MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Microsoft 365
23 tools · footprint 41
8 high 14 med 1 low
Paytm for Business
24 tools · footprint 41
2 critical 7 high 5 med 10 low COSOPCI+1 more
Vercel
20 tools · footprint 41
2 critical 3 high 2 med 13 low COSOSOX
Cloudinary
23 tools · footprint 40
1 critical 4 high 15 med 3 low
Freshdesk
24 tools · footprint 40
6 high 14 med 4 low
Netlify
23 tools · footprint 40
2 critical 4 high 4 med 13 low
Zapier
14 tools · footprint 39
1 critical 3 high 3 med 7 low COSOPCI+1 more
Freshservice
23 tools · footprint 38
6 high 15 med 2 low
GitHub
83 tools · footprint 38
1 high 20 med 62 low COSOSOX
Bright Data
25 tools · footprint 37
5 high 17 med 3 low
Snowflake
6 tools · footprint 37
2 critical 3 high 1 med COSOSOX
Brex
25 tools · footprint 36
3 high 17 med 5 low COSOGLBA+2 more
Microsoft Dataverse
15 tools · footprint 35
1 critical 3 high 8 med 3 low
Calendly
35 tools · footprint 34
2 high 13 med 20 low
Lovable
25 tools · footprint 34
1 critical 2 high 9 med 13 low
Smartsheet
42 tools · footprint 34
2 high 9 med 31 low COSOSOX
‹ PrevPage 3 of 19Next ›
FreshserviceDocs ↗
5 high 12 med 6 low · 23 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (5 of 23)

freshservice.fetchOffboardingRequests high conf highOBO
Returns every offboarding request, exposing who is leaving the organization along with their personal data — sensitive HR and access-lifecycle detail at scale.
freshservice.fetchAgents high conf highOBO
Returns the full directory of support agents, exposing staff names, emails, and role assignments across the account.
freshservice.fetchRequesters high conf highOBO
Returns the full requester directory — potentially every end user in the organization — exposing names and contact details at scale.
freshservice.fetchTickets high conf highOBO
Returns all existing tickets, exposing requester identities and free-text support content that routinely contains personal data across the whole helpdesk.
freshservice.fetchTicketFilter high conf highOBO
Runs an arbitrary field filter across tickets and returns every match, enabling bulk extraction of support records and the personal data they hold.
All other tools (18)
freshservice.createAsset medium conf mediumaudit
Adds a new asset to the configuration database, altering the recorded IT estate that change and audit processes rely on.
freshservice.createOffboardingRequest medium conf mediumaudit
Initiates an employee offboarding request that drives deprovisioning of a departing worker's accounts and access; a leaver's personal data flows through it.
freshservice.createOnboardingRequest medium conf mediumaudit
Initiates an employee onboarding request carrying new-hire personal data that drives account, access, and equipment provisioning downstream.
freshservice.createSolutionArticle low conf highallow
Publishes a new knowledge-base article; reversible content write to the solutions library.
freshservice.createSolutionFolder low conf highallow
Creates a folder in a knowledge-base category; low-impact organizational write.
freshservice.createTicket low conf highallow
Opens a new support ticket; routine, reversible helpdesk write with limited blast radius.
freshservice.createTicketNote low conf highallow
Appends a note to a ticket; reversible, low-impact addition to a support record.
freshservice.fetchAgent medium conf highaudit
Returns one agent's profile, including personal contact details and role assignment.
freshservice.fetchAsset low conf mediumallow
Returns a single asset record by ID from the configuration database.
freshservice.fetchAssets medium conf mediumaudit
Returns the full asset inventory (CMDB), exposing hardware, software, and configuration records across the estate.
freshservice.fetchOffboardingRequestTickets medium conf highaudit
Returns the tickets tied to offboarding requests, revealing deprovisioning tasks and the personal data of departing workers.
freshservice.fetchOnboardingRequest medium conf highaudit
Returns a single onboarding request containing a new hire's personal details and planned access grants.
freshservice.fetchRequester medium conf highaudit
Returns one requester's profile including personal contact details.
freshservice.fetchTicket medium conf highaudit
Returns a single ticket by ID, including the requester's identity and support conversation, which may contain personal data.
freshservice.placeRequestServiceCatalogItem medium conf mediumaudit
Places a service-catalog request that can trigger fulfillment such as software, hardware, or access provisioning depending on the catalog item.
freshservice.updateAsset medium conf mediumaudit
Modifies an existing asset record, changing configuration-database state that downstream change management depends on.
freshservice.updateSolutionArticle low conf highallow
Edits an existing knowledge-base article; reversible change to published support guidance.
freshservice.updateTicket medium conf highaudit
Modifies an existing ticket's fields and state, changing support-record status, assignment, or priority.