How We Work

One named engineer, weekly demos, your cloud

The engagement model

We bill hourly, on a time-and-materials basis, whether we are running a project end to end or adding a senior engineer to your team. Scope, staffing, and a typical timeline are agreed in an initial conversation, and when the work teaches us that the plan was wrong, we say so at once and re-plan it with you in the open; we do not quietly extend.

Every engagement has one senior US engineer as its named lead from first call to handover. That person writes the code, writes the evidence pack, and joins your customer's security call if you want them to.

How a build runs

Discovery before commitment. An initial conversation, a look at your API and identity setup, and a short written plan of what we would do first. No charge for that conversation.

Design first. The first week of any build is design: use cases, tool inventory, permission model, threat model. Security is decided here, not retrofitted in the last week. You sign off on the design before we build.

Weekly working demos. Every week you see the server running against a real MCP client, not slides. You can bring your security lead to any of them.

Adversarial testing before handover. We attack our own work: prompt injection through tool descriptions and outputs, token replay, cross-tenant access attempts, oversized inputs, abusive call rates. Findings and fixes are in the evidence pack.

Handover you can run. Infrastructure as code, a runbook, and a walkthrough with whoever will be on call.

What we deliver

  • Source code in your repository, under your ownership, with tests
  • Infrastructure as code for your cloud account
  • A security evidence pack: threat model, data-flow diagram, control matrix, questionnaire answers
  • A runbook and operational documentation
  • A directory submission package where a listing is in scope

Security and compliance posture

We work inside your environment, not ours. Code lives in your repositories, secrets in your secret manager, deployments in your cloud account. We ask for the least access that lets us do the job and we document what we were given.

We are engineers, not auditors. We do not issue compliance attestations and we do not claim certifications on your behalf. What we do is build so that your existing compliance program (SOC 2, ISO 27001, HIPAA, or none yet) has clear evidence to point to: a documented control for every question a reviewer will ask.

We follow the MCP specification as published, including its authorization requirements and its security best-practice guidance, and we tell you when the specification moves under you.

Communication

One shared channel, one weekly written status, and a demo. No account managers between you and the engineer doing the work.

How we are paid

By the hour, time and materials, invoiced at a regular cadence we agree up front. We do not sell fixed-price packages and we do not publish rates; what we will tell you in the first conversation is who would do the work, what we would do first, and how long comparable work has typically taken. Hours are reported weekly, so you always know where the time went.

Start with a conversation

Start with a conversation about what you have today.
Want to see how a build would run for you?