Services
Security-first MCP engineering, billed by the hour
What we do
Granthinge is an MCP security engineering practice. Senior US engineers design, build, audit, and maintain Model Context Protocol servers for companies whose customers run vendor security reviews. Every engagement is billed hourly, on a time-and-materials basis, either as a project we run end to end or as staff augmentation inside your team.
- MCP Security Audits. A written assessment of an existing or planned MCP server against the MCP authorization specification, token handling, per-user scoping, tool design, audit logging, and connector-directory requirements, ranked by what will block a security review.
- MCP Server Engineering. Design and build of a production MCP server for your product: OAuth 2.1 wired to your identity provider, server-enforced per-user and per-tenant scoping, structured audit events, deployment in your cloud, and a security evidence pack.
- Governed MCP Platforms. A gateway and policy layer for organizations exposing many systems to agents: centralized authorization, identity propagation, per-tool policy, unified audit to your SIEM, and an onboarding kit for your own teams.
- Ongoing support and staff augmentation. Specification and directory-requirement tracking, vulnerability response, directory re-submissions, and new tools as your product changes - or a senior engineer embedded in your team for as long as the work needs one, with a named engineer your customers' security teams can email.
Who this is for
- B2B SaaS teams with a public API and enterprise or mid-market customers who run vendor security reviews
- Platform and security leads asked to make MCP safe across an organization
- Engineering teams that want a senior MCP or identity engineer alongside their own, without a hiring cycle
How we work with you
We bill hourly, time and materials. There are no fixed-price packages and no published rates; scope, staffing, and a typical timeline are agreed in an initial conversation and revisited openly as the work teaches us more. You can engage us to run a project end to end or to add senior capacity to your own team. Either way, the engineer you talk to first is the engineer who does the work, the code lands in your repositories, and you own everything we produce.
Next step
Tell us what you have and who is asking about it, and we will reply with what we would do first, including if the honest answer is that you do not need us yet. Contact us.