Live
[2m ago] Detected unpinned npx in @modelcontextprotocol/server-git
Free · No login · ~30 seconds

Security for the agentic stack.

Cavexia Agentic Security Systems is the security platform for AI agent infrastructure. We scan MCP configs on demand, monitor them continuously, alert your team when things drift, publish a public threat intel feed, and ship enterprise services including SSO, on-prem deployment, and compliance evidence packs.

Try it now — we've pre-loaded the scanner with a real MCP config that has issues. Hit Scan to see what we find.

0
Configs scanned
0
Issues caught · this month
0
CVE patterns tracked
0+
Poisoning rules
The Scanner

Run a security scan in under 30 seconds

Paste your config or drop a JSON file. No login. We don't store your data.

Cavexia Scanner·v1.0.0
⌘+↵to scan
Demo config loaded. It contains 3 servers with real security issues — an unpinned npx, an unpinned uvx, and a shell pipe. Click Scan config below to see them flagged.
Step 1 — Your config (edit, paste, or drop a .json file)
3 servers:filesystem, git, fetch

Tip: Claude Desktop's config lives at ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows). Click Load Claude Desktop to pick yours and scan it for real findings.

Step 2 — Run the scan
Server-side scan · ~30 seconds · Cryptographically signed report
Or swap in a different example config
Detection Coverage

Four scanners run in parallel

Every finding is severity-graded and ships with an actionable remediation. No vague warnings.

0114 patterns

Known CVEs

Inspector RCEs, path traversals, supply-chain disclosures.

027 rules

Tool Poisoning

Zero-width unicode, bidi overrides, base64 payloads, prompt injection.

03live

Maintainer Drift

GitHub maintainer changes, archived repos, low-trust accounts.

046 checks

Config Hygiene

Unpinned versions, insecure HTTP, shell pipes, leaky env vars.

Built on disclosures and research from
Koi Security·Cymulate·OX Security·OWASP MCP Top 10·Vulnerable MCP Project·NVD

Scan once is good. Scan continuously is better.

Add an MCP config to your inventory and Cavexia re-scans hourly, alerts you when a maintainer changes, a new CVE drops for a package you use, or a config introduces a hygiene regression. Diffs and acknowledgments live in a dashboard built for security teams, not for dashboards.

Signed reports across every tier.

Every scan produces a cryptographically signed report. Free or Enterprise, same signature, same verifiability. Send it to a customer, attach it to a SOC 2 audit, archive it as evidence. Free across all tiers, by design.

Product Surface

Ten products. One platform.

From a free one-shot scanner to on-prem enterprise. Use what you need.

01Free

Scanner

On-demand security scan of MCP configs. ~30s, server-side, nothing stored.

Learn more →
02Free across all tiers

Signed reports

Cryptographically signed scan reports. Verifiable, archivable, audit-friendly.

Learn more →
03Free

Threat intel feed

Browse MCP vulnerability advisories or submit your own.

Learn more →
04Pro

Continuous monitoring

Hourly re-scans of tracked MCP configs. Catch drift before it ships.

Learn more →
05Pro

Email alerting

Get notified when monitored configs change or new findings appear.

Learn more →
06Pro 50/mo · Team 500/mo · Enterprise unlimited

Sandbox runs

Execute MCP servers in a sandbox to verify behavior without trusting the source.

Learn more →
07Team

Slack & webhook alerts

Push alerts into Slack channels or your own incident pipeline.

Learn more →
08Team

Audit log

Full team activity history. Who scanned what, when, and what they did about it.

Learn more →
09API tier and up

Programmatic API

/api/scan with bearer-token auth. Drop Cavexia into your CI/CD pipeline.

Learn more →
10Enterprise

Enterprise services

SSO (SAML/OIDC), on-prem, custom detection rules, dedicated TAM, HIPAA / SOC 2 / EU AI Act evidence.

Learn more →
Pricing

Free to scan. Pay for continuous coverage.

Most teams need on-demand scans during config changes. Paid tiers are for when you want to know the moment something drifts.

Free
$0
For one-off audits
  • On-demand scanner
  • Signed reports
  • Public threat intel access
Use the scanner ↑
API
$2.99/mo
For programmatic access
  • 10,000 API requests/month
  • Signed compliance reports
  • 30-day scan history
Start API trial
Pro
$12.99/mo
Recommended for active teams
  • Continuous monitoring (hourly)
  • Email alerts on drift + new findings
  • 50 sandbox runs/mo
Start Pro trial
Team
$59.99/mo
For security teams
  • Everything in Pro
  • Slack + webhook alerts
  • Audit log, 500 sandbox runs/mo
Start Team trial
Enterprise
Custom
For regulated organizations
  • Everything in Team
  • SSO, on-prem, custom rules
  • Compliance evidence packs
Contact sales →
Enterprise

Built for security teams who need more than a SaaS dashboard.

On-prem deployment, SSO (SAML and OIDC), custom detection rules tailored to your stack, a dedicated technical account manager, and evidence packs for HIPAA, SOC 2, and EU AI Act audits. We sign mutual NDAs before the first call.

  • SSO (SAML 2.0 + OIDC)
  • On-prem deployment (Helm chart + air-gapped install)
  • Custom detection rules
  • Dedicated technical account manager
  • HIPAA, SOC 2, EU AI Act evidence packs
  • Mutual NDA before first call