{
  "schema_version": "ecz-mcp-services-v2",
  "surface": "mcp.ecocitizenz.com",
  "surface_role": "The website of the ECZ-ID Trust MCP layer. Explains the layer, routes a reader to the named surface they need, and explains, compares and qualifies fixed-scope MCP professional services. Does not host checkout, does not write truth, does not prove state, and is not itself a resolver.",
  "authority_boundary": {
    "this_site": "Explains and routes.",
    "trustops": "Reviews the order, then handles acquisition, payment, intake and lifecycle. Owns entitlement and commercial state and is authoritative for order and payment status. Publishes no proof.",
    "backend_core": "Writes deterministic truth. Canonical ECZ-ID state is written here and nowhere else.",
    "resolver": "Provides public read-only proof. A projection of canonical state, never a source of it.",
    "mcp_surfaces": "Distribution and interaction surfaces. They read the projection; no tool on any of them writes truth."
  },
  "contact": "mcp@ecocitizenz.com",
  "currency": "GBP",
  "pricing_notes": "Fixed published prices, exclusive of VAT. The four professional services are fixed-scope engagements and are not subscriptions. No discounts.",
  "layer": {
    "name": "ECZ-ID Trust MCP",
    "website": "https://mcp.ecocitizenz.com",
    "is": [
      "A neutral identity, authority, evidence and current-state layer for MCP.",
      "A public record with a canonical URL for a person and a canonical URL for a machine, resolvable by anyone, without an account.",
      "A vocabulary that publishes its own limits. Every record states what may be relied on and what must not be inferred, in the record itself.",
      "Read-only in public. Authoritative state is written only by ECZ-ID Backend/Core; the Resolver renders a permitted projection of it and is never the source."
    ],
    "is_not": [
      "Not an MCP security scanner. It inspects nothing, probes nothing and executes nothing.",
      "Not a certification authority. There is no ECZ-ID certificate and no approval to be granted.",
      "Not a trust score. There is no rating, grade, percentage or traffic light anywhere in the record.",
      "Not a marketplace or a directory of approved servers. Presence is not endorsement, and absence is not a finding.",
      "Not an identity provider. It does not issue, hold, replace or resell your credentials.",
      "Not a gateway, a proxy or a firewall. It is never in the execution path.",
      "Not a replacement for your security controls. It is designed to sit alongside them.",
      "Not a compliance requirement. No regulation names ECZ-ID, and using it makes you compliant with nothing."
    ],
    "ecz_id_format": "^ECZ(-[A-Z0-9]{2,32}){1,4}$",
    "writes_authoritative_state": false,
    "is_resolver": false,
    "is_registry_or_directory": false,
    "is_certification_authority": false,
    "is_trust_score_provider": false,
    "is_identity_provider": false,
    "is_gateway_proxy_or_firewall": false,
    "is_security_control_replacement": false,
    "is_compliance_requirement": false,
    "disambiguation": "Two of those names sit close together on purpose, so this site never uses either without saying which surface it means. ECZ-ID Trust MCP is the layer. The Trust MCP Server is its machine surface. ECZ-ID MCP Trust is the VS Code extension. Nothing has been renamed."
