MCP RELEASE CONTROL

MCP contract checks that run in your CI—not in a public form.

Sentinel gives platform teams a release decision before a changed tools/list contract reaches shared agent infrastructure. Baselines, candidate manifests and credentials stay inside the pipeline you already control.

Inside your CIReview manifests where your deployment already runs.
Decision-readyPass, review or block with a stable evidence record.
Focused boundaryContract change control—not a vague “AI security” claim.

THE CI FLOW

A release gate for a small, expensive class of mistakes.

Remote MCP servers become a product surface: a renamed tool, narrower input or altered description can change what an agent is able—or encouraged—to do. Sentinel makes that diff reviewable before it reaches customers.

  1. 01

    Capture a reviewed baseline

    Keep the known-good tools/list contract with the release artefacts you already review.

  2. 02

    Run the candidate in CI

    The local CLI/action compares the next contract in your own runner—no dashboard upload and no production credentials required.

  3. 03

    Gate the release

    Use the resulting pass, review or block decision as a PR/deployment check with a fingerprinted JSON evidence record.

PRIVATE DESIGN-PARTNER PROGRAM

Get the gate into a real production workflow.

For teams already operating a remote or customer-facing MCP server. We install the release check with your existing CI, agree the change policy, and review the first live releases together.

Limited design-partner programme. No “paste your manifest into our cloud” requirement.

WHO PAYS FOR THIS

Teams shipping MCP as part of a real product.

Hosted SaaS MCPs

A new tool or changed schema affects every connected customer and agent workflow.

Data & security platforms

Tool descriptions and input changes deserve a release record alongside code and access controls.

AI platform teams

One repeatable check is easier to own than an ad-hoc contract diff in every pull request.

CLEAR BOUNDARY

What Sentinel does—and does not—promise.

It does: compare supplied tool contracts, flag compatibility changes and detect suspicious instruction-like metadata before release.

It does not: execute tools, inspect arbitrary source code, access customer secrets or replace a full application-security assessment.

BROWSER-ONLY DECISION-ENGINE DEMO

Try the comparison logic with safe sample data

This is a demo, not the product’s data path.The paid workflow runs in your CI. Any sample you enter here remains in this browser and is never sent to Sentinel.

Evidence will appear here

Load the demo, or paste a trusted baseline and candidate release.

BUILT FOR THE RELEASE PATH

Make MCP contract changes a deliberate decision.

Use the demo to understand the check. Use Sentinel in CI so your release artefacts never have to leave your own environment.

Explore the design partner