.png)
MODEL CONTEXT PROTOCOL
Every MCP server you connect is a new door into your systems.
The Model Context Protocol makes it easy to plug an AI assistant into your calendar, codebase, CRM, or file storage — and just as easy to grant a poorly-vetted third-party server far more access than the task in front of it needs. We review MCP servers and tool permissions before they get standing access.
WHAT WE REVIEW
Four checks before an MCP server gets connected.
CHECK
WHAT WE LOOK FOR
Provenance
Who publishes and maintains the server, and how it's authenticated before your systems trust it.
Permission scope
Whether the server requests only the specific tools and data it needs, or broad, unscoped access.
Data handling
What data flows through the server, where it's processed, and whether that's acceptable under your data policies.
Supply chain
What the server itself depends on, and whether a compromise upstream could reach you through it.
WHY THIS MATTERS NOW
MCP adoption is outpacing MCP review.
Teams are connecting MCP servers the way they once installed browser extensions — quickly, based on convenience, with little scrutiny of what access is actually being granted. Unlike a browser extension, an MCP server can sit directly between an AI assistant and systems holding financial, customer, or source-code data.
We maintain a running inventory of MCP servers in use across your organization, review new ones before they're approved, and periodically re-check existing connections as servers update. This pairs directly with our Shadow AI discovery service, since unreviewed MCP servers are one of the most common forms shadow AI takes.