MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
n8n
25 tools · footprint 56
1 critical 7 high 13 med 4 low
PagerDuty
64 tools · footprint 55
5 high 16 med 43 low
Datadog
24 tools · footprint 52
1 critical 11 high 12 med
Attention
25 tools · footprint 51
1 critical 6 high 18 med
Box
37 tools · footprint 50
10 high 14 med 13 low COSOHIPAA+1 more
Gusto
36 tools · footprint 48
12 high 11 med 13 low COSOGLBA+1 more
ActiveCampaign
58 tools · footprint 47
4 high 15 med 39 low COSOSOX
GitHub
24 tools · footprint 47
5 high 12 med 7 low COSOSOX
Sanity
36 tools · footprint 47
1 critical 5 high 12 med 18 low
Amplitude
43 tools · footprint 44
6 high 16 med 21 low
Mem
23 tools · footprint 44
5 high 8 med 10 low
Microsoft SharePoint (Work IQ)
23 tools · footprint 44
1 critical 5 high 13 med 4 low
PagerDuty
25 tools · footprint 44
6 high 18 med 1 low
Coralogix
21 tools · footprint 43
5 high 13 med 3 low
Sentry
25 tools · footprint 43
3 high 14 med 8 low
Clarify
25 tools · footprint 42
3 high 15 med 7 low
‹ PrevPage 2 of 19Next ›
QontoDocs ↗
15 high 9 med 1 low · 25 tools · 7 SoD-flagged
regimes APPICCPACOSOGDPRGLBAISO_27001LGPDNIST_CSFPCIPIPEDAPIPLPOPIAPSD2SOC2SOXUK_GDPR

Tools needing tighter control (18 of 25)

qonto.create_membership high conf mediumOBO
Invites a new member into the banking organization and sends an activation email, expanding who can access company financial data and act within the org.
qonto.list_memberships high conf mediumhuman approval
Exposes the full member roster including role, birthdate, and nationality, a bulk read of employee personal data across the organization.
qonto.create_multi_transfer_request high conf mediumOBO
Bundles up to 400 SEPA transfers into a single approval batch, staging outbound payments that an approver later signs with strong customer authentication.
qonto.change_client_invoice_status high conf mediumOBO
Finalizes or cancels a client invoice; finalizing locks it against edits and recognizes it as issued revenue with audit-trail impact.
qonto.mark_client_invoice_as_paid high conf mediumOBO
Records a client invoice as paid and stamps the payment date, directly affecting accounts-receivable and revenue reconciliation.
qonto.create_credit_note high conf mediumOBO
Issues a credit note against an existing invoice, recording a partial or full refund that reduces recognized revenue.
qonto.change_supplier_invoice_status high conf mediumhuman approval
Marks a supplier invoice paid or rejects it, an accounts-payable control action a single actor can take without a second approver.
qonto.create_card high conf mediumOBO redact
Issues a new payment card of the selected level, creating a live spending instrument tied to the organization's funds.
qonto.change_card_status high conf mediumOBO redact
Locks, unlocks, or permanently terminates a card as lost, stolen, or closed, altering an active payment instrument's usability.
qonto.get_card_iframe_url high conf mediumhuman approval redact
Returns a short-lived URL that renders the card's full PAN, expiry, and CVV, exposing sensitive cardholder data as a credential.
qonto.update_client high conf mediumOBO
Patches a client's stored personal data, a single-record write to name, contact, and tax-identifier fields.
qonto.delete_client high conf mediumhuman approval
Permanently deletes a client and auto-cancels its recurring invoices, an irreversible single-actor erasure of personal data.
qonto.list_transactions high conf mediumhuman approval
Reads a paginated feed of a bank account's transactions, a bulk pull of sensitive banking activity.
qonto.list_statements high conf mediumhuman approval
Lists monthly account statements, each carrying a short-lived presigned URL to the downloadable bank statement file.
qonto.get_statement high conf mediumhuman approval
Fetches a bank statement whose presigned file URL is a credential granting direct download of the statement document.
qonto.create_payment_link medium conf mediumaudit redact
Creates a customer-facing payment link that collects card or bank payments into a Qonto account.
qonto.update_card medium conf mediumaudit redact
Changes a card's nickname or its ATM, NFC, online, and foreign-payment option flags, adjusting spending controls on a live card.
qonto.create_card_request medium conf mediumaudit redact
Creates a flash or virtual card request for the authenticated member, pending approval before a card is issued.
All other tools (7)
qonto.approve_request low conf mediumallow
Returns a link to the web approval page for a pending expense or transfer request without executing the approval itself.
qonto.create_client medium conf mediumaudit
Creates a client record holding personal data such as name, email, phone, and tax identification number.
qonto.create_client_invoice medium conf mediumaudit
Creates a draft client invoice tied to an existing client, seeding accounts-receivable and revenue records.
qonto.decline_request medium conf mediumaudit
Declines a pending expense or transfer request, moving it to declined so the underlying financial action never runs.
qonto.delete_client_invoice medium conf mediumaudit
Deletes a draft client invoice; only drafts are accepted, but removes a nascent financial record before it is issued.
qonto.get_attachment medium conf mediumaudit
Fetches a transaction attachment via a short-lived presigned URL, exposing receipts and invoices that may contain financial detail.
qonto.get_organization medium conf mediumaudit
Returns the organization's bank accounts including IBAN, BIC, and current balance, exposing sensitive banking identifiers.