42Crunch audits, scans, and scores every MCP server against a deterministic baseline. You set the threshold that decides what's good enough for production — and every finding comes with the remediation guidance to get a server over that bar.
Most teams shipping MCP servers today have no consistent way to answer a basic question: is this server actually safe to expose to an agent? A one-time review answers that for a moment, then drifts out of date the next time the server changes. 42Crunch replaces the snapshot with a posture — a score that's recomputed on every audit and every scan, backed by a threshold your organization controls, and a gate that enforces it automatically.
Two engines, two different jobs, one deterministic result.
Runs automatically on every MCP Contract, no live connection required. PromptDefense and YARA engines scan every tool and prompt description for agent-facing threats — prompt injection, tool poisoning, data exfiltration, tool shadowing — and structural checks cover authentication, authorization, and rate-limiting design. Every finding carries a severity and a remediation string.
See MCP Audit →Connects to the running server and probes what the contract can't tell you: eight protocol-level checks drawn from the OWASP MCP Security Cheat Sheet — unauthenticated access, missing TLS, no message signing, replay acceptance, spoofed identity — plus input-format fuzzing against every tool's declared parameters.
See MCP Scan →Every audit and scan rolls up into a single deterministic score and letter grade — the same server evaluated twice returns the same result, so it's usable as evidence, not an estimate. That score only matters if something is willing to act on it. The Security Quality Gate (SQG) is a minimum acceptable score your organization defines — a default baseline to start from, adjustable per server, per environment, or per risk tier — and it's checked automatically in CI/CD. A server below the threshold doesn't reach production. No manual override, no "we'll fix it later."
A score that just says "no" isn't useful on its own. Every finding — from either engine — ships with the specific, actionable guidance to close it, so the path from a failed gate to a passing one is a known quantity, not a research project.
Audit and Scan run against the contract and the live server.
Findings roll up into a deterministic score and grade.
The score is checked against your Security Quality Gate.
Below the bar, every finding carries the fix required to clear it.
Re-run Audit and Scan — once the gate passes, the server ships.
Findings are tagged against OWASP, the EU AI Act, ISO 42001, NIST AI RMF, and CSA AICM automatically as part of the same audit and scan — so a posture assessment doesn't just gate a release, it produces the evidence a regulator, auditor, or customer security review would ask for. See AI Regulatory Compliance for how that mapping works across geographies.
A single deterministic score and letter grade computed from every Audit and Scan finding against an MCP server — covering agent-facing content threats, protocol-level risk, and structural contract quality. It's designed to be tracked over time and compared across every server in the organization, not read as a one-off report.
You set it. The Security Quality Gate ships with a sensible default (score 75 / grade B) but it's fully adjustable — a stricter threshold for a server handling sensitive data, a looser one for an internal proof of concept, different thresholds per environment as a server moves from dev to production.
Both, depending on where it runs. In CI/CD, the Security Quality Gate refuses to let a server below the threshold pass — a hard block, not a warning. Outside a pipeline, the same score surfaces on the dashboard so a server can be triaged and remediated before it's ever pushed toward that gate.
Every finding carries a remediation string — specific, actionable guidance tied to that exact issue, not a generic best-practices link. Re-running Audit and Scan after a fix recomputes the score immediately, so the loop from failed gate to passing gate is fast and visible.
A pen test is a snapshot — accurate the day it's delivered, and stale the moment the server changes. Posture assessment re-runs on every audit and scan, so drift between reviews shows up as a score change, not a surprise discovered at the next annual test.
Point 42Crunch at any MCP server and get a scored, graded report — plus the remediation guidance to close every gap. No agent, no deployment, no commitment required.