRUCT ........ WARN: delete_* unconfirmed
▸ CFM-07 STATELESS ....... PASS: 2026-07-28 ready
▸ CFM-08 TRANSPORT ....... PASS
GRADE: F. Do not connect to production data
report anchored → rekor logIndex 1548217734
A grade nobody can fake. Including us.
Every report is hashed and written to the Sigstore/Rekor public transparency log. The grade can't be back-dated, edited, or quietly deleted; anyone can verify it independently, forever.
- SHA-256 report digest, anchored at issue time
- Public verify link on every report and badge
- Grade history is append-only: trust that compounds
- The artifact auditors and insurers can actually rely on
{
"server": "mcp.vendor.com",
"grade": "A",
"battery": "CFM-8 v1",
"digest": "sha256:9f3a…c021",
"rekor": {
"logIndex": 1551442087,
"integratedTime": 1781136000
},
"reVerified": "weekly"
}
// verify: rekor-cli get --log-index 1551442087
The place security teams check first.
Every scanned server, graded and last-verified, in one public index. Before your team connects anything, the question becomes one lookup: is it on Conformant, and what's the grade?
- Search by server, vendor, category, or capability
- Grade + last-verified timestamp on every row
- Named-vendor grades published under coordinated disclosure
- Watchlists: get alerted when a tool you use drops a grade
200 OK
{
"results": [
{ "server": "pg-mcp.vendor-a.dev", "grade": "A", "verified": "2026-06-09" },
{ "server": "sql-bridge.vendor-b.io", "grade": "B", "verified": "2026-06-08" }
],
"excluded_below_grade": 214
}
The badge that ends the security-review stall.
Pass the battery, earn the embeddable Conformant Verified badge, re-verified weekly and linked to your live anchored report. Attach it to the questionnaire and move to commercials.
- Live status: buyers see a current grade, not last quarter's stamp
- One-line embed for your site, docs, and listing pages
- Every badge links to the public Rekor-anchored report
- Auto-revokes if your weekly re-verification fails
<script src="https://conformant.io/badge.js"
data-server="mcp.vendor.com"></script>
renders →
┌──────────────────────────────┐
│ ◆ CONFORMANT VERIFIED │
│ Grade A · re-verified 6d ago │
│ view anchored report ↗ │
└──────────────────────────────┘
Fleet-wide policy for everything your agents touch.
Conformant Control inventories every MCP server connected across your org (including private internal ones), enforces a minimum grade, and alerts the moment anything drops.
- Private attestation for internal servers (never published)
- Policy: "block connections below Grade B," enforced
- Grade-drop alerts to Slack, Teams, or your SIEM
- Board-ready agent-supply-chain posture report
org: acme-corp
policy:
minimum_grade: B
block_unregistered: true
re_verify: weekly
alerts:
- slack://sec-ops
- siem://splunk-hec
✔ 47 servers in policy · 2 blocked · 1 grade-drop alert
Eight checks. Weighted. Documented. Anchored.
Aligned with the NSA's MCP design guidance and the 2026-07-28 specification. Every check is documented publicly: vendors know exactly what an A requires.
Auth present and enforced on every tool endpoint. The check 40% of public servers fail.
Flow integrity: WWW-Authenticate challenge and RFC 9728 protected-resource metadata.
Injection surface in tool names, descriptions, and instructions that can steer the calling agent.
Least-privilege credentials. No wildcard database access behind a convenience wrapper.
No keys, tokens, or connection strings leaking through metadata, errors, or tool output.
Irreversible operations gated behind confirmation. No naked delete_* in the tool list.
TLS posture, origin validation, and rate limiting on every exposed surface.
Config and credential documents served unauthenticated from the same origin — the paths attackers are scanning for right now.
Scan. Anchor. Display.
Paste a URL
The battery probes the live endpoint across all 8 dimensions and returns a weighted A–F grade with line-item findings, in seconds.
Tamper-evident proof
Every report is hashed into the Sigstore/Rekor public transparency log. The grade can't be faked, back-dated, or quietly edited.
The badge that clears you
Pass, and you earn the embeddable Conformant Verified badge (re-verified weekly) that ends the "is it safe?" stall in enterprise deals.
Three sides of the same trust problem.
Stop losing deals to the questionnaire.
Your product is fine; your proof is missing. Get the third-party, cryptographically anchored credential that moves enterprise security review from weeks of email to one link.
Get Cleared-to-Connect →Vet every tool before agents touch it.
65% of firms already ate an agent-caused incident. Inventory what's connected, enforce a minimum grade, and get alerted the moment anything drops, including private internal servers.
See Conformant Control →Underwrite agent risk on evidence.
Append-only, anchored grade history across the agent-tool supply chain. The dataset that turns "AI risk" from a guess into a priced, auditable exposure.
Talk data licensing →Adjacent isn't the same as solved.
