Async Security Audit
€2,500 · pilot €1,900
5 business days
- Full auth & tenancy review
- Prioritised findings report
- 10–15 min Loom walkthrough
- Zero meetings
MCP Security Engineer · fully async
When you let AI agents into your product, three things decide whether it's safe: OAuth 2.1, tenant isolation, and audit logging. That's what I build, review and fix — for SaaS teams shipping remote MCP servers.
Written specs in, PRs + reports out. No meetings required.
Remote MCP servers ship fast — often generated from an OpenAPI spec or a no-code builder. The common failures are boring and dangerous: tool calls that work without a token, missing PKCE, one tenant able to read another's data, tool descriptions carrying hidden instructions, stack traces leaking secrets. Generators can't give you the lockable, production layer. I can.
Fixed prices, English, fully async. Payment: 50% on order, 50% on delivery, net 14.
€2,500 · pilot €1,900
5 business days
€6,000–12,000
2–3 weeks
€12,000–25,000
4–8 weeks
€500–1,500 / month
ongoing
Add-on: EU AI Act (Art. 50) technical labelling — disclosure UI, C2PA content credentials, watermark API. Fixed price by scope. Technical implementation only, not legal advice.
Agencies: white-label subcontracting available — specs in, PRs out, under NDA, invisible to your client. Get in touch.
Open-source auth & tenancy scanner for remote MCP servers. Try it on your own server.
View on GitHub →A reference MCP server done right: OAuth 2.1, tenant isolation, audit log, rate limiting.
View on GitHub →Deep dives on MCP security: confused deputy, PKCE, multi-tenancy, tool poisoning.
Read the blog →Case study coming after the first delivered project. Links go live at launch.
mcp-sec-scan and send a teaser report + a 3-min Loom.Async intake — I reply in writing within one business day.
Async is a quality feature, not a limitation: clear written specs, fixed prices, deliverables as PRs and reports. It filters for the buyers (dev/CTO) who prefer it anyway. If a project truly needs it, one short optional 20-min call per project is available on request.
Yes. It's an external, non-invasive scan of your public MCP server (with your permission) and a short teaser report. The full audit adds the internal checks and remediation steps.
Yes. NDA on request; a DSGVO data-processing agreement (AVV) when access to personal data is involved.
Fixed price, 50% on order and 50% on delivery, net 14. EU B2B: reverse charge. US clients: not taxable in Germany.
Yes — white-label, under NDA, invisible to your client. Specs in, PRs out.