CuratedMCP

Free Hub · self-serve Control Plane at $29/seat

Start free. Govern your whole team for $29/seat.

The Hub is free for every developer. When you need fleet-wide visibility and an audit trail, upgrade the team to the Control Plane — self-serve, no sales call.

Prefer it deployed for you? $7,500 flat, 60-day pilot — converts to per-seat only if it lands.

Free

For individual developers

$0forever

See and govern your own machine. Run the open-source Hub, scan for shadow MCP servers, install from the risk-classified catalog. No account required.

  • Shadow-MCP scan — every AI client, graded A–F
  • CuratedMCP Hub — install once, sync every client
  • Sentinel local policy guard (early access)
  • TokenShield token ledger (beta · measured)
  • 70+ human-reviewed servers in the catalog
  • Community support (Discord, GitHub)
Scan your machine — free
Most teams start here

Team

Governance for engineering orgs

$29per seat / month

$23/seat billed annually

Everything the Hub sees, in one place: fleet-wide shadow-MCP inventory, org allowlist, and audit-ready reporting across every AI client your engineers run.

  • Everything in Free
  • Fleet-wide shadow-MCP inventory
  • Admin dashboard + allowlist push
  • Audit log of every MCP tool call
  • Multi-IDE enforcement (Claude Code, Cursor, Windsurf, Copilot, Gemini)
  • Basic RBAC (admin / member)
  • Email support, 1 business day SLA
Start at $29/seatOr tour the live demo first →

Pilot

The Control Plane, deployed for you

$7,500flat · 60 days

Founding-customer pricing, limited seats. We run the fleet audit, stand up the allowlist, deploy the control plane, and train your team — converts to per-seat from month 4 only if it lands.

  • Everything in Team
  • Week 1–2: full MCP audit across your dev fleet
  • Week 3–4: control plane deployed, SIEM wired
  • Week 5–8: policy tuning, handoff, team training
  • SSO / SAML + self-hosted option, stood up during the pilot
  • Keep the audit report + free Hub even if you walk
Apply for the pilot

70

Servers reviewed

22 rejected for quality

1.0k

CLI installs / mo

Across auditor, hub, sentinel

MIT

Open source

All CLIs, no vendor lock-in

7

AI clients scanned

Claude Code & Desktop, Cursor, Windsurf, VS Code, Copilot, Gemini

Frequently asked questions

How does the $29/seat Control Plane work?
Self-serve — no sales call. Sign in, we auto-provision a team for you, pick your seat count, and pay with a card via Stripe. You get fleet-wide shadow-MCP inventory, an admin dashboard with allowlist push, a full audit log, and multi-IDE enforcement immediately. Annual billing saves ~17%; volume discounts kick in at 100 seats.
How does the 60-day, $7,500 pilot work?
For teams that want it deployed for them instead of self-serve. Founding-customer pricing, limited seats. $7,500 flat for an 8-week engagement: Week 1–2 we run a full MCP audit across your dev fleet and stand up the allowlist. Week 3–4 we deploy the control plane and wire per-tool-call audit to your SIEM. Week 5–8 is policy tuning, dashboard handoff, and team training. Convert to the Team plan ($29/seat) from month 4 only if it lands — otherwise you keep the audit report and the free Hub forever. Apply at /enterprise/pilot.
Why per-seat instead of flat pricing?
Per-seat is what platform and AppSec leads already buy. It scales linearly with the population you're governing (your engineers), which matches the audit and policy load. Volume discounts kick in at 100 seats. Annual billing saves ~17%.
What's actually live today vs. roadmap?
All Team features are live: allowlist push, audit log, multi-IDE enforcement, Sentinel guard, basic RBAC. Enterprise controls — SSO, SIEM export, self-hosted — are stood up per design-partner pilot. We don't sell roadmap; if it's on this page, you can run it during the pilot.
Can I run this entirely on-prem?
Yes — it's stood up during the pilot. The control plane ships as a Docker image with Postgres backing — runs in your VPC, no data leaves your network. The Hub is local-first by design (the CLIs are open-source, MIT-licensed). On-prem is the standard offer for AppSec-led procurement, not a stretch deliverable.
What does "Sovereign Certified" mean?
Every server we list goes through a human security review: credential handling, network egress, code patterns, dependency audit. 70 servers approved, 22 rejected to date. The same review backs the policy templates your admins import — risk-classified, ready to allowlist.

Govern MCP before your engineers install the wrong thing.

$7,500 flat 60-day pilot for the first 10 design-partner orgs. Founding-customer pricing. Convert to per-seat from month 4 only if it lands.