What you send
- MCP server definitions, or the tool schemas your agents load
- Agent configuration — which servers, tools, and scopes are reachable
- Optionally, a policy you already try to enforce by convention
Design partners
We are looking for a small number of teams running MCP servers or tool-using agents in production. You send configurations, we run the detectors, you get findings and evidence back. Two weeks, no cost, no commitment.
What we look for
Every detector is measured against a versioned corpus of labeled attack and benign fixtures. The benchmark runs in continuous integration and fails the build when detection or false-positive rate regresses.
Instructions hidden in a tool description the model reads as direction
Payloads concealed in zero-width and bidirectional characters
One server redefining another's tool to intercept calls
Behavior written to be visible to the model but not the operator
Tools that route arguments or context to somewhere they should not go
Descriptions that ask the model to supply credentials it holds
Where this actually is
The engine is real: fourteen detectors, benchmarked at full detection and zero false positives against a versioned corpus, with a signed evidence chain and a control crosswalk behind them. The control plane is deployed and the command-line gate runs in continuous integration today.
Self-serve onboarding is not built. For now a pilot means you send configurations and we run the analysis, rather than signing up and connecting a source yourself. That is a concierge engagement wearing a product's clothes, and you should know that before you spend time on it.
We are telling you because it is the same standard the product is built on. Provenant reports a control as unproven rather than claiming one it cannot evidence, and a company that would not apply that to its own maturity has no business selling it.
The exchange
A design partnership only works if both sides get something they could not get alone.
A finding that misses, a false positive, a remediation step that does not fit how your team works. Negative findings are worth more to us than praise.
Not your content or secrets — the structural patterns. Real configurations are how the detector corpus grows past fixtures we wrote ourselves.
A reference, only if the pilot warrants one. If it does not, we would rather know why than have a logo.
A pilot is run by the people who built the engine, which is the reason it is useful and the reason there cannot be many of them.