MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Microsoft 365
23 tools · footprint 41
8 high 14 med 1 low
Paytm for Business
24 tools · footprint 41
2 critical 7 high 5 med 10 low COSOPCI+1 more
Vercel
20 tools · footprint 41
2 critical 3 high 2 med 13 low COSOSOX
Cloudinary
23 tools · footprint 40
1 critical 4 high 15 med 3 low
Freshdesk
24 tools · footprint 40
6 high 14 med 4 low
Netlify
23 tools · footprint 40
2 critical 4 high 4 med 13 low
Zapier
14 tools · footprint 39
1 critical 3 high 3 med 7 low COSOPCI+1 more
Freshservice
23 tools · footprint 38
6 high 15 med 2 low
GitHub
83 tools · footprint 38
1 high 20 med 62 low COSOSOX
Bright Data
25 tools · footprint 37
5 high 17 med 3 low
Snowflake
6 tools · footprint 37
2 critical 3 high 1 med COSOSOX
Brex
25 tools · footprint 36
3 high 17 med 5 low COSOGLBA+2 more
Microsoft Dataverse
15 tools · footprint 35
1 critical 3 high 8 med 3 low
Calendly
35 tools · footprint 34
2 high 13 med 20 low
Lovable
25 tools · footprint 34
1 critical 2 high 9 med 13 low
Smartsheet
42 tools · footprint 34
2 high 9 med 31 low COSOSOX
‹ PrevPage 3 of 19Next ›
CalendlyDocs ↗
15 med 7 low · 22 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (0 of 22)

None — every tool is low-risk, high-confidence, and outside PCI/HIPAA payload scope.
All other tools (22)
calendly-api.availability-list_user_busy_times low conf mediumallow
Lists a user's busy time blocks within a date range, revealing when they are unavailable.
calendly-api.event_types-create_event_type low conf mediumallow
Creates a new bookable event type, adding a scheduling offering to the account.
calendly-api.event_types-update_event_type medium conf mediumaudit
Updates an existing event type's configuration, changing how and when it can be booked.
calendly-api.event_types-update_event_type_availability_schedule medium conf mediumaudit
Changes the availability schedule tied to an event type, altering the windows when it can be booked.
calendly-api.meetings-cancel_event medium conf highaudit
Cancels a scheduled event, notifying invitees and freeing the booked time slot.
calendly-api.meetings-create_invitee medium conf highaudit
Books a meeting on an event type, recording the invitee's name, email, and responses to booking questions.
calendly-api.meetings-create_invitee_no_show low conf mediumallow
Flags an invitee as a no-show for a scheduled event, recording attendance behavior against that person.
calendly-api.meetings-delete_invitee_no_show low conf mediumallow
Clears the no-show flag on an invitee, restoring their attendance record for the event.
calendly-api.meetings-get_event low conf mediumallow
Returns details of one scheduled event including its time, location, and membership.
calendly-api.meetings-get_event_invitee medium conf highaudit
Returns one invitee's booking details including name, email, and answers to scheduling questions.
calendly-api.meetings-list_event_invitees medium conf highaudit
Lists all invitees for a scheduled event with their names, emails, and question responses, enabling bulk read of attendee PII.
calendly-api.meetings-list_events medium conf highaudit
Lists scheduled events across a user or organization with their times, locations, and status.
calendly-api.organizations-create_organization_invitation medium conf highaudit
Emails an organization invitation that provisions a new member into the Calendly org once accepted, writing the invitee's email address.
calendly-api.organizations-get_organization_membership medium conf highaudit
Returns one organization member's profile, role, and email address.
calendly-api.organizations-list_organization_invitations medium conf highaudit
Lists pending organization invitations, exposing the email addresses of everyone invited but not yet joined.
calendly-api.organizations-list_organization_memberships medium conf highaudit
Lists every member of the organization with their names, email addresses, and roles, enabling bulk extraction of the member directory.
calendly-api.organizations-revoke_organization_invitation medium conf highaudit
Revokes a pending organization invitation, removing a prospective member's access before they can join.
calendly-api.routing_forms-get_routing_form_submission medium conf highaudit
Retrieves a single routing form submission with the respondent's answers and contact information.
calendly-api.routing_forms-list_routing_form_submissions medium conf highaudit
Lists submissions to a routing form, exposing in bulk the contact details and answers respondents entered.
calendly-api.scheduling_links-create_single_use_scheduling_link low conf mediumallow
Generates a single-use scheduling link for an event type that lets one recipient book a meeting.
calendly-api.shares-create_share low conf mediumallow
Creates a customized single-use scheduling link from an event type for sharing with a recipient.
calendly-api.users-get_user medium conf highaudit
Returns a specific user's profile including name, email, timezone, and scheduling URL.