MCP spec 2026-07-28 goes final: 10,000+ servers must migrate. Time left: Check your server now →
FAQ

The questions security teams actually ask.

Straight answers on methodology, disclosure, and pricing. If your question isn't here, ask us directly.

Methodology

Eight documented checks (CFM-01 through CFM-08): authentication, OAuth-flow correctness, tool-poisoning surface, scope minimization, secret exposure, destructive-tool guardrails, 2026-07-28 spec conformance, and transport security. Each is weighted into the overall A–F grade, and every finding ships as a line item in the report. A ninth advisory line (CFM-09) maps every scan to the MCP command-injection class without affecting the grade.

Gateways proxy traffic after you've already decided to connect a tool. Conformant is the decision input: an independent, anchored grade you read at procurement time. They're complementary: many customers enforce a Grade B minimum in Conformant Control and route approved tools through their gateway.

No. Every report is hashed into the Sigstore/Rekor public transparency log at issue time. Grades are append-only: a vendor can improve and re-scan, but the history stays verifiable. Badges auto-revoke if weekly re-verification fails.

Not on its own, and we won't pretend otherwise. Agentjacking hijacks a Grade-A server (Sentry's own MCP) by poisoning the error content it relays, not by breaking the server's security posture. A Conformant grade measures posture: auth, scopes, transport, and the injection surface in a tool's own descriptions (CFM-03). Sanitizing the live third-party content an authorized tool passes back is a separate, ecosystem-wide problem still being solved. What the grade gives you is the pre-connect read procurement needs, plus a registry and a minimum-grade connection policy to control which tools are even eligible to touch your agents in the first place.

The MCP 2026-07-28 specification goes final: stateless core, MCP Apps, formal deprecation policy. Every stateful server must migrate. CFM-07 tests exactly this: scan now and you know precisely what breaks before your users find out.

Disclosure

Not by name. We operate a coordinated-disclosure policy: failing servers appear anonymously in aggregate statistics, the vendor is notified privately, and a remediation window applies before any named publication. Consented and already-publicly-disclosed servers are listed by name.

Commercial

Yes. Conformant Control runs the same battery against private servers and produces anchored attestations that are never published. You get the proof for auditors without the exposure.

Yes, on Growth and above: if a vulnerability class we explicitly graded as cleared is exploited on your covered server during the coverage period, we cover your documented incident-response costs. Limits and terms are set in the coverage agreement; it's a commitment we price off a tested battery, not a gimmick.

Conformant is built in Houston, TX by Shayne Beavan on the same cryptographic evidence rails as VERDICT (AI action evidence) and COSIGN (action authorization). One trust layer: prove what's safe, prove what happened.