  },
  "surfaces": [
    {
      "id": "layer",
      "name": "ECZ-ID Trust MCP",
      "kind": "layer",
      "role": "The layer, and this website. Explains the layer and routes you to the surface you actually need.",
      "where": "mcp.ecocitizenz.com",
      "url": "https://mcp.ecocitizenz.com",
      "explained_at": "https://mcp.ecocitizenz.com/trust-mcp",
      "external": false,
      "writes_authoritative_state": false
    },
    {
      "id": "server",
      "name": "Trust MCP Server",
      "kind": "server",
      "role": "Machine surface — a hosted MCP server. Distribution and interaction only; it writes no truth.",
      "where": "trust-mcp.ecocitizenz.com/mcp",
      "url": "https://trust-mcp.ecocitizenz.com/mcp",
      "explained_at": "https://mcp.ecocitizenz.com/trust-mcp/server",
      "external": true,
      "writes_authoritative_state": false,
      "tools": {
        "total": 7,
        "anonymous_read_only": 6,
        "protected": 1,
        "published": [
          {
            "name": "resolve_identity",
            "access": "anonymous",
            "read_only": true,
            "answers": "Who is this ECZ-ID, what state is it in, where is the proof"
          },
          {
            "name": "get_current_state",
            "access": "anonymous",
            "read_only": true,
            "answers": "The narrow current state, nothing else"
          },
          {
            "name": "get_resolver_link",
            "access": "anonymous",
            "read_only": true,
            "answers": "The deterministic proof URL. Makes no network call"
          },
          {
            "name": "explain_status",
            "access": "anonymous",
            "read_only": true,
            "answers": "What a status means, rendered deterministically. No LLM"
          },
          {
            "name": "find_product",
            "access": "anonymous",
            "read_only": true,
            "answers": "The single best next ECZ-ID action for a described situation"
          },
          {
            "name": "get_install_instructions",
            "access": "anonymous",
            "read_only": true,
            "answers": "Official install and discovery routes for an ECZ-ID surface"
          },
          {
            "name": "create_request_to_resolve",
            "access": "oauth2",
            "read_only": false,
            "answers": "Creates a neutral request for evidence. Scope RequestToResolve.Create"
          }
        ]
      }
    },
    {
      "id": "verifier",
      "name": "ECZ-ID MCP Verifier",
      "kind": "verifier",
      "role": "CI and command-line surface. Checks a target against public resolver proof, free to use under the ECZ-ID Proprietary Limited-Use License.",
      "where": "@ecocitizenz/ecz-id-mcp-verifier",
      "url": "https://www.npmjs.com/package/@ecocitizenz/ecz-id-mcp-verifier",
      "explained_at": "https://mcp.ecocitizenz.com/developers",
      "external": true,
      "writes_authoritative_state": false
    },
    {
      "id": "extension",
      "name": "ECZ-ID MCP Trust",
      "kind": "extension",
      "role": "Editor surface — a VS Code extension. Inventories the MCP configuration on your own machine and shows what changed.",
      "where": "developers.ecocitizenz.com/mcp-trust",
      "url": "https://developers.ecocitizenz.com/mcp-trust",
      "explained_at": "https://mcp.ecocitizenz.com/developers",
      "external": true,
      "writes_authoritative_state": false
    },
    {
      "id": "resolver",
      "name": "ECZ-ID Resolver",
      "kind": "resolver",
      "role": "Proof surface — the public, read-only projection of the record. Never a source of truth.",
      "where": "resolver.ecocitizenz.org",
      "url": "https://resolver.ecocitizenz.org",
      "explained_at": "https://mcp.ecocitizenz.com/trust-mcp",
      "external": true,
      "writes_authoritative_state": false
    }
  ],
  "related_external_sites": [
    {
      "id": "msp-vertical",
      "name": "ECZ-ID for MSPs & MSSPs",
      "url": "https://msp.ecocitizenz.com",
      "role": "Vertical site for managed service providers: machine actors across a managed client estate, the authority behind them, and a free structured self-assessment.",
      "free_self_assessment_url": "https://msp.ecocitizenz.com/trust-check",
      "is_route_of_this_site": false,
      "is_layer_surface": false,
      "writes_authoritative_state": false,
      "publishes_proof": false,
      "self_assessment_is_audit": false,
      "self_assessment_is_certification": false,
      "self_assessment_is_compliance_determination": false,
      "superseded_paths_on_this_site": {
        "/msp": "https://msp.ecocitizenz.com/",
        "/msp/trust-check": "https://msp.ecocitizenz.com/trust-check"
      },
      "redirect_status": 308
    }
  ],
  "commercial_surface": {
    "id": "trustops",
    "name": "TrustOps",
    "kind": "commercial",
    "role": "Commercial surface — entitlement and order state. Authoritative for order and payment status; it publishes no proof.",
    "where": "trustops.ecocitizenz.com",
    "url": "https://trustops.ecocitizenz.com",
    "is_layer_surface": false,
    "publishes_proof": false,
    "writes_authoritative_state": false
  },
  "live_proof_snapshot": {
    "ecz_id": "ECZ-GB-RBS1NW",
    "record_type": "ECZ_ID_PARENT",
    "captured_at": "2026-08-23T02:07:25Z",
    "is_proof": false,
    "is_live": false,
    "role": "STALE_ABLE_SNAPSHOT",
    "canonical_resolver_url": "https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW",
    "canonical_machine_url": "https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json",
    "note": "This is a transcript, captured at the time shown. A transcript can become stale. It is not proof. Always verify live.",
    "site_fetches_it_at_runtime": false,
    "can_rely_on": [
      "record_existence",
      "active_parent_state",
      "current_parent_tier",
      "public_resolver_visibility"
    ],
    "do_not_infer": [
      "legal_name",
      "domain_control",
      "api_control",
      "repository_control",
      "wallet_control",
      "asset_control",
      "agent_authority",
      "insurance",
      "regulatory_approval",
      "safety",
      "compliance",
      "business_quality",
      "live_operational_monitoring"
    ]
  },
  "purchase_semantics": {
    "purchaseBegins": "intake_scope_capacity_validation",
    "automatic_commencement": false,
    "reserves_start_date": false,
    "note": "Purchase starts the engagement and written intake; the delivery schedule is confirmed during intake."
