FAQ
Questions answered straight
Everything a buyer needs to know before paying: how purchase works, who delivers, when work begins, what gets refunded and where the hard boundaries sit. Where the honest answer is “no”, we say so.
Buying
How purchase works: published prices, direct TrustOps checkout, VAT, and which service to choose first.
Can I buy without a sales call?
Yes. Every service publishes its fixed price and full scope, and no call is required. Checkout is hosted by TrustOps — you review your order before any payment step. You can ask us anything by email first.
What happens immediately after I pay?
TrustOps confirms your order and opens the intake form for your service. You provide the agreed inputs (for example repository access and your intended client list), we validate scope, and we confirm your start date with you during intake. If we conclude the engagement is not a fit before commencement, the amount paid is refunded in full.
Which service should I start with?
If you are unsure, start with the MCP Readiness Audit (£395). It produces a severity-ranked findings report and remediation plan, and it tells you precisely whether a Migration Sprint, identity work or an Enterprise Pilot is worth buying. The free scanner also maps its findings to a recommended next step.
Are there discounts or promotional codes?
No. The professional services on this site are fixed-price engagements and are never discounted — the published price is the price everyone pays. Any platform credit offered elsewhere in the EcoCitizenz ecosystem applies to eligible TrustOps subscription payments only, never to these engagements.
Are any of these services subscriptions?
No. Every one of the four services is a fixed-scope engagement with a defined completion: no subscription, no auto-renewal and no recurring charge is attached to any of them, and buying one never enrols you in anything ongoing. The ongoing ECZ-ID MCP packages shown lower down the page are separate optional products, priced monthly and operated by TrustOps under their own terms. They are a continuation route you choose after delivery, not part of these engagements.
Do prices include VAT?
Prices are shown exclusive of VAT. Any applicable VAT is calculated and shown at TrustOps checkout before you pay.
Delivery
Who does the work, when it starts, which stacks are supported, how client compatibility is verified and how refunds operate.
Who actually does the work?
Engagements are delivered by EcoCitizenz. EcoCitizenz may use appropriately vetted specialists or subcontractors to support delivery; EcoCitizenz remains responsible for the agreed deliverables, and any specialist access to your systems or confidential information is disclosed and governed by the engagement terms.
When can work begin?
Delivery start is confirmed after intake and scope validation — typically discussed at the kickoff scheduled once your intake is complete. We do not promise immediate starts, because scope validation protects both sides from a mis-sold engagement.
Which languages and frameworks do you support?
The supported implementation is agreed during qualification, before any milestone is fixed in writing. Typical engagements involve TypeScript/Node and Python MCP implementations; other stacks are assessed case by case. If we cannot support your stack, we say so before commencement and refund anything paid.
Do you guarantee my server will work with every MCP client?
No — and you should be wary of anyone who does. Client behaviour varies and changes. Instead, we agree a named list of real clients and test conditions in the written scope, verify against those, and record the results in your evidence pack. That gives you concrete, reproducible evidence rather than a blanket promise.
What is the refund position?
If EcoCitizenz declines an engagement before commencement — for example because qualification shows the scope is not a fit — the amount paid is refunded in full. After commencement, milestone payments track delivered work as set out in the engagement terms, and later milestones fall due only at the agreed triggers such as acceptance.
Security & boundaries
System access, identity, ECZ-ID state, Microsoft certification readiness and what these services deliberately do not claim.
Do you need access to our production systems?
Usually not. Audits work from repository read access and configuration with secrets redacted. Implementation work happens in branches and staging environments under your control. Production access is requested only if the agreed scope requires it, with least-privilege credentials that you issue, control and can revoke — and only with explicit written authorisation.
Does the identity service replace our identity provider?
No. EcoCitizenz is not an identity provider. The EMA/ID-JAG engagement designs and pilots authorization flows against your existing identity infrastructure — for example Okta, Microsoft Entra ID or Ping — and hands the result over to your team.
Does buying a service create or change ECZ-ID state?
This website never writes canonical ECZ-ID state — no page, badge or scan here creates, activates or amends it. What a successful purchase does do: payment plus successful account provisioning trigger the contracted ECZ-ID backend activation path, and the backend automatically creates and activates your included Parent Business Passport entitlement. The public Resolver remains a read-only projection of proof. Payment does not verify, certify or approve you or your MCP implementation, does not complete service delivery and does not establish customer acceptance.
What exactly activates after I pay, and when do the 90 days start?
Every paid MCP professional service includes a 90-day Parent ECZ-ID Business Passport. Once your payment succeeds and your account is provisioned, the ECZ-ID backend automatically creates and activates the applicable included entitlement — there is no KYC, KYB, eligibility assessment, qualification, identity check, assurance step or operator approval to pass. The 90 days run from that automatic activation, and dashboard access, your Parent Resolver page, badge and QR are included. Nothing renews automatically and nothing is charged at day 91. Adding self-declared, verified, bound or referenced profile evidence is a separate, later matter — it is never created by the purchase.
Is the free scanner safe to use on our code and configs?
The scanner is passive by design. The configuration analysis runs entirely in your browser — nothing you paste is uploaded, stored or executed. It never runs your code or packages, and any future network-based checks require your explicit consent before a single request is made. The scanner's results page states exactly what was and was not examined.
Will this certify us as secure or compliant?
No. These services do not provide certification, regulatory approval, compliance attestation or a security guarantee — no consultancy honestly can. What you receive is documented, reproducible evidence of what was assessed, changed and verified, in a form your security and procurement reviewers can evaluate against their own standards.
Can you get us Microsoft MCP server certification?
No — and nobody outside Microsoft can. Microsoft operates its own MCP server certification process for its supported surfaces, and Microsoft alone decides review, approval and publication. EcoCitizenz is independent: we are not Microsoft, we do not act for Microsoft, we are not a Microsoft certification authority, and we are neither Microsoft-approved nor Microsoft-endorsed. What the £395 Readiness Audit can include, where your agreed scope and available evidence make it relevant, is an independent readiness matrix mapped against Microsoft's published requirements — publisher and package readiness, authentication, documentation consistency, telemetry and responsible-AI exposure — plus prioritised remediation guidance. That is preparation and evidence mapping, not certification, and it does not guarantee that a submission will be accepted.
What about MCP 2026-07-28?
MCP 2026-07-28 is a published stable specification release. It introduces a stateless protocol core, per-request version and capability metadata, server/discover, subscriptions/listen, Multi Round-Trip Requests, versioned extensions, authorization changes, caching metadata and formal feature deprecation. Ecosystem adoption varies, and clients and servers may continue to support and negotiate earlier protocol versions — publication is not a deadline, and it does not mean existing MCP servers stop working. The Audit can map your implementation's exposure to it — stateless-core assumptions, the removed handshake and protocol-level sessions, routing and version metadata, Extensions, Tasks, MCP Apps and authorization hardening — reported against the protocol revision you actually target.
Still unsure?
Ask before you buy. The contact form needs two fields, and we will tell you plainly whether a service fits — including when the answer is that it does not.