MCP Security Engineer · fully async

I make MCP servers production-grade.

When you let AI agents into your product, three things decide whether it's safe: OAuth 2.1, tenant isolation, and audit logging. That's what I build, review and fix — for SaaS teams shipping remote MCP servers.

Written specs in, PRs + reports out. No meetings required.

The problem

Remote MCP servers ship fast — often generated from an OpenAPI spec or a no-code builder. The common failures are boring and dangerous: tool calls that work without a token, missing PKCE, one tenant able to read another's data, tool descriptions carrying hidden instructions, stack traces leaking secrets. Generators can't give you the lockable, production layer. I can.

Offer & pricing

Fixed prices, English, fully async. Payment: 50% on order, 50% on delivery, net 14.

Async Security Audit

€2,500 · pilot €1,900

5 business days

  • Full auth & tenancy review
  • Prioritised findings report
  • 10–15 min Loom walkthrough
  • Zero meetings
Request audit

Remediation Sprint

€6,000–12,000

2–3 weeks

  • Fix the findings
  • Delivered as pull requests
  • Loom demos + written status
Discuss scope

Production Build

€12,000–25,000

4–8 weeks

  • OAuth 2.1 + PKCE
  • Multi-tenant isolation
  • Audit logging + rate limiting
  • Tests, docs, handover
Start a build

Retainer · Protocol Watch

€500–1,500 / month

ongoing

  • Spec diffs & dependency updates
  • 1 scan / month
  • Written monthly report
Ask about retainer

Add-on: EU AI Act (Art. 50) technical labelling — disclosure UI, C2PA content credentials, watermark API. Fixed price by scope. Technical implementation only, not legal advice.

Agencies: white-label subcontracting available — specs in, PRs out, under NDA, invisible to your client. Get in touch.

Proof, not claims

Case study coming after the first delivered project. Links go live at launch.

How it works — fully async

  1. Submit the form. Tell me your MCP server URL and what you need. No call.
  2. Free short scan. With your permission I run mcp-sec-scan and send a teaser report + a 3-min Loom.
  3. Decide from a fixed price. If you want the full audit or a build, you get a written SOW and a Stripe invoice.
  4. Delivery as PRs + reports. Progress via Loom and written updates. Response < 4h on weekdays 9–18.

Request a free scan or a quote

Async intake — I reply in writing within one business day.

FAQ

Why no calls?

Async is a quality feature, not a limitation: clear written specs, fixed prices, deliverables as PRs and reports. It filters for the buyers (dev/CTO) who prefer it anyway. If a project truly needs it, one short optional 20-min call per project is available on request.

Is the free scan really free?

Yes. It's an external, non-invasive scan of your public MCP server (with your permission) and a short teaser report. The full audit adds the internal checks and remediation steps.

Do you sign an NDA / AVV?

Yes. NDA on request; a DSGVO data-processing agreement (AVV) when access to personal data is involved.

How do payments work?

Fixed price, 50% on order and 50% on delivery, net 14. EU B2B: reverse charge. US clients: not taxable in Germany.

Can you work as a subcontractor for my agency?

Yes — white-label, under NDA, invisible to your client. Specs in, PRs out.