agentic safety · trust layer · 2,644 servers scored
Security scoring, agent identity, payment verification, and data lineage tracking for the agentic economy. Know what your agents are connecting to, who they are, and where your data goes.
Know what’s connected.
Block what’s dangerous.
Prove what happened.
01
Add the MCP server to any client — point your client at https://usestrata.dev/mcp with an x-api-key header — or install the TypeScript SDK and call strata.verify() directly. REST API also available — no lock-in.
02
Every MCP server gets two trust signals: security_score (repo health) and runtime_score (live endpoint probing + static analysis). Per-tool scoring exposes which specific tools are dangerous — not just the server.
03
Block dangerous servers before your agent connects. Define policies — "no shell_exec in production" — enforced at the Strata layer. Get real-time alerts when connected servers change risk profile.
see it in action
Scan your agent config, verify servers and payments, issue agent identities, enforce policies, or query the directory from inside Claude Code or Cursor.
Phases 3 & 4 — Now Live
Define rules that govern what your agents are allowed to do. "No shell_exec in production." Enforced before any tool call executes.
open →One-click SOC 2 and ISO 27001 audit evidence packages. Tamper-evident ledger with HMAC verification. JSON and CSV export.
open →Push alerts when connected servers change risk profile, gain dangerous capabilities, or get quarantined. Turn alerts into policies in one click.
open →Automatic disconnection when connected servers cross critical risk thresholds. Agents continue in degraded-safe mode. No human intervention required.
open →Visual map of every MCP server your agents depend on. Risk scores, capability flags, circuit breaker status, and data flow relationships in one view.
open →Baseline normal agent behavior. Alert when volume spikes, high-risk server usage surges, or net-egress floods deviate from the baseline. Hourly detection.
open →Claude
liveChatGPT
liveGemini
liveLangChain
liveOllama
liveTypeScript SDK
Zero-dependency. Works in Node, browser, Bun, and Cloudflare Workers.
npm install @strata-ai/sdkSDK docs →GitHub Action
Scans MCP configs, posts a trust report comment, fails on critical risk.
uses: PThrower/strata-mcp-check@v1Marketplace →Native MCP Server
Add to Claude Desktop, Cursor, or any MCP client — all 10 tools available instantly. MCP server verification, agent identity, payment trust, data lineage, real-time threat alerts, and behavioral anomaly detection in one connection.
{
"url": "https://usestrata.dev/mcp",
"headers": {
"x-api-key": "sk_..."
}
}MCP docs →community
Every MCP server is continuously re-scored as repos evolve, runtime behavior changes, and new capability flags are detected. The directory never goes stale.
22
ecosystems tracked
2,644
mcp servers scored
Daily
index updates
Know what’s connected.
Block what’s dangerous.
Prove what happened.
Everything you need to wire up a prototype agent.
Production-grade access for teams shipping real agents.
Founder Offer
Lock in everything Strata becomes. Forever.
Claim Founder Access →47 of 50 spots remaining
Now live — Policy Engine · Compliance Reporting · Threat Feed · Circuit Breaker · Dependency Graph · Behavioral Anomaly Detection · Coming in Phase 5 — Multi-Agent Trust