Scan, audit, build, assure.
Four rungs, one operator. Each stands on the one before it, each is a fine place to start, and only the first one is mandatory-feeling — because it's free and takes a minute. You own everything that gets produced: the report, the server, the code.
Scan
Enter a work email or just your company website. We read public DNS and your homepage — nothing invasive — and map every tool we can confirm against the MCP ecosystem: agent-reachable today, or build territory. On screen in about a minute, no email, no account.
Audit
The scan reads public records; the audit reads your actual stack, with you in the room. Auth boundaries, what an agent should and shouldn't reach, which gaps are worth closing and in what order, and what each costs. You get a written readiness report that's yours to act on — with me or without me.
- Stack + auth-boundary map
- Gaps ranked by value, not by ease
- Priced 90-day plan you can execute with anyone
Build
I build the server against your real systems — the tools an agent can call, the shape of what comes back, and the error cases that matter when a model is the caller. It reaches only what you authorise, runs wherever you want, and at handover you get the code, the deploy setup, and docs. No platform, no lock-in.
- Source in your repo, MIT or your licence
- Deploy setup for wherever you run it
- Tool docs written for the next engineer
Assure — servers you already run
MCP deployments are a new attack surface — tool poisoning and over-broad scopes are named problems now, not hypotheticals. I review servers you already run, yours or a vendor's: what the agent can actually reach versus what you think it can, where auth is soft, and what to fix first.
- Tool-surface and permission audit
- Prompt-injection and tool-poisoning exposure
- Findings ranked by blast radius, with fixes
Fixed fees, agreed in writing before work starts. No retainers, no platform fees, no per-seat licensing. If scoping shows the work is smaller than the price, the price comes down; if it’s bigger, you get the number before anyone commits.
Three separate tools, one operator.
Each is bought, priced and run on its own, and each is worth doing by itself — none of them is a prerequisite for another, and there's no order you have to follow. Doing them together does compound: a bill you've already cut is a cheaper, cleaner thing to connect an AI agent to. That's an option, not a gate.
Connect
Free 60-second scan · you own the code
Scan your stack free to see what AI agents can already reach — then close the gaps with an MCP server scoped to your systems.
Stands alone: no audit and no cuts required first. Bring the stack you already have.
Diagnose
Free · 2 minutes · no account
Detect the tools you actually run from public records, model the rest, and surface every category you pay for twice.
Stands alone: take the numbers into your own renewal review and stop there.
fatsaas.com →Cut — guaranteed
3× the fee in cuts, or you pay nothing
A prioritized consolidation plan run by a vendor-neutral operator — biggest, least-disruptive cuts first.
Stands alone: it ends when the savings land. Nothing obliges you to connect an agent afterwards.
tightsaas.com →