The assurance layer between your AI agent and production.
One execution spine grades any MCP server — and the agent around it — then keeps score on every deploy. Five pillars are the evidence; the spine is the product.
The product isn't five tools. It's one assurance spine.
Most teams stitch together a prompt tool, a security tool, and a RAG tool — three silos, three data models, nothing shared. Kawach runs every pillar on one spine, so history, trend, and regression come for free.
Most assurance tools
Three silos. Three data models. Nothing compounds.
Kawach — one spine
Connect
any MCP server
Run Assurance
every pillar
Score
one number
Ship
gate the deploy
Monitor
observability
Regression
diff vs last run
Five pillars. One spine underneath.
Each pillar is proof the spine works — and each writes the same run record, so history, trend, regression, and observability all come for free.
MCP Inspector
Connect over stdio or HTTP, normalize tools/resources/prompts, call and diff them, and catch capability drift against a baseline.
Contract & Prompt
Capture .kawach contracts, seed positive / negative / boundary test prompts, set goldens, and re-run them as regressions.
Performance
Load-test a contract against an SLO — p50/p95/p99, throughput, and % under budget. Local up to 5 VUs; more on hosted runners.
Security · Red-team
Attacks the entire application, not just the prompt — six layers, a library of 22 attacks on the OWASP LLM Top 10, severity-weighted scoring, and regression replay.
RAG Assurance
Not answer evaluation — retrieval assurance. Grade the retriever across seven dimensions — quality, tool selection, behavior, contract, drift, an LLM-judged chain, and fault-injection resilience.
Assurance Observability
One pane across every pillar — latest score, trend, coverage, and what got worse since your last deploy.
A score you can act on — not a wall of logs.
Each pillar rolls up to a single score, then drills all the way down to the probe, the response, and the exact evidence.
The moat is the spine. MCP-awareness is the edge.
Anyone can build a scanner or a RAG eval. The defensibility is the shared spine — and on top of it, Kawach is the only one that attacks the whole application: the protocol, the tools, the resources, and the retrieval chain.
Off-catalog tools
Invoke tools the server never advertised, bypass unadvertised capabilities, and send schema-violating arguments.
Tool abuse
Path traversal, template injection, and destructive tools exposed to an agent with no confirmation gate.
Resource & RAG poisoning
Secrets in resources, hidden URIs, and adversarial instructions hidden inside retrieved documents.
Multi-step agents
Crescendo escalation, deferred triggers, and tool chains that walk a benign task into a destructive call.
Priced by production systems under assurance.
The unit is simple: how many production MCP servers Kawach protects. Plans map to deployment maturity — discover free, assure one server, govern a team, scale the enterprise. Execution stays local; your keys never leave your machine.
- 1 local MCP server
- 5 MCP tools monitored
- Security attacks
- 10 prompt regressions
- Load profile (10 VUs)
- RAG monitored retrievers
- Deployment Assurance
- 7-day history & trends
- CI/CD
- Static rule feed
- 1 production MCP server
- 10 MCP tools monitored
- Choose any 10 security attacks
- 100 prompt regressions/month
- Load profile (100 VUs)
- 10 RAG monitored retrievers
- Deployment Assurance
- CI/CD
- 90-day history & trends
- Live rule feed
- 5 production MCP servers
- 50 MCP tools monitored
- Full security attack library
- 1000 prompt regressions/month
- Stress profile (500 VUs)
- 100 RAG monitored retrievers
- Deployment Assurance
- CI/CD
- 1-year history & trends
- Live rule feed
- Unlimited production servers
- Unlimited MCP tools monitored
- Full security library + custom attacks
- Unlimited prompt regressions
- Custom load profile
- Unlimited RAG monitored retrievers
- Deployment Assurance
- CI/CD
- Unlimited history & trends
- Priority rule feed
| Plan | Free | Scale | Team | Enterprise |
|---|---|---|---|---|
| MCP servers | 1 local | 1 production | 5 | Unlimited |
| MCP tools monitored | 5 | 10 | 50 | Unlimited |
| Security attacks | ❌ | Choose any 10 | Full library | Full + custom |
| Prompt regressions | 10 | 100/month | 1000/month | Unlimited |
| Performance | 10 VUs | 100 VUs | 500 VUs | Custom |
| RAG monitored retrievers | ❌ | 10 | 100 | Unlimited |
| Deployment Assurance | ❌ | ✅ | ✅ | ✅ |
| History & trends | 7 days | 90 days | 1 year | Unlimited |
| CI/CD | ❌ | ✅ | ✅ | ✅ |
| Rule feed | Static | Live | Live | Priority |
Amounts are directional, set with early design partners. Primary unit = production MCP servers under assurance; attacks, prompts, retrievers and load are fair-use plan limits.
Talk to the Kawach team.
Tell us about the MCP systems you want to assure. We’ll reach out to discuss the right path forward.
We didn't build five tools.
We built the assurance spine.
Point Kawach at a server and get a score in under a minute — then keep it green on every deploy.