About
Built around one hard problem
Who we are
Granthinge is a US engineering practice. Our engineers are senior, US-based, and have spent their careers building the integration layers between software products: APIs, identity, and now the protocol that lets AI agents use those products safely.
We are not a marketing agency with a development arm, and we are not an offshore shop with a US sales office. The person you talk to on the first call is an engineer, and the engineers who scope your work are the ones who do it.
Why this niche
The Model Context Protocol became the way agents talk to software in a very short time. Most of the MCP servers built in that time were built fast, by product teams, to get a demo working. They are now meeting enterprise security reviews, and many are failing them: no real authorization, tokens passed straight through to downstream APIs, tools that can act on any tenant, no audit trail a customer could use.
Writing the server is not the hard part. Getting it through a customer's security review, listing it in the connector directories buyers look at, and keeping it correct as the specification evolves is the hard part. That is the part we do.
What we believe
- Security is a design decision, not a hardening phase. Authorization, scoping, and audit are decided in the first week or they are wrong.
- Plain proposals are a form of respect. You should not need three calls to learn what an engagement includes.
- Hours should be visible. We bill time and materials and report every week what the time went to, so trust is built on the record rather than the invoice.
- The specification wins. When a shortcut and the specification disagree, we follow the specification and explain why.
How we are paid
By the hour, on a time-and-materials basis, as a project engagement or as staff augmentation inside your team. No commissions, no vendor referral fees, no resold licenses. The service lines are on the services page.
Where we are
Granthinge is based in the United States and works with clients across US time zones. We work remotely, inside your environment, and travel for kickoff or a customer security meeting when it helps.