MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Legal Data Hunter
7 tools · footprint 8
7 low
Melon
18 tools · footprint 8
6 med 12 low
Jentic
3 tools · footprint 7
1 critical 2 low
Profound
25 tools · footprint 7
2 med 23 low
TickTick
23 tools · footprint 7
7 med 16 low
AirOps
40 tools · footprint 6
5 med 35 low
Eraser
20 tools · footprint 6
1 high 1 med 18 low
LegalZoom
24 tools · footprint 6
5 med 19 low
Intuit TurboTax
5 tools · footprint 5
1 high 1 med 3 low GLBA
Adobe Experience Manager
7 tools · footprint 4
2 med 5 low
Adobe Journey Optimizer
3 tools · footprint 4
3 low
Bitly
25 tools · footprint 4
4 med 21 low
E2B
1 tools · footprint 4
1 high
Function (Function Health)
3 tools · footprint 4
2 med 1 low HIPAA
Medidata
2 tools · footprint 4
1 med 1 low
CoCounsel Legal
4 tools · footprint 3
3 med 1 low
‹ PrevPage 14 of 19Next ›
HarveyDocs ↗
1 med 4 low · 5 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (0 of 5)

None — every tool is low-risk, high-confidence, and outside PCI/HIPAA payload scope.
All other tools (5)
harvey.ask_about_vault medium conf mediumaudit
Surfaces AI-generated answers derived from confidential documents in a specific Vault project, which routinely hold client PII and privileged legal material.
harvey.ask_harvey low conf mediumallow
Returns an AI-generated answer from Harvey's general legal knowledge base; no client or matter data is accessed.
harvey.ask_with_knowledge_source low conf mediumallow
Queries a designated legal research knowledge source and returns an AI-generated answer scoped to that source.
harvey.list_knowledge_sources low conf mediumallow
Lists the research knowledge sources available to the account for scoping subsequent legal queries.
harvey.list_vault_projects low conf mediumallow
Enumerates the Vault projects the authenticated user can access, revealing client-matter names and workspace structure.