The MCP security platform, on one page: every block, its minimal contract, and the RFCs behind it

Part 5: the blueprint. Prerequisites, eight blocks with their minimal contracts, the physical deployment - three planes, a fifteen-step call path, a build order, the lab-to-production delta, and the case for not building any of it.

2026-08-04 · 55 min · Alexander Romanov

Signed provenance for MCP tool results: the envelope, and the consumer that acts

Part 4: a portable, verifiable origin assertion for MCP tool results, plus a Biba taint floor - and an out-of-tree consumer that actually changes its action on the verdict, proven against a real MITM with logs and a wire capture. Includes every place the honest answer was ’this doesn’t fully work yet'.

2026-07-24 · 58 min · Alexander Romanov

I built an MCP security gateway. Then I found the attack every layer allowed.

The architecture worked as designed. That was the problem: an untrusted tool result influenced a second, clean request that passed every control. The implementation evidence, the blind spot, and how it changed the design.

2026-07-19 · 39 min · Alexander Romanov

AI agents are talking to everything. Nobody agreed on who can ask.

MCP fragmentation isn’t a developer-experience problem — it’s a security surface. Part 1: why there’s no single place to ask whether an AI-agent tool call should happen.

2026-06-28 · 11 min · Alexander Romanov

Mediate, don't classify: the design of a runtime MCP security gateway

The architecture that gives AI-agent tool calls a single place to be decided: one gateway, one port, six checks, per-identity profiles, and brokered credentials. No code — just the design and the trust boundaries.

2026-06-28 · 9 min · Alexander Romanov