Runtime gateways act after you connect. Researchers publish one-off findings. Identity standards verify the agent, not the tool. The pre-connect credential is the empty seat. Conformant sits in it.
| Capability | Conformant no gaps below | Runtime gateways | Security research | Agent identity standards |
|---|---|---|---|---|
| Verdict before you connect | ✓ | After connection | One-off posts | No pre-connect signal |
| Independent third party | ✓ | Platform-owned | ✓ | Consortium specs |
| Standing, re-verified credential | ✓weekly | No standing credential | No standing credential | No standing credential |
| Cryptographically anchored grades | ✓Rekor | Not anchored | Not anchored | Not anchored |
| Portable proof vendors can show buyers | ✓badge | Not portable | Not portable | Not portable |
| Tests live MCP-protocol behavior | ✓8 checks | Traffic proxy | Ad hoc | Signs requests |
The registry is live. Every grade is anchored.
We grade the MCP servers enterprises connect and anchor every report to the Sigstore/Rekor transparency log. The marquee names pass. The danger is the unverified long tail.
Live registry sample (39 servers and growing). Passing public servers are listed by name; servers that fail stay anonymous under a coordinated-disclosure policy until the vendor is notified and given a remediation window.
Stop losing enterprise deals to the security questionnaire.
Be the tool buyers are allowedto plug in. Outcome-priced: you're buying enterprise-ready status, not a scanner subscription.
Cleared-to-Connect
Submit your server, pass the battery, earn the anchored badge in a week, or it's free until you are.
Scan any public server free and get a graded, anchored, shareable report. Real value before you pay a cent.
Incident-response coverage on Growth and above: if a vulnerability class we graded as cleared is exploited during your coverage period, we cover documented response costs. Terms in the coverage agreement.
Your grade re-runs weekly. Buyers always see a live status, not a stale stamp from last quarter.
Priced against the deal it unlocks.
- 1 server certified
- Anchored A–F report
- Verified badge
- Weekly re-verification
- Public registry listing
- Up to 5 servers
- Everything in Indie
- 7-day Cleared-to-Connect SLA
- Incident-response coverage (terms in the coverage agreement)
- Security-review report pack
- Priority remediation guidance
- Unlimited servers
- Private internal-server attestation
- Conformant Control dashboard
- Grade-drop alerting + policy enforcement
- Verification API (x402-payable)
- SIEM / Slack / Teams integrations
The questions security teams actually ask.
Eight documented checks (CFM-01 through CFM-08): authentication, OAuth-flow correctness, tool-poisoning surface, scope minimization, secret exposure, destructive-tool guardrails, 2026-07-28 spec conformance, and transport security. Each is weighted into the overall A–F grade, and every finding ships as a line item in the report. A ninth advisory line (CFM-09) maps every scan to the MCP command-injection class without affecting the grade.
Gateways proxy traffic after you've already decided to connect a tool. Conformant is the decision input: an independent, anchored grade you read at procurement time. They're complementary: many customers enforce a Grade B minimum in Conformant Control and route approved tools through their gateway.
No. Every report is hashed into the Sigstore/Rekor public transparency log at issue time. Grades are append-only: a vendor can improve and re-scan, but the history stays verifiable. Badges auto-revoke if weekly re-verification fails.
Not on its own, and we won't pretend otherwise. Agentjacking hijacks a Grade-A server (Sentry's own MCP) by poisoning the error content it relays, not by breaking the server's security posture. A Conformant grade measures posture: auth, scopes, transport, and the injection surface in a tool's own descriptions (CFM-03). Sanitizing the live third-party content an authorized tool passes back is a separate, ecosystem-wide problem still being solved. What the grade gives you is the pre-connect read procurement needs, plus a registry and a minimum-grade connection policy to control which tools are even eligible to touch your agents in the first place.
The MCP 2026-07-28 specification goes final: stateless core, MCP Apps, formal deprecation policy. Every stateful server must migrate. CFM-07 tests exactly this: scan now and you know precisely what breaks before your users find out.
Not by name. We operate a coordinated-disclosure policy: failing servers appear anonymously in aggregate statistics, the vendor is notified privately, and a remediation window applies before any named publication. Consented and already-publicly-disclosed servers are listed by name.
Yes. Conformant Control runs the same battery against private servers and produces anchored attestations that are never published. You get the proof for auditors without the exposure.
Yes, on Growth and above: if a vulnerability class we explicitly graded as cleared is exploited on your covered server during the coverage period, we cover your documented incident-response costs. Limits and terms are set in the coverage agreement; it's a commitment we price off a tested battery, not a gimmick.
Conformant is built in Houston, TX by Shayne Beavan on the same cryptographic evidence rails as VERDICT (AI action evidence) and COSIGN (action authorization). One trust layer: prove what's safe, prove what happened.
One spine: prove what's safe, prove what happened.
Certifies whether a tool is safe to connect. The pre-flight credential, consumed at procurement.
Produces tamper-evident evidence of what an agent actually did. The post-incident record, for liability.
Authorizes high-value actions, deepfake-resistant. Its policy can require Conformant-Verified tools.
Don't connect what you can't verify.
Scan your first server free. Get the anchored grade. Know where you stand before July 28.