Security posture of the AI ecosystem
We scan the public security posture of MCP servers, model providers, and AI tools — the same checks for everyone, observed from the outside, dated, and re-run on a schedule. No vendor questionnaires, no self-attestation.
- Entities tracked
- 39
- DMARC-enforced
- 92.3%
- Publish security.txt
- 53.8%
- Publish llms.txt
- 64.1%
Last scanned August 27, 2026
Categories
MCP serversThe servers people connect their AI agents to — scored on the security basics of the vendor domains behind them.View the ranking →18 entities trackedModel providersThe companies serving frontier and open models, scored on the same public security posture checks as everyone else.View the ranking →10 entities trackedAI apps & toolsThe AI products teams adopt fastest — measured on the unglamorous domain-security basics.View the ranking →8 entities trackedAgent platforms & frameworksThe platforms agents are built on. If agents are the new apps, this is the new app-store security question.View the ranking →3 entities tracked