๐Ÿ›ก๏ธ Independent Trust Authority

Trust, but verify.

Check AI tools before you trust them. Search the Registry, review live findings, and understand risk before your agents connect.

No account required ยท Results are public ยท Max 5 scans/hour

Start With Your Goal

View platform directory โ†’

If you are new here, start with one of these four paths instead of jumping straight into the deeper listings and research pages below.

Evaluate an MCP Server

Search the Registry, review Touchstone research, and understand whether a server is indexed, live verified, certified, or actively monitored.

Search Registry Touchstone Coverage

Publish and Certify Your Server

Use scans, assisted review, certification, badges, and proof exports to make trust visible to users, buyers, and marketplaces.

Publisher Center Start Certification Badge Generator

Protect Production Agent Traffic

Move from trust checks to runtime policy, agent identity, traces, approvals, and governance when you need operational control.

Runtime Gateway Trace Governance Identity

Share Proof With Buyers and Partners

Use the Trust Center, procurement materials, signed proof bundles, and partner integration hooks when a public score is not enough.

Trust Center Proof Bundles Partner Integrations

Trust Score Distribution

Recently Scanned

View all โ†’

Highest Rated

View all โ†’

Newly Certified

View all โ†’

Recently Flagged

View all โ†’

Recently Indexed Packages

View all โ†’

Touchstone Security Research

View Advisories โ†’

Independent Security Review

Touchstone checks MCP servers for common security weaknesses, risky design choices, and operational gaps before those issues turn into production surprises.

Supply Chain & SBOM

Review dependencies, SBOM data, provenance signals, and package hygiene when you need to understand how a server is built, not just how it scores.

Framework Mapping

Findings are mapped into the frameworks buyers and security teams already use, so technical issues can turn into evidence instead of another translation exercise.

Red Team Testing

Go deeper with adversarial testing when a simple trust score is not enough and you need to understand how a server behaves under pressure.

Published Advisories Check Reference (63) Red Team Dashboard

What Changed Recently

View changelog โ†’

Recent work focused on five practical improvements: safer runtime control, clearer agent identity, simpler buyer diligence, portable trust proof, and benchmark-ready validation assets.

Phase 1

Runtime Gateway

Audit is now the Runtime Gateway story: in-path policy, receipts, approvals, quickstarts, and compliance-oriented evidence.

Overview Quickstart
Phase 2

Agent Identity & Trace

Identity now issues agent-native delegated sessions, while Trace and Governance expose the execution and oversight context around them.

Identity Trace Open Source Toolkit
Phase 3

Trust Center & Procurement

The public trust layer now includes security, disclosure, incident response, procurement, HIPAA/FedRAMP posture, and researcher-program materials.

Trust Center Procurement Kit
Phase 4

Proof Bundles & Partner Hooks

Signed proof bundles, trust manifests, partner integrations, and public asset summaries now connect trust data to real buyer and partner workflows.

Proof Bundles Partner Integrations
Phase 5

Benchmarks & Buyer Packets

Runtime benchmark methodology, questionnaire starters, partner packets, and CNA-readiness surfaces now make external validation simpler and more accurate.

Runtime Benchmarks Questionnaire Starter

Get Your Server Certified

Stand out in MCP marketplaces with a verified trust badge. Prove to users your server is safe, transparent, and trustworthy.

Start Certification Learn More