Skip to content

Claude's directory portal is open →

Connector Trust Pack

Threat model, scope matrix and a reviewer-ready security statement.

Price
$1,500 to $3,000
Timeline
1 week

Problem

Enterprise buyers and platform reviewers ask how your connector handles risk: what each tool can do, which scopes it needs, and what happens when tool output tries to steer the model.

A connector that fetches Client ID Metadata Documents also fetches URLs it does not control, which creates a server-side request forgery risk.

Who it's for

A good fit

  • Teams whose enterprise buyers ask for a security review of the connector
  • Teams preparing a submission that needs a security statement for reviewers
  • Teams adding tools that write or delete data

Not a fit

  • Teams that need SOC 2 or a formal penetration test. The Trust Pack excludes both.

What we do

We model the threats specific to an MCP connector, including prompt injection through tool output and SSRF when fetching Client ID Metadata Documents. We map every tool to the scopes it needs, design confirmations for destructive actions and review what data each tool returns.

A lightweight pen test checks the result, and you get a security statement written for platform reviewers and enterprise buyers.

Deliverables

  • Threat model, including prompt injection via tool output and SSRF when fetching CIMD URLs
  • Scope matrix
  • Destructive-action confirmation design
  • Data minimization review
  • Reviewer security statement
  • Lightweight pen test

Process

  1. Start of the week

    Model

    Threat model and scope matrix for every tool.

  2. Mid-week

    Test

    Lightweight pen test and data minimization review.

  3. End of the week

    Write up

    Destructive-action confirmation design and the reviewer security statement.

Timeline

1 week.

Pricing

$1,500 to $3,000

1 week

How the price is set
By the number of tools. The Audit fixes the price before work starts.
Payment
100% at kickoff.

What you provide

  • Architecture documentation
  • Access to the repository and a staging environment
  • A list of the data each tool can read or change

What you receive

  • A threat model and a scope matrix
  • A reviewer-ready security statement
  • Pen-test findings, each with a fix or a written mitigation

Acceptance criteria

  • Every tool appears in the scope matrix
  • Every destructive tool has a confirmation design
  • Every high-severity finding is fixed or accepted in writing

Exclusions

  • SOC 2
  • Formal penetration tests
  • Legal sign-off

Questions

Is this a SOC 2 audit?

No. The Trust Pack excludes SOC 2 and formal penetration tests. It covers the risks specific to an MCP connector.

What sets the price?

The number of tools. The Audit fixes the price before work starts.

Can we add it to a Launch Sprint?

Yes. The cost calculator adds it when your enterprise buyers ask for a security review.

Find out where you stand in five days.

$750. Credited in full to your build.

Book a $750 Audit