BusinessMCP

By application only

Custom AI development for your enterprise

Custom AI software built on your own data: your systems unified behind one governed MCP endpoint, so any model you choose can answer questions, build software and automate real work — inside your perimeter.

Scoped after a discovery call · A founder replies within 48 hours

Your systems

SAPSnowflakeDatabricksPostgresGitHubInternal APIsLegacy systemsDocument stores
Your MCP layer

Every system behind one governed endpoint — deployed inside your own perimeter, not ours.

Access rules, approvals, audit log

Built, documented and handed over

Your people and your agents

ClaudeChatGPTGeminiCursorInternal appsAny MCP agent

Three stages, in that order: your data in one placegoverned access for AIAI that builds and automates. Most companies are stuck on the first one, which is why the pilots stall.

Why now

Everyone bought AI. Almost nobody deployed it.

The same three failures, in nearly every programme we get called into.

Pilots that never ship

Three pilots this year, none in production. They impress in the meeting and die in the real workflow.

The important data is out of reach

Your best data sits in a fifteen-year-old system and internal APIs no model has ever seen.

Security says no, and they are right

Every promising tool wants your data in someone else’s cloud. Nobody senior is going to sign that.

Stage one

First, your business data ends up in one place

Most companies do not have an AI problem. They have a data problem that AI makes impossible to ignore.

One set of numbers

Analytics, CRM, ad spend, revenue and product usage behind a single source of truth, so one question stops getting three answers depending on who you ask. Enterprise data unification, which is most of the job.

Your internal systems, finally reachable

The old ERP, the internal API nobody documented, the database that is not allowed to leave the building. We build an MCP server over each one, on your own infrastructure — and anything we do not support yet becomes a first-party connection.

Retrieval that cites the paragraph

Contracts, policies, runbooks and schemas chunked, embedded and retrieved at question time, so an answer shows where it came from. Custom RAG architecture over your own documents, not a model guessing.

Answers in plain English

Someone asks why enterprise signups dropped last month and gets a straight answer with the numbers behind it. Business intelligence without a business-intelligence project.

Stage two

Then it is safe to hand to AI

Where most AI projects die: the data exists, and nobody signs off on a model touching it without governance they can read.

Capability, not custody

An agent uses your connected tools without ever seeing the credentials behind them. Keys sit in a vault your own signed-in session cannot read back.

You decide what each agent may see

Give a contractor’s AI the analytics and nothing else. The rule is applied four times over: prompt, tool list, execution, and what comes back.

Nothing leaves without a person

Every email and every ad-budget change waits for approval. Code arrives as a pull request, never as a commit to your default branch.

No model lock-in

One open protocol, so Claude, GPT and Gemini reach the same tools. Bring your own key and inference runs on your account, not ours.

Our hardening is public

The gateway code that stops a connected server reaching internal addresses is MIT, with its tests and a write-up of a real bypass we found in it.

Secure custom AI software for an enterprise is two different things, and vendors conflate them. A server we build for you runs in your own perimeter and we never see what passes through it. The platform runs on our infrastructure with its database in the EU — the security page, the DPA and every named sub-processor are what your reviewer wants.

For your security reviewer: data privacy and governance, specifically

On your BusinessMCP workspace

Shipped today, and every line of it checkable.

  • Every table scoped to a workspace by Postgres row-level security
  • Connected keys and OAuth tokens in a deny-all vault — RLS on with zero policies, so not even your own session can read them back
  • Platform API keys stored as SHA-256 hashes; the key itself is shown once and never again
  • Scoped keys carrying an access policy over 13 data classes, enforced in the prompt, the tool list, execution and the output
  • A policy that cannot be loaded fails closed, never open
  • An OAuth 2.1 consent screen that binds a policy at connection time — PKCE S256 only, exact-match redirect URIs
  • Every email send is approval-gated; code changes arrive as a pull request, never a commit to your default branch
  • A workspace audit log of privileged actions, readable and exportable as CSV
  • Enforced 2FA and allowed sign-in domains, per workspace

In your own perimeter

What the engagement delivers, on infrastructure you control.

