Inquire +
ALEETH · The only ICA-governed stateless MCP in the world

Stateless.
And governed.

On July 28 the industry rebuilds its AI connectors to one new standard. Of every server ready for it, exactly one also governs and proves every action it takes. That one is ALEETH. It is the only ICA-governed, stateless MCP in the world, it is live, and it is independently graded.

INDEPENDENTLY GRADED · 2026-07-13 · RE-VERIFIED 2026-07-24 · mcp-spec-check
Readiness
YES
for the 2026-07-28 spec
Overall grade
A
7 pass · 0 fail · 1 warn
Required checks
3 / 3
discover · routing · stateless
Ready in the registry
1 of 4,356
public scan · 2026-07-12

The whole field resets on one date

MCP is the standard that lets any AI connect to a system and use its tools. On July 28 it goes stateless, forcing nearly every server on it to be rebuilt. A public scan of the official registry on July 12 found that of more than four thousand reachable servers, exactly one was ready. The field is open, and a hard deadline is about to reshuffle it.

A governed action, on the live server

A read-only identity connects, reads real data, seals a signed receipt, and has that receipt verified. Then it tries to act, and is refused. Captured from the live run on 2026-07-13.

ALEETH Authority MCP · governed action console
connected to ALEETH Authority MCP · write scopes: none READ-ONLY
governed read  list_frameworks
   158 governance frameworks on file
sealing signed receipt
   c918345a03339fcdd83502d0597ed6ba25f813f380592bb17c160269d9151de5
verifying the receipt on the public ledger
   VALID · signature ✓ · hash ✓
emergency kill switch  stop_agent
   REFUSED BLOCKED caller lacks the required scope
write a ledger entry  issue_receipt
   REFUSED BLOCKED caller lacks the required scope

Read what it was permitted to read, with a verified receipt. Refused every action it was not permitted to take.

Stateless is the plumbing. Governed is the moat.

The public readiness test checks three things, and all three are about transport: a discovery step, routing headers, and no session pinning. Not one asks whether the server controls what the AI does, or whether it can prove it afterward. So the other ready server is stateless. Ours is stateless and governed. Their own test cannot see the difference.

The one warning, published on purpose

The scan returns seven passes, no failures, and one warning. We print it rather than round it away. The warning says the server declares a capability the new spec removed. We do not serve that method. We serve the replacement the spec defines, and the library underneath us sets the old flag precisely because we serve the new mechanism. The scanner reads that flag as the old capability. On the substance we are conformant. On the scoreboard we carry a warning, and it is still there on the re-verified run.

We sell the difference between a claim and a receipt. That has to hold for our own scorecard first.

Three graders, three fields of view

Different registries measure different things, and none of them is wrong. Each one sees exactly what its method can reach. Read the three together and the picture is complete.

mcp-spec-check
Live black-box probe. It calls the running server: discovery, routing, statelessness, authentication behavior.
GRADE A 7 pass · 0 fail · 1 warn · re-verified 2026-07-24
MCPgrade
Static scan of the published package and linked repository. It never calls the server. Our implementation is private and the server is remote-only, so 4 of its 6 checks had nothing to read. The one check it could fully run, transport security, passed. We have since published the public interface and provenance repository so the scannable surface is honestly larger.
INSUFFICIENT 2 of 6 checks scannable · their report
The ICA ledger
Continuous and per-action. Every governed call is sealed with a signed receipt, hash-chained, and anchored to Bitcoin. Not a point-in-time scan: a running record.
EVERY CALL verify any receipt offline with a key you hold

A static scan can grade what a server publishes. It cannot see what a server does at runtime. That is the argument of our briefing, Stateless Is Not Governed, playing out on our own scoreboard: the grader that probes the live server grades it A, the grader that cannot reach it reports insufficient evidence, and the ledger proves each action as it happens.

Do not take our word

The scanner is public and we do not own it. With a read-only credential, one line reproduces this grade on your own machine, and every receipt verifies on the public ledger.

npx mcp-spec-check https://mcp.aleeth.com/mcp --bearer <read-only-token>

Ready when you are

See it inside your own operation.

The proof is public. The next step is private: tell us what you are evaluating, and we will show you what governed AI looks like on your systems.

Request access