MCP spec 2026-07-28 goes final: 10,000+ servers must migrate. Time left: Check your server now →
Verified Badge

The badge that ends the security-review stall.

Enterprise deals stall on one question: is this tool safe to connect? The Conformant Verified badge answers it with a live, third-party, cryptographically anchored grade instead of two weeks of questionnaire email.

What the badge asserts

  • The server passed the Conformant Battery at the displayed grade
  • The grade was re-verified within the last week, or the badge revoked itself
  • Every render links to the live Rekor-anchored report behind it
  • History is append-only: improvements show, and so would regressions

What the badge does not assert

A badge is an automated observation of publicly reachable posture plus any signed operator attestations, at a timestamp. It is not a promise that a tool can never fail, and it does not claim to stop live response-content injection. That honesty is why security teams can actually rely on it: the boundary is documented, not papered over.

Embed this grade

The badge URL is stable per server: weekly re-verification updates the grade and date in place. It links to this live anchored report.

Conformant badge for https://mcp.linear.app/mcp
<a href="https://conformant.io/report/878a0ba268283304" target="_blank" rel="noopener">
  <img src="https://conformant.io/api/badge?server=https%3A%2F%2Fmcp.linear.app%2Fmcp" alt="Conformant security grade" width="232" height="44" />
</a>

Badge lifecycle

  • Pass the battery: the badge goes live with your grade and last-verified date
  • Weekly re-verification updates the grade and date in place
  • A failed re-verification auto-revokes the badge; no stale stamps, ever
  • Fix the finding, re-scan, and the badge restores with the dated remediation history