for teams & enterprises

Put the AI tool supply chain under policy.

Every agent in your company connects to MCP servers and APIs that can change their instructions at any time, without notice. Toolproof turns that moving surface into a control: cryptographically signed verdicts, CI enforcement, and replayable audit evidence.

shipping today — free

toolproof-gate — fail the build when a tool turns hostile

A committed baseline of every MCP server you depend on. CI re-verifies on every run: signature checked client-side (ed25519), grade gated by policy, and any change to a tool's model-visible instructions blocks the merge — the same discipline you already apply to dependencies, applied to the instructions your agents read.

npx toolproof-gate --init https://mcp.example.com/mcp --min-grade B
npx toolproof-gate --audit audit.jsonl   # in CI: exit 1 on drift

Signed evidence, not screenshots

Every gate check appends a JSONL audit line containing the full signed passport and its signature — replayable by any auditor with the public key. Compliance evidence for the newest supply chain in your stack, without inventing a new process.

The agent-side guard

The check_tool MCP server lets any employee's AI check a tool before connecting — the same verdicts, same signatures, enforced at the moment of connection, not just at merge time.

plans
Free
$0
Everything an individual builder needs.
  • +Unlimited trust cards & grades
  • +Watchlist with diff-on-change alerts
  • +check_tool MCP server (Claude, Cursor, …)
  • +toolproof-gate CLI — MIT licensed
  • +Signed passports (ed25519) on every verdict
start scanning →
Team
from $490/mo
Policy as code for the whole org.
  • +Org-wide baselines, managed centrally
  • +Webhook alerts on drift (Slack, PagerDuty, SIEM)
  • +Private watchlists & team review workflow
  • +Badge + gate enforcement across all repos
  • +Priority rules & signed key rotation
talk to us →
Enterprise
custom
The control your security team mandates.
  • +Self-hosted scanner & signing keys
  • +SSO / SAML, RBAC, org audit trails
  • +SIEM streaming (Splunk, Sentinel) of signed verdicts
  • +Vendor due-diligence reports on demand
  • +SLA + security review support
contact sales →

Team & Enterprise tiers are in early access — everything on the Free tier stays free and open source. No lock-in: your baselines and audit files are plain JSON in your repos.

the value math
One poisoned MCP tool can exfiltrate every conversation it touches — customer data, credentials, code. The average enterprise tooling incident costs six figures; enforcement + evidence here costs less than the coffee budget of the incident review. It isn't a line item, it's the cheapest control you'll add this year.