Know which MCP reviews need attention again—and preserve the evidence behind the decision.
MCPwatch Exposure Ledger matches a customer-owned MCP inventory against a bounded, source-linked advisory feed, keeps uncertainty explicit, records human disposition, and packages replayable review evidence without uploading private inventory.
The operator job
From private inventory to a reviewable decision trail.
The product keeps package identity, deployment facts, advisory conditions and human judgment separate. Missing or conflicting evidence stays visible instead of becoming a safety claim.
What it does
A connected evidence workflow—not another generic scanner.
Applicability with uncertainty
Exact package, version and deployment evidence can produce an applicability state. Alias-only, missing-version and unsupported conditions remain review-required or unknown.
Decision Freshness
Feed, inventory, graph, policy and engine changes invalidate applicable prior decisions with explicit stale reasons.
Portable evidence
JSON, CSV and self-contained HTML reports, a human review ledger, hashes and a deterministic Review Capsule support handoff and replay.
Bounded source feed
The included coverage manifest names every advisory, ecosystem, conflict and exclusion. It never claims complete MCP coverage.
Local security boundary
The verified workflow reads local inputs. It does not discover live infrastructure, connect to MCP servers, invoke tools or execute reviewed components.
Optional review worksheets
Source-verification and byte-baseline records help document tool-surface review. A changed hash triggers review; it does not prove malicious modification.
One complete core · two operating licenses
Professional correctness is not feature-limited.
Professional and Agency use the same evidence engine, feed, schemas and report semantics. Agency adds tested multi-client execution, isolation, portfolio summaries and client handoff resources.
One purchasing organization
- Complete matcher, graph, freshness, ledger, reports and capsule workflow
- Internal-use license for one legal organization
- 12-month downloadable offline feed update entitlement
- Perpetual use of downloaded executable and packs
Authorized client engagements
- Everything in Professional with the identical correctness core
- Tested isolated multi-client batch workflow
- Engagement index, portfolio freshness and per-client handoff
- Neutral intake, approval, exception, reapproval and retention resources
One-time purchase. No SaaS account, subscription dependency, telemetry, automatic renewal or recurring billing. Updates are downloaded manually; stated coverage and as_of dates remain explicit.
Public proof
Inspect the output and non-coverage before checkout.
Generated sample report
The downloadable proof bundle contains real deterministic HTML, JSON and CSV output from a synthetic historical Review Capsule fixture, with hashes and scenario boundaries.
Download sample ZIPCoverage manifest
The same bundle includes the exact release coverage manifest: included advisory IDs, ecosystems, known conflicts and explicit exclusions. Synthetic evidence demonstrates workflow, not production efficacy.
Review sample notesImportant boundary: Exposure Ledger does not prove compromise, exploitation, continuous exposure, remediation, non-exposure, safety or compliance. No match is not a safety conclusion. Every decision remains evidence-bounded and subject to human review.
Editorial independence
Commercial goals do not change MCPwatch findings.
MCPwatch’s source-first editorial lane remains independent from this product. Product revenue cannot select advisory severity, suppress corrections, alter source conclusions or change publication timing.
FAQ
Scope before purchase.
Does it scan or connect to running MCP servers?
No. The verified workflow operates on local files and does not invoke MCP tools or execute reviewed components.
Is Windows supported?
No. The current verified buyer package is Linux x86_64 and requires glibc 2.39 or newer. Windows fails closed and is deferred.
Are all MCP vulnerabilities included?
No. The release feed is deliberately bounded. The coverage manifest names 23 included advisories, four ecosystems, conflicts and exclusions.
Does Agency use a stronger matcher?
No. Core correctness is identical. Agency adds authorized client-use rights and tested multi-client/isolation/handoff operations.
Terms, delivery and refund policy · Privacy Policy · Contact and support