Skip to content
ECZ-IDMCP

Service terms

How engagements work, in plain language

This page summarises how engagements on this site work. It is a summary, not the contract: the full written engagement terms provided at intake govern each engagement, and where this summary and those terms differ, the engagement terms apply.

Last updated: July 2026

1. Fixed-scope engagements

Every service sold on this site is a fixed-scope professional engagement with a published price. There are no subscriptions on this site, and no discounts: the price published on each service page is the price everyone pays. Platform credits offered elsewhere in the EcoCitizenz ecosystem apply to eligible TrustOps subscription payments only, and never to these professional engagements.

The ongoing ECZ-ID MCP packages shown as a continuation route are separate monthly products operated by TrustOps. These packages are operated work on EVIDENCE, and they are a different axis from identity: your ECZ-ID and your Resolver record are free and permanent, and stay so whether or not you ever buy one of these. Nothing here is an endpoint allowance either — that is AEC, which is a third axis again. These packages keep a published projection current and re-checkable. These packages are not certification, not compliance approval and not a security guarantee; the Verifier does not certify the party being checked, and MCP Policy is buyer-side policy that does not replace an identity provider, a gateway or a firewall. The engagements above are fixed-scope with a written scope and defined milestones — they are not subscriptions, never convert into one, and agreeing an engagement never enrols you in one.

2. Payment and milestones

Every amount is quoted and taken through TrustOps. Some engagements are a single fixed fee; others are split into milestones, with later amounts falling due only at the triggers agreed in writing. TrustOps is authoritative for price, payment and order status — if anything on this page and your TrustOps record ever disagree about an order, the TrustOps record is correct.

This site publishes no amounts. The table below is the SHAPE of each commitment, which is what a written scope fixes; the figures attached to it are TrustOps’, are quoted before anything is agreed, and are not restated here — a second copy of a price is a second thing that can go out of date.

Commitment shape per engagement: how each engagement is committed to, and when milestones fall due
EngagementHow it is committed to
MCP Readiness AuditOne fixed fee, agreed in writing before the audit begins.
Stateless Migration SprintTwo milestones — one on reservation, the balance on acceptance against the agreed criteria.
EMA/ID-JAG Design & PilotAn initial milestone to start the design, then a written scope after design review. No further milestone is due before that written confirmation.
Enterprise MCP PilotThree milestones — reservation, the implementation milestone defined in the written scope, and acceptance.

Each engagement page states exactly what falls due when. The amounts themselves are quoted by TrustOps and fixed in the written scope before anything is agreed.

3. Refunds

If EcoCitizenz declines an engagement before commencement — for example because intake shows the work is out of scope for a fixed-scope engagement — the amount you paid is refunded in full. After commencement, milestones track delivered work: later milestones fall due only at the agreed triggers, such as acceptance against the criteria fixed in the written scope, and never before. The per-service position is:

  • MCP Readiness Audit: Nothing is due until the written scope is agreed, and anything already paid is refunded in full if EcoCitizenz declines the engagement before commencement.
  • Stateless Migration Sprint: The initial milestone is refunded in full if EcoCitizenz declines the engagement before commencement.
  • EMA/ID-JAG Design & Pilot: The initial milestone is refunded in full if EcoCitizenz declines the engagement before commencement.
  • Enterprise MCP Pilot: The initial milestone is refunded in full if EcoCitizenz declines the engagement before commencement.

Refunds are processed back through the original TrustOps payment, and TrustOps is authoritative for their status.

4. Scope and change control

Every engagement runs against a written scope agreed before work begins. The written scope fixes the deliverables, the exclusions, the acceptance criteria and the named clients that validation runs against. Requests outside that scope follow change control: they are assessed, priced and agreed in writing before any work proceeds — no silent scope growth, and no surprise invoices.

Your delivery schedule is confirmed during intake.

5. Customer responsibilities

Fixed timetables depend on timely inputs. Each engagement asks you to provide the inputs listed on its service page — typically repository or environment access at the agreed level, relevant configuration, and answers to clarification questions — and to nominate a reviewer empowered to accept deliverables against the agreed criteria. Where inputs are delayed, delivery dates move with them; the written engagement terms set out how.

6. Subcontractors

EcoCitizenz may use appropriately vetted specialists or subcontractors to support delivery. EcoCitizenz remains responsible for the agreed deliverables. Any specialist access to customer systems or confidential information will be disclosed and governed by the engagement terms.

7. Intellectual property and handover

Implementation work is delivered into your repository, as reviewable changes, and stays there: the engagement ends with structured handover, not a dependency on us. Deliverables — reports, evidence packs, runbooks and documentation — are provided for your use. EcoCitizenz retains its pre-existing methods, tools, templates and know-how; nothing in an engagement transfers ownership of those, and nothing in this summary restricts your use of your own systems and code.

8. What we do not promise

Honest boundaries matter more on a terms page than anywhere else. Each limit on an engagement is stated below in full, so that no line can be read apart from the context that qualifies it.

  • An engagement does not provide certification, regulatory approval or any compliance attestation.
  • An engagement is not a security guarantee. Reviews and testing reduce risk; nothing eliminates it.
  • An engagement does not guarantee compatibility with every MCP client. Validation runs against the clients named in your written scope, and the results are recorded whether they pass or fail.
  • An engagement does not confer approval by any client directory or third-party listing process.

What you receive instead is recorded evidence: findings, test results and documentation your own engineering, security and procurement reviewers can judge for themselves.

9. System boundaries

This website explains MCP identity and the engagements around it. Acquisition, payment, entitlement and every published price are handled by TrustOps. Canonical ECZ-ID state is held by the ECZ-ID backend; the public Resolver is a read-only projection of proof. Nothing on this site creates or amends authoritative ECZ-ID state.

10. ECZ-ID Business Passport — evidence-state definitions

Your organisation’s ECZ-ID Business Passport record is free and permanent, and holding one has never required a purchase. Where an organisation has none, a DECLARED parent record is created automatically during account setup for a paid engagement. The definitions below state precisely what that record is and is not:

  • Payment does not create Declared, Verified, Assured or BOUND status, and does not make anything approved, compliant or safe. Paying does not verify, certify, assure or approve you or your MCP implementation.
  • Getting a Business Passport is frictionless: no eligibility assessment, no qualification, no identity verification and no approval step stands between asking for one and holding one. It is also free, and holding one has never required a purchase.
  • The record is permanent. It does not expire, and it does not lapse because an engagement ended or a subscription was never bought.
  • The 90 days of Verified access included with a paid engagement start at successful provisioning and activation. An attempted or failed payment starts nothing.
  • There is no automatic charge and no automatic renewal at day 91. When the included Verified period ends the organisation returns to the Declared tier, which is free and permanent, and the ECZ-ID does not change.
  • Adding profile details and field-level declared, verified, bound or referenced evidence comes later and is a separate matter from holding the record.
  • ECZ-ID Backend/Core writes authoritative state. The public Resolver renders a read-only projection of what that state permits.
  • Verified, self-declared, bound and referenced information stay visibly distinct on the Resolver page. A reader can always tell which is which.
  • The Resolver page is an adjunct to your confidential Production Evidence Pack, never a replacement for it. The evidence pack goes to you; the Resolver page is what you can point others at.
  • The page is as complete and as useful as the information and bindings you choose to maintain. It does not claim to contain everything about your business.

11. Contact

Questions about these terms, an order or an engagement in progress: write to mcp@ecocitizenz.com or use the contact page. A person reads every message and replies by email.

More on ECZ-ID MCP