  • A custom MCP server deployed inside your perimeter — your VPC or your own hardware
  • A data-flow review, written for the people who have to sign it off
  • Recording retention set to your policy rather than ours
  • All delivered source code and documentation, yours to keep

Stage three

Then AI does the work

Once the data is reachable and the rules hold, using AI stops being a project and becomes a Tuesday.

The work your team does by hand

A quote assembled out of three systems, an onboarding pack, a nightly reconciliation. We build the agent workflow once and it runs inside your systems, under your approvals.

Development against the real thing

Your engineers point Claude Code, Cursor or ChatGPT at the same endpoint and it reads the actual schema and the actual API, instead of guessing at your business.

Off the pile of one-off scripts

Brittle automation chains and the abandoned AI pilot consolidate onto one platform your team is trained to extend without us.

Proof

We run this on ourselves

Every number below is our own, pulled by the AI business analyst and replayed here. Not a mockup.

app.businessmcp.com/assistant

What can I help you grow today?

Pick a question our founder actually asked and watch the analyst pull the real numbers.

Try it on your data — free

A real conversation from our workspace, replayed.

Where this lands

Regulated data is the normal case

We are not a legal-tech or fintech specialist shop. The fit is the data constraint, not the vertical — and it is the same one each time.

Legal and professional services

Custom legal-tech AI development, with privileged documents and matter data staying inside the firm’s own perimeter rather than going near a public model.

Financial services

Enterprise financial services AI development lives on the trail: regulated records, access rules per agent, a log your reviewer can export.

Anything under the same rules

Healthcare, public sector, manufacturing IP. If “can this data leave the building” is a no, the architecture is the same one.

The workspace

What Enterprise adds to the product

An enterprise AI solution provider sells you a platform too. Ours is in the engagement — here against Business, the top self-serve tier.

Business is $499/mo self-serve. Enterprise is contracted, and the last four rows are the engagement itself.
 BusinessEnterprise
Monthly unique visitors50,000Unlimited
Team seats10Unlimited
AI business analyst runs a month5,000 / moUnlimited
Control what each person and agent can seeFive presetsPresets, or your own rules
Audit log of privileged actions, exportableNoYes
Require 2FA and restrict sign-in to your domainsNoYes
Session-recording retention you setKept while the account is openYour window
Custom servers over your internal systemsNoIn the engagement
Runs inside your own perimeterNoIn the engagement
You keep the source code and the docsNoIn the engagement
A founder on it end to endNoYes

Every self-serve tier is on the pricing page.

Straight answers

Where we are the wrong call

A page that only cuts one way is an advert. Honestly:

No SOC 2 report and no ISO 27001. If procurement needs one before signing, we fail that gate today — the security page, the DPA and the published code are what we offer instead.
Founder-led means capacity-limited. There is a queue. If you need six people starting Monday, we are not it.
No 24/7 on-call, no NOC, no procurement portal. Two founders who answer — better than a support tier most days, worse than one at 3am.
Not a staffing shop. We will not place engineers in your team or take over a backlog; an engagement is a scoped build with a handover date.
Most teams should start on the self-serve product: $19 to $499 a month for the endpoint, the analyst and the dashboard. Come here when you need custom servers over internal systems.

The process

How an engagement runs

Enterprise artificial intelligence consulting that ends in shipped software, in three steps.

101 · Discovery

Discovery call

A 45-minute working session with a founder. We map your highest-leverage gaps and say plainly if we are not the right fit.

202 · Proposal

Scoped proposal

Bespoke AI development services quoted upfront, as a fixed-scope pilot — typically one internal server or one automated workflow. The typical pilot runs about six weeks to production.

303 · Handover

Build and hand over

We build alongside your team, train them as it is built, and hand over the code and the docs. The goal is that you extend it without us.

Companies running MCP servers with us

Makers and companies publishing a server in the BusinessMCP directory.

Apply for an engagement

Tell us about your systems and where AI keeps failing your team. A founder reads every application and replies within 48 hours — including when the answer is no.

Reviewed personally by the founders. No sales team, no drip campaigns.

