MCP Server Deployment & Governance on AWS - Claude-Native (CPN Partner)
Kriv AI · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
**Every MCP server is a new identity, a new attack surface, and a new audit obligation. Until now, no fixed-fee transparent-pricing MCP server deployment + governance SKU has existed on AWS Marketplace with Anthropic CPN credentialing.**
Model Context Protocol (MCP) is Anthropic's 2024 open standard for connecting AI applications (Claude Agent SDK, Bedrock Agents, custom Claude deployments) to data sources + tools via JSON-RPC 2.0. Adoption has been rapid (Anthropic, Cursor, Linear, Raycast, Block, Apollo, Replit, Zed, and dozens of platforms in 2025–2026). AWS launched the **AWS API MCP Server** (awslabs, Nov 2025). **Amazon Bedrock AgentCore became HIPAA-eligible Feb 10, 2026**. **MCP is on the OWASP Top 10 for LLM Applications**, prompt injection, indirect prompt injection, tool poisoning, and cross-tool contamination are now board-level enterprise risks.
Show the rest of the publisher’s description (6 more lines)
Existing AWS Marketplace listings are thin. **Rackspace FAIR Model Context Protocol Accelerator** (Jul 2025, private-offer only) is the strongest direct competitor, 8-week, Bedrock-centric, zero-trust + SOC 2. **Chaos Gears MCP Server on AWS** is boutique with no CPN and no governance depth. **Milvian Group MCP** is ~2 weeks Bedrock-oriented and shallow. Off-Marketplace SMB MVP MCP servers run $25K–$50K; production multi-tenant SaaS $60K–$120K; enterprise $100K+. Rackspace FAIR Premier-tier industry-chatter is **$150K–$400K**.
**Kriv white-space:** only 2 direct Marketplace competitors with real governance; **zero publish transparent tiered pricing**, Kriv's $50K / $85K / $150K removes procurement friction; **nobody else is CPN-branded**; Kriv = only **Claude-native** implementer with Claude Agent SDK depth; **HIPAA-aligned MCP** is empty space; first-mover window.
**Reference architecture.** MCP Server Runtime (ECS Fargate; JSON-RPC 2.0 over TLS 1.3; mTLS; signed ECR; ALB + App Mesh). MCP Registry (discovery, versioning, deprecation, lifecycle hooks; metadata: owner, data classification, RBAC, rate limits). Identity & Access (OAuth 2.1 + JWT; IAM Identity Center + SAML/OIDC; RBAC/ABAC; tenant isolation via tags/SCPs). Secrets (Secrets Manager + KMS CMKs; per-tool scoping; 30/60/90-day rotation). PI Defenses (schema validation; sanitization; PII scanning; tool-poisoning detection; sandbox isolation;** HITL gates** for payments, PHI, code exec, external calls, regulatory actions). Audit (CloudTrail + structured logs; OpenTelemetry; S3 Object Lock 7-year HIPAA). Rate/Cost (API throttling; tenant budgets; Bedrock logs → CloudWatch → QuickSight). Data Residency (region isolation; VPC; PrivateLink to Bedrock/SageMaker/S3/Secrets Manager). Security (GuardDuty, Security Hub, Macie, Inspector). DevSecOps (CodePipeline/CodeBuild; SAST/DAST/SCA; SBOM SPDX/CycloneDX; signed ECR). Compliance (SOC 2 CC1–CC9; ISO 27001:2022; ISO 42001:2024; HIPAA §164.308/312/316; PCI DSS v4.0.1).
**Week-by-week.** W1 Scoping. W2 Landing zone + runtime baseline + DevSecOps pipeline. W3 MCP deployment + identity (OAuth 2.1 + JWT + mTLS; RBAC/ABAC; Secrets Manager). W4 PI defenses + HITL + rate limiting. W5 Audit + monitoring + cost dashboards (Foundation closes). W6 Standard, SOC 2 + ISO 27001:2022 evidence; MCP Registry (60-day warranty). W7–8 Enterprise, HIPAA alignment; multi-tenant validation; load testing; UAT; 90-day hypercare.
**Three tiers.** Foundation $50K (5 wk; 3 MCP servers; single-tenant; 30-day warranty) for Series A–C AI-native + internal-platform. Standard $85K (6 wk; up to 10 MCP servers; multi-tenant + Registry; **SOC 2 Type II + ISO 27001:2022 evidence**; 60-day warranty) for Series C–E + Fortune 1000 internal Claude. Enterprise $150K (8 wk; up to 20 MCP servers; full multi-tenant validation; **HIPAA §164.308/312 alignment**; load testing; 90-day hypercare) for regulated industries + multi-tenant SaaS. Optional Extra MCP Server $15K each.
**Important disclosures.** Kriv is a member of Anthropic Claude Partner Network (April 9, 2026), partner, not an Anthropic-authorized reseller. Kriv does NOT develop Customer MCP tools or business-logic applications, infrastructure + governance scope only. Kriv does NOT operate Customer MCP servers post-deployment (unless separate Managed Service retainer). Kriv issues no SOC 2 / ISO / HIPAA / HITRUST certifications. No legal / regulatory / compliance advice. AWS + Anthropic API + Bedrock consumption separate. No prompt-injection prevention guarantee, defenses reduce but don't eliminate risk. No MCP specification stability guarantee, MCP is evolving and breaking changes may require Customer-side remediation. EDP-eligible — engagement fees ($50K / $85K / $150K) count toward your AWS Enterprise Discount Program commitment (up to 25%). Structure via Marketplace private offer for EDP alignment. Contact info@kriv.ai or +1-732-433-5564.
Highlights
Highlighted by the publisher on AWS Marketplace.
First Anthropic CPN-branded MCP governance SKU on AWS Marketplace, transparent $50K / $85K / $150K tiered pricing where every competitor is private-offer only. Only 2 direct Marketplace competitors with MCP governance depth (Rackspace FAIR $150K–$400K, Chaos Gears boutique no-CPN). Kriv = only Claude-native MCP implementer with Claude Agent SDK depth + HIPAA-aligned coverage. Category <1 year old; CSA MCP frameworks launching 2026.
OAuth 2.1 + JWT + mTLS + RBAC / ABAC + Secrets Manager auto-rotation + JSON-schema input validation + output sanitization + indirect-PI scanning + tool-poisoning detection + cross-tool isolation via per-invocation sandboxes + HITL gates for high-risk tools (payments, PHI writes, code execution, external sends, regulatory filings). Rate limiting + per-agent / per-tenant token budgets + FinOps via CloudWatch + QuickSight.
SOC 2 Type II Common Criteria (CC1–CC9) + ISO/IEC 27001:2022 Annex A (A.5–A.18) + ISO/IEC 42001:2024 + HIPAA §164.308 / §164.312 / §164.316 + PCI DSS v4.0.1 evidence mapping per tier. CloudTrail + OpenTelemetry + S3 Object Lock immutable audit (7-year HIPAA retention). GuardDuty + Security Hub + Macie + Inspector. AWS CodePipeline + CodeBuild with SAST / DAST / SCA + signed ECR images. DevSecOps pipeline + SBOM (SPDX / CycloneDX). Member of Anthropic CPN April 9, 2026.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

