Skip to main content

Flagship · MCP specialist kit

ECZ-ID MCP Security & Customer Assurance Kit

Turn MCP server, tool, operator and security evidence into a customer-ready assurance record.

A practical MCP evidence product for vendors and internal platform teams that have to answer the same security, identity and procurement questions for every customer — who operates the server, which tools it exposes, how authorisation is configured, what has been observed and what is actually enforced — without rebuilding the pack for each review.

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.

ECZ-ID MCP Security & Customer Assurance Kit: fit, outcomes and contents

Best for

  • MCP providers selling into enterprise security and procurement review.
  • Platform teams publishing internal MCP servers to other business units.
  • Vendors whose customers ask for tool-surface, authorisation and operator evidence before an agent may connect.

What you get out of it

  • Reusable MCP review evidence instead of a new pack for every questionnaire.
  • Clearer operator, server and tool-surface accountability, tied to the server's public ECZ-ID.
  • Faster procurement conversations, with OBSERVED facts and ENFORCED controls kept visibly apart.

What is included

  • MCP identity and operator evidence: the server's MCP Passport, its Parent record and the bindings a reviewer can re-check on the Resolver.
  • A tool-surface review structure: tool inventory, schemas, input validation, destructive-action safeguards and the provenance of tool descriptions.
  • Authorisation and deployment evidence prompts: how OAuth-based MCP authorization, transport and session state are configured — documented, not replaced.
  • An OBSERVED-versus-ENFORCED register, so every control is stated as either a published observation or an enforcement your own runtime performs.
  • Customer-facing assurance artefacts: a review pack, questionnaire-to-evidence mapping and a Resolver proof page to point reviewers at.

How it works

  1. Define the MCP surface: the server, its operator and the tools it exposes.

  2. Collect the identity, tool-surface, authorisation and deployment evidence you already hold.

  3. Resolve the material gaps — on your own, or with a fixed-scope professional service.

  4. Produce the customer review pack and keep it current as the server changes.

What it is not

  • The kit is an evidence product, not a certification of MCP security.
  • It organises evidence about your authorisation and runtime controls; it does not replace OAuth, your identity provider, MCP authorization or runtime mediation.
  • An observation recorded in the kit is not an enforced control. Enforcement stays in your own runtime and policy.

Professional services it pairs with

Price and availability

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.