  },
  "order_review_contract": {
    "status": "contract_defined_routes_not_asserted_live",
    "scheme": "https",
    "host": "trustops.ecocitizenz.com",
    "path": "/start/review",
    "intent_parameter": "intent",
    "intents": {
      "readiness-audit": "mcp_service_audit",
      "migration-sprint": "mcp_service_sprint",
      "ema-id-jag": "mcp_service_ema_pilot",
      "enterprise-pilot": "mcp_service_enterprise_pilot"
    },
    "direct_payment_links_permitted": false,
    "note": "This site never routes a buyer to a raw payment page. Whether a given service currently renders a review CTA is reported per service in acquisition.state."
  },
  "services": [
    {
      "id": "mcp-readiness-audit",
      "slug": "readiness-audit",
      "name": "MCP Readiness Audit",
      "url": "https://mcp.ecocitizenz.com/services/readiness-audit",
      "summary": "A structured audit of one MCP server or integration: protocol conformance, transport and session behaviour, authorization boundaries, client compatibility risks and operational readiness. You receive a severity-ranked findings report and a prioritised remediation plan your engineering and security teams can act on.",
      "price_display": "£395",
      "price_from_gbp": 395,
      "price_is_from": false,
      "payment": "£395, paid in full at checkout.",
      "due_at_checkout_gbp": 395,
      "milestones": [
        {
          "trigger": "On purchase",
          "amount_gbp": 395,
          "share": "100%"
        }
      ],
      "cta_label": "Start the audit — £395",
      "acquisition": {
        "state": "PURCHASABLE",
        "review_intent": "mcp_service_audit",
        "review_url_shape": "https://trustops.ecocitizenz.com/start/review?intent=mcp_service_audit",
        "note": "Open for direct purchase through the TrustOps order review."
      },
      "included_passport": {
        "name": "ECZ-ID Business Passport",
        "duration_days": 90,
        "statement": "The applicable included Parent ECZ-ID Business Passport entitlement is created and activated automatically by the ECZ-ID backend once payment and account provisioning succeed — nothing to apply for, and no check stands in between. Later self-declared, verified, bound or referenced field evidence is separate from acquisition and is assessed afterwards by ECZ-ID Backend/Core, never created or promised by the purchase."
      }
    },
    {
      "id": "mcp-stateless-migration-sprint",
      "slug": "migration-sprint",
      "name": "Stateless Migration Sprint",
      "url": "https://mcp.ecocitizenz.com/services/migration-sprint",
      "summary": "A fixed-scope engineering sprint that migrates one existing MCP server from session-bound or legacy transport patterns to a stateless, horizontally deployable architecture — with tests, deployment and rollback documentation, and verification against named real clients.",
      "price_display": "£1,950",
      "price_from_gbp": 1950,
      "price_is_from": false,
      "payment": "£1,950 total: £1,170 initial milestone at checkout, £780 on acceptance.",
      "due_at_checkout_gbp": 1170,
      "milestones": [
        {
          "trigger": "On reservation",
          "amount_gbp": 1170,
          "share": "60%"
        },
        {
          "trigger": "On acceptance",
          "amount_gbp": 780,
          "share": "40%"
        }
      ],
      "cta_label": "Start the migration — £1,170",
      "acquisition": {
        "state": "PURCHASABLE",
        "review_intent": "mcp_service_sprint",
        "review_url_shape": "https://trustops.ecocitizenz.com/start/review?intent=mcp_service_sprint",
        "note": "Open for direct purchase through the TrustOps order review."
