Research
Tools and analysis to track emerging technology, adoption, and risk. None of it is for sale.
mcprisk
Evaluation and risk scoring for MCP servers
MCP servers give AI agents their tools, and most were built with little thought to what a bad one can do. mcprisk scores any MCP server against a published security policy: provenance, permissions, transport and auth, known vulnerabilities, and whether the description matches the code.
The scoring method is open, so you can check or challenge any result.
Signal Scout
Data-driven mapping of the AI software ecosystem
Signal Scout maps the AI ecosystem from real ground truth data, classifying 50,809 public repositories by framework, MCP server, and security practice. It surfaces trends, risks, and deployment patterns you would otherwise have to scan for yourself.
StableScope
Stablecoin registry and real-time operational risk monitoring
A registry and freeze monitor for blockchain stablecoins. Still early and rough in places. It exists to make one thing concrete: how much control issuers keep over money that is described as decentralized.
Writing
Analysis of security, AI, blockchain, and emerging technology risk
Deep dives on security and AI risk, mostly published on Medium.
Contact
What we learn here goes straight into the security work. If you want that applied to your own systems, get in touch.