For security and platform teams

Know your MCP server's security posture — and decide what's allowed to ship.

42Crunch audits, scans, and scores every MCP server against a deterministic baseline. You set the threshold that decides what's good enough for production — and every finding comes with the remediation guidance to get a server over that bar.

Why this matters

A security review that goes stale the day it's filed isn't a posture — it's a snapshot.

Most teams shipping MCP servers today have no consistent way to answer a basic question: is this server actually safe to expose to an agent? A one-time review answers that for a moment, then drifts out of date the next time the server changes. 42Crunch replaces the snapshot with a posture — a score that's recomputed on every audit and every scan, backed by a threshold your organization controls, and a gate that enforces it automatically.

How posture gets assessed

Audit the declaration. Scan the live server. Score both.

Two engines, two different jobs, one deterministic result.

MCP Audit — static analysis

Runs automatically on every MCP Contract, no live connection required. PromptDefense and YARA engines scan every tool and prompt description for agent-facing threats — prompt injection, tool poisoning, data exfiltration, tool shadowing — and structural checks cover authentication, authorization, and rate-limiting design. Every finding carries a severity and a remediation string.

See MCP Audit →

MCP Scan — live analysis

Connects to the running server and probes what the contract can't tell you: eight protocol-level checks drawn from the OWASP MCP Security Cheat Sheet — unauthenticated access, missing TLS, no message signing, replay acceptance, spoofed identity — plus input-format fuzzing against every tool's declared parameters.

See MCP Scan →
The part most tools skip

You set the threshold. 42Crunch enforces it.

Every audit and scan rolls up into a single deterministic score and letter grade — the same server evaluated twice returns the same result, so it's usable as evidence, not an estimate. That score only matters if something is willing to act on it. The Security Quality Gate (SQG) is a minimum acceptable score your organization defines — a default baseline to start from, adjustable per server, per environment, or per risk tier — and it's checked automatically in CI/CD. A server below the threshold doesn't reach production. No manual override, no "we'll fix it later."

42Crunch MCP Governance Dashboard showing audit posture across every server, and a Security Quality Gate enforcing pass/fail scoring against a configurable minimum threshold
Below threshold never reaches production
From finding to fix

Remediation isn't a separate step — it's built into the finding.

A score that just says "no" isn't useful on its own. Every finding — from either engine — ships with the specific, actionable guidance to close it, so the path from a failed gate to a passing one is a known quantity, not a research project.

01

Assess

Audit and Scan run against the contract and the live server.

02

Score

Findings roll up into a deterministic score and grade.

03

Compare to threshold

The score is checked against your Security Quality Gate.

04

Remediate

Below the bar, every finding carries the fix required to clear it.

05

Re-assess & ship

Re-run Audit and Scan — once the gate passes, the server ships.

Compliance, for free

The same assessment doubles as audit evidence.

Findings are tagged against OWASP, the EU AI Act, ISO 42001, NIST AI RMF, and CSA AICM automatically as part of the same audit and scan — so a posture assessment doesn't just gate a release, it produces the evidence a regulator, auditor, or customer security review would ask for. See AI Regulatory Compliance for how that mapping works across geographies.

Deterministic, not LLM-judged. The same server evaluated twice returns the same score and the same findings — reproducible, not a best-effort opinion, and safe to build a hard production gate on top of.
Frequently asked

AI security posture assessment, answered.

What does a "security posture score" actually measure? +

A single deterministic score and letter grade computed from every Audit and Scan finding against an MCP server — covering agent-facing content threats, protocol-level risk, and structural contract quality. It's designed to be tracked over time and compared across every server in the organization, not read as a one-off report.

Can we set our own threshold, or is it fixed? +

You set it. The Security Quality Gate ships with a sensible default (score 75 / grade B) but it's fully adjustable — a stricter threshold for a server handling sensitive data, a looser one for an internal proof of concept, different thresholds per environment as a server moves from dev to production.

Does it actually block a non-compliant server, or just flag it? +

Both, depending on where it runs. In CI/CD, the Security Quality Gate refuses to let a server below the threshold pass — a hard block, not a warning. Outside a pipeline, the same score surfaces on the dashboard so a server can be triaged and remediated before it's ever pushed toward that gate.

How do we actually fix what the assessment finds? +

Every finding carries a remediation string — specific, actionable guidance tied to that exact issue, not a generic best-practices link. Re-running Audit and Scan after a fix recomputes the score immediately, so the loop from failed gate to passing gate is fast and visible.

How is this different from a one-time penetration test? +

A pen test is a snapshot — accurate the day it's delivered, and stale the moment the server changes. Posture assessment re-runs on every audit and scan, so drift between reviews shows up as a score change, not a surprise discovered at the next annual test.

Does this replace MCP Audit and MCP Scan, or sit on top of them? +

It's the same engines. Posture assessment is what you get when Audit and Scan results roll up into one score, compared against a threshold you control. See MCP Audit and MCP Scan for how each engine works underneath.

Get your MCP server's security posture score in 60 seconds.

Point 42Crunch at any MCP server and get a scored, graded report — plus the remediation guidance to close every gap. No agent, no deployment, no commitment required.