      },
      "included_passport": {
        "name": "ECZ-ID Business Passport",
        "duration_days": 90,
        "statement": "The applicable included Parent ECZ-ID Business Passport entitlement is created and activated automatically by the ECZ-ID backend once payment and account provisioning succeed — nothing to apply for, and no check stands in between. Later self-declared, verified, bound or referenced field evidence is separate from acquisition and is assessed afterwards by ECZ-ID Backend/Core, never created or promised by the purchase."
      }
    },
    {
      "id": "mcp-ema-id-jag-pilot",
      "slug": "ema-id-jag",
      "name": "EMA/ID-JAG Design & Pilot",
      "url": "https://mcp.ecocitizenz.com/services/ema-id-jag",
      "summary": "Architecture and pilot implementation for enterprise-managed authorization in MCP deployments: identity-boundary design, ID-JAG-style token exchange flows, scope and audience design, and a working pilot integrated with your existing identity provider. EcoCitizenz designs and pilots against your IdP — it does not replace it.",
      "price_display": "from £3,500",
      "price_from_gbp": 3500,
      "price_is_from": true,
      "payment": "From £3,500. £1,750 initial milestone at checkout; final scope and price confirmed in writing before any further milestone.",
      "due_at_checkout_gbp": 1750,
      "milestones": [
        {
          "trigger": "On start",
          "amount_gbp": 1750,
          "share": "50% of minimum"
        },
        {
          "trigger": "Per written scope confirmation",
          "amount_gbp": 1750,
          "share": "balance of minimum"
        }
      ],
      "cta_label": "Start the identity pilot — £1,750",
      "acquisition": {
        "state": "PURCHASABLE",
        "review_intent": "mcp_service_ema_pilot",
        "review_url_shape": "https://trustops.ecocitizenz.com/start/review?intent=mcp_service_ema_pilot",
        "note": "Open for direct purchase through the TrustOps order review."
      },
      "included_passport": {
        "name": "ECZ-ID Business Passport",
        "duration_days": 90,
        "statement": "The applicable included Parent ECZ-ID Business Passport entitlement is created and activated automatically by the ECZ-ID backend once payment and account provisioning succeed — nothing to apply for, and no check stands in between. Later self-declared, verified, bound or referenced field evidence is separate from acquisition and is assessed afterwards by ECZ-ID Backend/Core, never created or promised by the purchase."
      }
    },
    {
      "id": "mcp-enterprise-pilot",
      "slug": "enterprise-pilot",
      "name": "Enterprise MCP Pilot",
      "url": "https://mcp.ecocitizenz.com/services/enterprise-pilot",
      "summary": "An end-to-end enterprise engagement: discovery, target architecture, security and identity review, pilot implementation, client interoperability testing, deployment and rollback planning, and a full operational evidence pack — delivered with structured handover to your team.",
      "price_display": "£6,500",
      "price_from_gbp": 6500,
      "price_is_from": false,
      "payment": "£6,500 total: £2,600 (40%) initial milestone, £1,950 (30%) at the agreed implementation milestone, £1,950 (30%) on acceptance.",
      "due_at_checkout_gbp": 2600,
      "milestones": [
        {
          "trigger": "On reservation",
          "amount_gbp": 2600,
          "share": "40%"
        },
        {
          "trigger": "Agreed implementation milestone",
          "amount_gbp": 1950,
          "share": "30%"
        },
        {
          "trigger": "On acceptance",
          "amount_gbp": 1950,
          "share": "30%"
        }
      ],
      "cta_label": "Start the enterprise pilot — £2,600",
      "acquisition": {
        "state": "PURCHASABLE",
        "review_intent": "mcp_service_enterprise_pilot",
        "review_url_shape": "https://trustops.ecocitizenz.com/start/review?intent=mcp_service_enterprise_pilot",
        "note": "Open for direct purchase through the TrustOps order review."
      },
      "included_passport": {
        "name": "ECZ-ID Business Passport",
        "duration_days": 90,
        "statement": "The applicable included Parent ECZ-ID Business Passport entitlement is created and activated automatically by the ECZ-ID backend once payment and account provisioning succeed — nothing to apply for, and no check stands in between. Later self-declared, verified, bound or referenced field evidence is separate from acquisition and is assessed afterwards by ECZ-ID Backend/Core, never created or promised by the purchase."
