beta Sign in Start free
AI System Assurance & Testing · for MCP

The assurance layer between your AI agent and production.

One execution spine grades any MCP server — and the agent around it — then keeps score on every deploy. Five pillars are the evidence; the spine is the product.

Local-first · your keys never leave stdio + remote HTTP + OAuth
Security · Red-team Guard
83
Assuranceseverity-weighted
5resisted
1breached
Prompt injection100
Data exfiltration100
Tool manipulation75
RAG Assurance Insight
88
7 dimsgraded
100
Quality
100
Behavior
92
Chain
Prompt regression ▲17
Instruction override✓ resisted
Secret exfiltration✗ breached
model changed opus-4.8 → sonnet-5
The product

The product isn't five tools. It's one assurance spine.

Most teams stitch together a prompt tool, a security tool, and a RAG tool — three silos, three data models, nothing shared. Kawach runs every pillar on one spine, so history, trend, and regression come for free.

Most assurance tools

Prompt tool
Security tool
RAG tool

Three silos. Three data models. Nothing compounds.

Kawach — one spine

01

Connect

any MCP server

02

Run Assurance

every pillar

03

Score

one number

04

Ship

gate the deploy

05

Monitor

observability

06

Regression

diff vs last run

Regression feeds the next run — the loop that turns testing into a standing assurance score, not a one-time report.
The evidence

Five pillars. One spine underneath.

Each pillar is proof the spine works — and each writes the same run record, so history, trend, regression, and observability all come for free.

Free

MCP Inspector

Connect over stdio or HTTP, normalize tools/resources/prompts, call and diff them, and catch capability drift against a baseline.

Core

Contract & Prompt

Capture .kawach contracts, seed positive / negative / boundary test prompts, set goldens, and re-run them as regressions.

Core

Performance

Load-test a contract against an SLO — p50/p95/p99, throughput, and % under budget. Local up to 5 VUs; more on hosted runners.

Guard

Security · Red-team

Attacks the entire application, not just the prompt — six layers, a library of 22 attacks on the OWASP LLM Top 10, severity-weighted scoring, and regression replay.

Insight

RAG Assurance

Not answer evaluation — retrieval assurance. Grade the retriever across seven dimensions — quality, tool selection, behavior, contract, drift, an LLM-judged chain, and fault-injection resilience.

Live

Assurance Observability

One pane across every pillar — latest score, trend, coverage, and what got worse since your last deploy.

What you actually see

A score you can act on — not a wall of logs.

Each pillar rolls up to a single score, then drills all the way down to the probe, the response, and the exact evidence.

Security score cardAttacks the whole application — protocol, tools, resources, retrieval. Severity-weighted resistance with a regression flag when a critical newly breaches.
Click to zoom
RAG assurance cardNot answer eval — retrieval assurance. Seven dimensions incl. an LLM-judged chain, golden-baseline drift, and fault-injection resilience.
Click to zoom
Deployment Assurance dashboardSee what blocks shipping, what is optional, and the shortest path back to green across every assurance pillar.
Click to zoom
Advantages on top

The moat is the spine. MCP-awareness is the edge.

Anyone can build a scanner or a RAG eval. The defensibility is the shared spine — and on top of it, Kawach is the only one that attacks the whole application: the protocol, the tools, the resources, and the retrieval chain.

// protocol

Off-catalog tools

Invoke tools the server never advertised, bypass unadvertised capabilities, and send schema-violating arguments.

// tools

Tool abuse

Path traversal, template injection, and destructive tools exposed to an agent with no confirmation gate.

// data

Resource & RAG poisoning

Secrets in resources, hidden URIs, and adversarial instructions hidden inside retrieved documents.

// chain

Multi-step agents

Crescendo escalation, deferred triggers, and tool chains that walk a benign task into a destructive call.

Pricing

Priced by production systems under assurance.

The unit is simple: how many production MCP servers Kawach protects. Plans map to deployment maturity — discover free, assure one server, govern a team, scale the enterprise. Execution stays local; your keys never leave your machine.

Free · Inspector
$0
Discover & validate your MCP server.
  • 1 local MCP server
  • 5 MCP tools monitored
  • Security attacks
  • 10 prompt regressions
  • Load profile (10 VUs)
  • RAG monitored retrievers
  • Deployment Assurance
  • 7-day history & trends
  • CI/CD
  • Static rule feed
Start free
Team
$399 /mo
Govern assurance across a team.
  • 5 production MCP servers
  • 50 MCP tools monitored
  • Full security attack library
  • 1000 prompt regressions/month
  • Stress profile (500 VUs)
  • 100 RAG monitored retrievers
  • Deployment Assurance
  • CI/CD
  • 1-year history & trends
  • Live rule feed
Choose Team
Enterprise
Custom
Governance at scale.
  • Unlimited production servers
  • Unlimited MCP tools monitored
  • Full security library + custom attacks
  • Unlimited prompt regressions
  • Custom load profile
  • Unlimited RAG monitored retrievers
  • Deployment Assurance
  • CI/CD
  • Unlimited history & trends
  • Priority rule feed
Talk to us
PlanFreeScaleTeamEnterprise
MCP servers1 local1 production5Unlimited
MCP tools monitored51050Unlimited
Security attacksChoose any 10Full libraryFull + custom
Prompt regressions10100/month1000/monthUnlimited
Performance10 VUs100 VUs500 VUsCustom
RAG monitored retrievers10100Unlimited
Deployment Assurance
History & trends7 days90 days1 yearUnlimited
CI/CD
Rule feedStaticLiveLivePriority

Amounts are directional, set with early design partners. Primary unit = production MCP servers under assurance; attacks, prompts, retrievers and load are fair-use plan limits.

Contact

Talk to the Kawach team.

Tell us about the MCP systems you want to assure. We’ll reach out to discuss the right path forward.

Thanks — the Kawach team will reach out shortly.

Get started

We didn't build five tools.
We built the assurance spine.

Point Kawach at a server and get a score in under a minute — then keep it green on every deploy.