Questions

What leadership teams ask

The ones that come up on nearly every discovery call.

What does an engagement cost?

There is no list price, and we would rather not quote one before we know what we are building. The platform is priced the way every other tier is, on your monthly visitor volume; the custom development is quoted on top of that once the scope is clear. You get both numbers in writing after the discovery call, before anything is committed.

How long before something is actually live?

Discovery usually happens within a week of an application, and the typical pilot runs about six weeks from kickoff to production. Whether the build starts straight after discovery depends on what is already in flight — we would rather give you the real date on the call than promise a start we cannot make.

What changes for my team day to day?

Early on, very little: we are building and your people carry on as they are. What changes by the end is where the answers come from — anyone can ask a question directly and get it with the working shown, instead of waiting two days on an analyst. Work your team repeats by hand moves to something that runs on its own, one piece at a time, with a person still approving anything that leaves the building.

Do we have to replace the tools we already use?

No, and that is rather the point. The endpoint sits over the tools you already run, and custom servers wrap your existing databases and internal APIs rather than replacing them. Nobody has to change how they work for this to pay off.

Are we locked into one AI model?

No. Everything we build speaks the Model Context Protocol, so Claude, GPT and Gemini reach the same tools. Use Claude today, switch to Gemini next year, run open models on your own hardware for sensitive work — nothing we built breaks. Connect your own model key and inference runs on your account rather than ours.

What happens after the engagement ends?

You keep everything: source code, documentation, and a team trained on the system. We design for our own obsolescence — the goal is that you extend it without us.

Do you build retrieval, or only connect tools?

Both, and they are different jobs. Connecting a tool gives an agent a live query against a system that can answer one. Retrieval is for the material that cannot — contracts, policies, runbooks, internal schemas — which we chunk, embed and fetch at question time so an answer can cite the paragraph it came from. A custom RAG architecture is usually one part of an engagement rather than the whole of it, and we will say so if retrieval is not actually your problem.

Do you work in legal or financial services?

Yes, and in anything else where the data cannot leave the building. We are not a vertical specialist and will not pretend to be: what we bring is the architecture that makes regulated data usable — the server inside your own perimeter, access rules per agent, human approval on anything that leaves, and an exportable audit log. If your procurement needs a named reference in your own sector before signing, we do not have one to give you.

Do you train or fine-tune models?

No. We build the system around a model rather than the model itself: retrieval, tools, access rules, and routing between providers. That is where we have seen the answer quality actually come from, and it leaves you free to change model next year without rebuilding. If what you need is a trained or fine-tuned model of your own, we are the wrong shop and will tell you on the call.

Where does our data actually live?

Two answers, because there are two things. A custom MCP server we build for you runs inside your perimeter — your VPC, your own hardware — and we do not operate it or see what passes through it. The BusinessMCP platform is a different thing: it runs on Vercel with its database in Supabase’s EU region, it stores what it is for (analytics events up to 13 months, contacts, agent runs and tool calls), and every sub-processor is named with its location and purpose on the privacy page. Connect your own model key and inference goes to your account instead of ours. We would rather draw that line clearly than tell you we store nothing.

Can we enforce 2FA and restrict who can sign in?

Yes, on Enterprise, per workspace in Settings. You can require two-factor authentication for every member — enforced against the session, so it holds however someone signed in — and restrict membership to your own email domains. You can also build access policies over 13 data classes and assign them to teammates or to individual API keys, so a contractor’s agent reads analytics and never revenue or contact details.

Can we audit your security code?

Part of it, yes. The gateway hardening we run in production — the SSRF guard that stops a user-supplied MCP server URL from reaching internal or cloud-metadata addresses, plus the upstream failure classification around it — is published under MIT at github.com/businessmcp/mcp-gateway, with the tests. The README walks through a real bypass we found in our own guard and the fix. The rest of the platform is closed, and we would rather say so plainly than claim more than we ship.

What is not included?

We do not place engineers into your team, take over a backlog, or do change-management consulting. An engagement is a scoped build with a handover date; anything outside that scope is a new scope, quoted separately. We also do not run your ad accounts or write your content.