      }
    }
  ],
  "included_business_passport": {
    "name": "ECZ-ID Business Passport",
    "description": "machine-readable business profile for the emerging agent and machine economy",
    "duration_days": 90,
    "startsOn": "backend_activation",
    "starts_on_note": "The period begins at successful provisioning and activation by ECZ-ID Backend/Core. An attempted or failed payment starts nothing.",
    "autoRenew": false,
    "auto_charge_at_expiry": false,
    "included_with": "every paid MCP professional service",
    "is_separate_product": false,
    "is_coupon": false,
    "purchase_creates": "included_parent_entitlement_on_successful_provisioning",
    "acquisition": {
      "provisioning": "automatic_on_successful_purchase",
      "activates_included_entitlement_on_successful_provisioning": true,
      "frictionless": true,
      "acquisition_checks_required": false,
      "requires_kyc": false,
      "requires_kyb": false,
      "requires_qualification": false,
      "requires_identity_verification": false,
      "requires_assurance": false,
      "requires_operator_approval": false,
      "failed_or_attempted_payment_activates": false
    },
    "payment_creates_status": false,
    "payment_certifies_or_completes_engagement": false,
    "payment_verifies_customer_or_mcp": false,
    "statuses_not_created_by_payment": [
      "declared",
      "verified",
      "assured",
      "bound",
      "approved",
      "safe"
    ],
    "later_evidence_states_are_separate_from_acquisition": true,
    "holder_controls": {
      "optional_profile_data": true,
      "bindings": true,
      "managed_through": "trustops"
    },
    "authority": {
      "writes_authoritative_state": "backend_core",
      "resolver_role": "read_only_permitted_projection",
      "replaces_production_evidence_pack": false,
      "relationship_to_evidence_pack": "adjunct"
    },
    "field_classes": [
      {
        "label": "Verified",
        "meaning": "Checked by ECZ-ID against a defined check. The check that was run is identifiable."
      },
      {
        "label": "Self-declared",
        "meaning": "Supplied by the holder and published as their statement. Useful, and not independently checked."
      },
      {
        "label": "Bound",
        "meaning": "Cryptographically or operationally tied to a control the holder demonstrated, such as a domain or an endpoint."
      },
      {
        "label": "Referenced",
        "meaning": "Points at something maintained elsewhere. It is only ever as current as that source."
      }
    ],
    "completeness_note": "Completeness and usefulness depend on the information and bindings the holder maintains. This is not a claim that the page contains everything, proves compliance, or makes its holder the correct choice.",
    "boundaries": [
      "Payment does not create Declared, Verified, Assured or BOUND status, and does not make anything approved, compliant or safe. Paying does not verify, certify, assure or approve you or your MCP implementation.",
      "Getting the included Passport is frictionless: no eligibility assessment, no qualification, no identity verification and no approval step stands between a successful purchase and an active entitlement.",
      "The 90 days start at successful provisioning and activation. An attempted or failed payment starts nothing.",
      "Adding profile details and field-level declared, verified, bound or referenced evidence comes later and is a separate matter from holding the entitlement.",
      "There is no automatic charge and no automatic renewal at day 91.",
      "ECZ-ID Backend/Core writes authoritative state. The public Resolver renders a read-only projection of what that state permits.",
      "Verified, self-declared, bound and referenced information stay visibly distinct on the Resolver page. A reader can always tell which is which.",
      "The Resolver page is an adjunct to your confidential Production Evidence Pack, never a replacement for it. The evidence pack goes to you; the Resolver page is what you can point others at.",
      "The page is as complete and as useful as the information and bindings you choose to maintain. It does not claim to contain everything about your business."
