CCS v1.0 · DOI: 10.5281/zenodo.21234580

The security standard
for MCP.

MCP protocol doesn't enforce security. We do. 215 fault types. 52 real exploits. 8 verified PoCs. 6 CVEs. Get certified or stay exposed.

Get Certified → Read the spec
215
Fault types
52
Real exploits
8
Verified PoCs
6
CVEs filed
20K+
Trajectories
9.8
Max CVSS

What is CCS?

Correctover Conformance Specification — the runtime security standard for MCP.

5-Component Architecture

Every MCP Server claiming CCS compliance must pass all 5 components. No exceptions.

1. Runtime Observatory
Capture every agent execution trace with cryptographic integrity
2. Fault Taxonomy
517-type runtime failure classification (215 public)
3. Required(τ) ⊆ Supported(τ)
Formal conformance criterion — no field drift
4. Receipt Schema
Cryptographic chain integrity for every output
5. Conformance Protocol
Four-axis verification: schema, integrity, cost, compliance
+ Audit Logger
Immutable forensic trail for SOC2/HIPAA/GDPR

Backed by evidence

Not theory. 52 MCP Servers exploited in the wild. 8 PoCs with accepted advisories (MSRC, GitHub). 6 CVEs assigned. 20,071 production agent traces analyzed. Peer-reviewed. DOI-registered. Blockchain-timestamped.

Get Certified

Display the "CCS Certified" badge. Your users trust your MCP Server.

1

Scan

Run the free scanner against your MCP config. See what's exposed.

2

Fix

Fix all findings. Install Runtime Guard for continuous protection.

3

Audit

Correctover audits your server. OAuth 2.1 + CCS v1.0 compliance check.

4

Certified

Get the badge. Listed in public registry. Annual re-certification.

Pricing

Standard is free. Certification costs money. Guard is insurance.

Free
Scan your exposure
¥0
Unlimited scans
  • Vulnerability scanning (unlimited)
  • See first 2 risks per scan
  • CCS v1.0 spec (free, DOI-registered)
  • 20K trajectory sample data
Scan free
Enterprise
Multiple servers + custom
¥9,999/year
Up to 10 MCP servers
  • Everything in Certified
  • 10 MCP server certifications
  • Custom compliance policies
  • Private threat intel feed
  • SLA + dedicated support
  • On-site audit (optional)
Contact

Start free — scan your MCP Server

5 seconds. No signup. See what's exposed.

$pip install correctover-security-audit
$correctover-security-audit scan-mcp config.json
Get Certified →