Find your security starting point
Building with AI or MCP? Start where the assistant can act
Pick the surface that can reach tools, data, or privileges first. We will fold adjacent app and cloud scope into one fixed plan during the technical sync.
MCP servers
AI/MCP builders start hereStart with tool, data, and auth boundaries
For assistants, agents, and MCP servers that call tools, reach APIs, read files, or touch tenant data.
MCP servers, tools, transports, auth flows, tenant boundaries, and connected resources.
Apps & APIs
Start with product behavior and authorization paths
For app logic, API trust boundaries, tenant isolation, and multi-role workflows inside the product.
Cloud, Kubernetes & IAM
Start from the trust boundary and privilege model
For cloud identity, Kubernetes separation, exposed services, storage risk, and chained escalation paths.
If more than one surface matters, start with the path that can create the highest-impact action. We combine the rest during scoping.


