About Orisan
We build where AI needs an approval record.
Orisan builds local-first security tooling for MCP server review. We focus on the new risks created when agents connect to local and remote tools through Model Context Protocol.
mcpscan is the current active project: an alpha CLI that enumerates MCP server tools, resources, prompts, and metadata before an AI agent connects.
The problem
MCP servers changed the boundary of agent trust.
Agents increasingly connect to MCP servers that expose tools, resources, prompts, and metadata. Reviewers need to understand that surface before the server becomes trusted agent context.
Why Orisan
Infrastructure for the approval moment.
01
MCP-aware from day one
Orisan starts from how AI agents actually connect to tools: MCP servers, exposed capabilities, metadata, and the quiet permissions around them.
02
Local-first where it matters
Teams should not have to upload source code, prompts, secrets, or raw MCP responses to understand MCP server exposure.
03
Evidence before theater
We care less about broad AI claims and more about specific findings that engineering and security reviewers can act on.
Values
Operating model
Study where AI agents connect to MCP servers, tools, prompts, and developer workflows.
Define the risk model in language engineering and security teams can share.
Build local-first checks that surface exposure without uploads.
Turn useful evidence into reports teams can review before connecting agents to new MCP servers.
Founder
Rakesh Bhavandlapelli
Founder. Builder.