How the practice works

Scan, audit, build, assure.

Four rungs, one operator. Each stands on the one before it, each is a fine place to start, and only the first one is mandatory-feeling — because it's free and takes a minute. You own everything that gets produced: the report, the server, the code.

01

Scan

Freeabout a minute, on screen

Enter a work email or just your company website. We read public DNS and your homepage — nothing invasive — and map every tool we can confirm against the MCP ecosystem: agent-reachable today, or build territory. On screen in about a minute, no email, no account.

02

Audit

$3,5002 weeks

The scan reads public records; the audit reads your actual stack, with you in the room. Auth boundaries, what an agent should and shouldn't reach, which gaps are worth closing and in what order, and what each costs. You get a written readiness report that's yours to act on — with me or without me.

  • Stack + auth-boundary map
  • Gaps ranked by value, not by ease
  • Priced 90-day plan you can execute with anyone
03

Build

from $7,500typically 2–3 weeks

I build the server against your real systems — the tools an agent can call, the shape of what comes back, and the error cases that matter when a model is the caller. It reaches only what you authorise, runs wherever you want, and at handover you get the code, the deploy setup, and docs. No platform, no lock-in.

  • Source in your repo, MIT or your licence
  • Deploy setup for wherever you run it
  • Tool docs written for the next engineer
04

Assure — servers you already run

$2,5003–5 days

MCP deployments are a new attack surface — tool poisoning and over-broad scopes are named problems now, not hypotheticals. I review servers you already run, yours or a vendor's: what the agent can actually reach versus what you think it can, where auth is soft, and what to fix first.

  • Tool-surface and permission audit
  • Prompt-injection and tool-poisoning exposure
  • Findings ranked by blast radius, with fixes

Fixed fees, agreed in writing before work starts. No retainers, no platform fees, no per-seat licensing. If scoping shows the work is smaller than the price, the price comes down; if it’s bigger, you get the number before anyone commits.

Three separate tools, one operator.

Each is bought, priced and run on its own, and each is worth doing by itself — none of them is a prerequisite for another, and there's no order you have to follow. Doing them together does compound: a bill you've already cut is a cheaper, cleaner thing to connect an AI agent to. That's an option, not a gate.