    ]
  },
  "microsoft_certification_readiness": {
    "microsoft_operates_certification": true,
    "ecocitizenz_is_independent": true,
    "ecocitizenz_is_certifier": false,
    "ecocitizenz_acts_for_microsoft": false,
    "ecocitizenz_is_microsoft_approved_or_endorsed": false,
    "microsoft_controls_certification_outcome": true,
    "guarantees_microsoft_acceptance": false,
    "offered": [
      "independent_readiness_assessment",
      "evidence_mapping",
      "remediation_guidance"
    ],
    "readiness_matrix_areas": [
      "Publisher readiness",
      "Package and metadata readiness",
      "Authentication readiness",
      "Functional and documentation consistency",
      "Security and access posture",
      "Telemetry and traceability",
      "Responsible-AI exposure",
      "Ongoing-maintenance exposure"
    ],
    "is_certification": false,
    "is_approval": false,
    "is_compliance_attestation": false,
    "is_security_guarantee": false,
    "unknown_evidence_handling": "evidence_gap_or_owner_confirmation_required",
    "unknown_evidence_is_failure": false,
    "included_in": "mcp-readiness-audit",
    "creates_no_new_service_or_price": true,
    "primary_sources_retrieved": "2026-07-25",
    "primary_sources": [
      "https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-certification",
      "https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-server-certification"
    ]
  },
  "protocol_revision_readiness": {
    "release_label": "MCP 2026-07-28",
    "status": "published_stable",
    "is_final": true,
    "is_stable": true,
    "publication_date": "2026-07-28",
    "introduces": [
      "stateless_protocol_core",
      "per_request_version_and_capability_metadata",
      "server_discover",
      "subscriptions_listen",
      "multi_round_trip_requests",
      "versioned_extensions",
      "authorization_changes",
      "caching_metadata",
      "formal_feature_deprecation"
    ],
    "ecosystem_adoption_varies": true,
    "earlier_versions_remain_negotiable": true,
    "universal_sdk_adoption_claimed": false,
    "universal_client_adoption_claimed": false,
    "universal_server_adoption_claimed": false,
    "migration_is_automatic": false,
    "is_mandatory_certification_requirement": false,
    "is_shutdown_deadline": false,
    "implies_existing_servers_will_break": false,
    "certifies_protocol_compliance": false,
    "publication_proves_production_readiness": false,
    "findings_reported_against_target_revision": true,
    "readiness_areas": [
      "Stateless-core assumptions",
      "Removed handshake",
      "Removed protocol-level sessions",
      "Routing and version metadata",
      "Extensions",
      "Tasks",
      "MCP Apps",
      "Authorization hardening"
    ],
    "included_in": "mcp-readiness-audit",
    "primary_sources_retrieved": "2026-07-28",
    "primary_sources": [
      "https://github.com/modelcontextprotocol/modelcontextprotocol/releases/tag/2026-07-28",
      "https://modelcontextprotocol.io/specification/2026-07-28/changelog"
    ]
  },
  "ongoing_packages": {
    "role": "continuation_after_delivery",
    "operated_by": "trustops",
    "acquisition_url": "https://trustops.ecocitizenz.com/start",
    "part_of_fixed_price_services": false,
    "engagement_never_auto_enrols": true,
    "products": [
      {
        "name": "ECZ-ID MCP Verifier™",
        "price_display": "Free",
        "recurring_monthly": false,
        "purpose": "Resolve a Passport, inspect what a page actually asserts, and see the basis of each field.",
        "best_for": "Anyone checking a provider before they rely on it."
      },
      {
        "name": "ECZ-ID MCP Assurance™",
        "price_display": "£199/month",
        "recurring_monthly": true,
        "purpose": "Keep your MCP provider identity and evidence current and independently resolvable, with the lifecycle operations that hold it accurate as your surfaces change.",
        "best_for": "Providers whose customers re-check them."
      },
      {
        "name": "ECZ-ID MCP Assurance Plus™",
        "price_display": "£499/month",
        "recurring_monthly": true,
        "purpose": "Extend that evidence posture across broader MCP surfaces and targets, within the entitlements the canonical product defines.",
        "best_for": "Providers operating several surfaces or targets."
      },
      {
        "name": "ECZ-ID MCP Policy™",
        "price_display": "£1,499/month",
        "recurring_monthly": true,
        "purpose": "Publish machine-readable buyer-side acceptance policy for MCP surfaces — what your organisation will and will not accept from what it consumes, stated under your own authority.",
        "best_for": "Buying organisations consuming third-party MCP surfaces."
      }
    ],
    "boundary": "These packages keep a published projection current and re-checkable. These packages are not certification, not compliance approval and not a security guarantee; the Verifier does not certify the party being checked, and MCP Policy is buyer-side policy that does not replace an identity provider, a gateway or a firewall. The four professional services above are fixed-scope engagements with published totals and milestones — they are not subscriptions, never convert into one, and buying an engagement never enrols you in one."
  },
  "forbidden_inferences": [
    "safety",
    "certification",
    "approval",
    "compliance",
    "endorsement",
    "guaranteed_compatibility",
    "authoritative_identity_state",
    "status_conferred_by_payment",
    "directory_acceptance"
  ],
  "recheck_before_reliance": true
}