FAQ
Questions answered straight
Everything a buyer needs to know before paying: how purchase works, who delivers, when work begins, what gets refunded and where the hard boundaries sit. Where the honest answer is “no”, we say so.
Buying
How purchase works: published prices, direct TrustOps checkout, tax, and which service to choose first.
Can I buy without a sales call?
Yes. Every service publishes its fixed price and full scope, and no call is required. Checkout is hosted by TrustOps — you review your order before any payment step. You can ask us anything by email first.
What happens immediately after I pay?
TrustOps confirms your order and opens the intake form for your service. You provide the agreed inputs (for example repository access and your intended client list), we validate scope, and we confirm your start date with you during intake. If we conclude the engagement is not a fit before commencement, the amount paid is refunded in full.
Which service should I start with?
If you are unsure, start with the MCP Readiness Audit — the smallest of the four. It produces a severity-ranked findings report and remediation plan, and it tells you precisely whether a Migration Sprint, identity work or an Enterprise Pilot is worth doing. The free Config Check also maps its findings to a recommended next step.
Are there discounts or promotional codes?
No. The professional services on this site are fixed-price engagements and are never discounted — the published price is the price everyone pays. Any platform credit offered elsewhere in the EcoCitizenz ecosystem applies to eligible TrustOps subscription payments only, never to these engagements.
Are any of these services subscriptions?
No. Every one of the four services is a fixed-scope engagement with a defined completion: no subscription, no auto-renewal and no recurring charge is attached to any of them, and buying one never enrols you in anything ongoing. The ongoing ECZ-ID MCP packages shown lower down the page are separate optional products, priced monthly and operated by TrustOps under their own terms. They are a continuation route you choose after delivery, not part of these engagements.
Is VAT added to these prices?
No. EcoCitizenz Ltd is not VAT-registered, so no VAT is added and no VAT invoice is issued. If you are buying from outside the United Kingdom your own country's tax rules may still apply, and any such amount is shown at checkout before you pay.
Delivery
Who does the work, when it starts, which stacks are supported, how client compatibility is verified and how refunds operate.
Who actually does the work?
Engagements are delivered by EcoCitizenz. EcoCitizenz may use appropriately vetted specialists or subcontractors to support delivery; EcoCitizenz remains responsible for the agreed deliverables, and any specialist access to your systems or confidential information is disclosed and governed by the engagement terms.
When can work begin?
Delivery start is confirmed after intake and scope validation — typically discussed at the kickoff scheduled once your intake is complete. We do not promise immediate starts, because scope validation protects both sides from a mis-sold engagement.
Which languages and frameworks do you support?
The supported implementation is agreed during qualification, before any milestone is fixed in writing. Typical engagements involve TypeScript/Node and Python MCP implementations; other stacks are assessed case by case. If we cannot support your stack, we say so before commencement and refund anything paid.
Do you guarantee universal compatibility across MCP clients?
No — and you should be wary of anyone who does. Client behaviour varies and changes. Instead, we agree a named list of real clients and test conditions in the written scope, verify against those, and record the results in your evidence pack. That gives you concrete, reproducible evidence rather than a blanket promise.
What is the refund position?
If EcoCitizenz declines an engagement before commencement — for example because qualification shows the scope is not a fit — the amount paid is refunded in full. After commencement, milestone payments track delivered work as set out in the engagement terms, and later milestones fall due only at the agreed triggers such as acceptance.
Security & boundaries
System access, identity, ECZ-ID state, Microsoft certification readiness and what these services deliberately do not claim.
Do you need access to our production systems?
Usually not. Audits work from repository read access and configuration with secrets redacted. Implementation work happens in branches and staging environments under your control. Production access is requested only if the agreed scope requires it, with least-privilege credentials that you issue, control and can revoke — and only with explicit written authorisation.
Does the identity service replace our identity provider?
No. EcoCitizenz is not an identity provider. The EMA/ID-JAG engagement designs and pilots authorization flows against your existing identity infrastructure — for example Okta, Microsoft Entra ID or Ping — and hands the result over to your team.
Does buying a service create or change ECZ-ID state?
This website never writes canonical ECZ-ID state — no page, badge or check here creates, activates or amends it. What a successful purchase does do: payment plus successful account provisioning trigger the contracted ECZ-ID backend activation path, and where your organisation holds no ECZ-ID the backend automatically creates and activates a free DECLARED parent record. The public Resolver remains a read-only projection of proof. Payment does not verify, certify or approve you or your MCP implementation, does not complete service delivery and does not establish customer acceptance.
What exactly activates after I pay, and do I have to pay to have an ECZ-ID?
You do not have to pay to have an ECZ-ID, and you never did have to buy an engagement to get one. A parent ECZ-ID Business Passport record is free and permanent, and an MCP Passport for a server you operate is free too. What happens after a purchase: once your payment succeeds and your account is provisioned, the ECZ-ID backend automatically creates and activates a DECLARED parent record if your organisation did not already hold one — there is no KYC, KYB, eligibility assessment, qualification, identity check, assurance step or operator approval to pass. Your Resolver page, badge and QR come with the record itself, not with the payment. Adding self-declared, verified, bound or referenced profile evidence is a separate, later matter — it is never created by the purchase.
Is the free Config Check safe to use on our code and configs?
The Config Check is passive by design. The configuration analysis runs entirely in your browser — nothing you paste is uploaded, stored or executed. It never runs your code or packages, and any future network-based checks require your explicit consent before a single request is made. The Config Check's results page states exactly what was and was not examined.
Will this certify us as secure or compliant?
No. These services provide no certification, no regulatory approval, no compliance attestation and no security guarantee — no consultancy honestly can. What you receive is documented, reproducible evidence of what was assessed, changed and verified, in a form your security and procurement reviewers can evaluate against their own standards.
Can you get us Microsoft MCP server certification?
No — and nobody outside Microsoft can. Microsoft operates its own MCP server certification process for its supported surfaces, and Microsoft alone decides review, approval and publication. EcoCitizenz is independent: we are not Microsoft, we do not act for Microsoft, we are not a Microsoft certification authority, and we are neither Microsoft-approved nor Microsoft-endorsed. What the Readiness Audit can include, where your agreed scope and available evidence make it relevant, is an independent readiness matrix mapped against Microsoft's published requirements — publisher and package readiness, authentication, documentation consistency, telemetry and responsible-AI exposure — plus prioritised remediation guidance. That is preparation and evidence mapping, not certification, and it does not guarantee that a submission will be accepted.
What about MCP 2026-07-28?
MCP 2026-07-28 is a published stable specification release. It introduces a stateless protocol core, per-request version and capability metadata, server/discover, subscriptions/listen, Multi Round-Trip Requests, versioned extensions, authorization changes, caching metadata and formal feature deprecation. Ecosystem adoption varies, and clients and servers may continue to support and negotiate earlier protocol versions — publication is not a deadline, and it does not mean existing MCP servers stop working. The Audit can map your implementation's exposure to it — stateless-core assumptions, the removed handshake and protocol-level sessions, routing and version metadata, Extensions, Tasks, MCP Apps and authorization hardening — reported against the protocol revision you actually target.
Still unsure?
Ask before you buy. The contact form needs two fields, and we will tell you plainly whether a service fits — including when the answer is that it does not.
