MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Magic Patterns
23 tools · footprint 28
2 high 8 med 13 low
WordPress.com
19 tools · footprint 28
3 high 6 med 10 low COSOSOX
Grain
15 tools · footprint 27
1 high 10 med 4 low
Oracle NetSuite
11 tools · footprint 27
3 high 3 med 5 low COSOSOX
Databricks
5 tools · footprint 26
1 critical 2 high 2 med COSOSOX
Lusha
22 tools · footprint 26
1 critical 6 high 15 low
Outlook Mail
10 tools · footprint 26
6 high 4 med
Airwallex Developer MCP
18 tools · footprint 25
1 critical 8 med 9 low COSOGLBA+3 more
Calendly
22 tools · footprint 25
15 med 7 low
Metabase
13 tools · footprint 25
1 critical 4 high 8 low
Atlassian Rovo
54 tools · footprint 24
13 med 41 low
Cognito Forms
9 tools · footprint 24
2 high 6 med 1 low HIPAA
Local Falcon
25 tools · footprint 24
1 high 9 med 15 low
ZoomInfo
15 tools · footprint 24
5 high 4 med 6 low
Braze
40 tools · footprint 23
1 high 5 med 34 low COSOSOX
Glean
11 tools · footprint 23
3 high 7 med 1 low
‹ PrevPage 5 of 19Next ›
DataGrail (Vera)Docs ↗
8 med 15 low · 23 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (0 of 23)

None — every tool is low-risk, high-confidence, and outside PCI/HIPAA payload scope.
All other tools (23)
datagrail.add_system medium conf mediumaudit
Adds a new system to the Live Data Map inventory, changing the record of where the organization processes and stores data for its RoPA and audits.
datagrail.answer_assessment_question medium conf mediumaudit
Records an answer to a question within a risk assessment, directly populating the compliance documentation that DPIA and vendor-review conclusions rest on.
datagrail.associate_processing_activity medium conf mediumaudit
Links processing activities to an inventory system in the Live Data Map, reshaping the record-of-processing that regulators and auditors rely on.
datagrail.create_assessment medium conf mediumaudit
Creates a new privacy/risk assessment (PIA, DPIA, or vendor review) record from a template, establishing a governance artifact in the compliance program.
datagrail.fetch_configured_integration_catalog low conf mediumallow
Lists the organization's connected integrations with connection status and capabilities, revealing which systems are wired to DataGrail; configuration only.
datagrail.fetch_cookies low conf mediumallow
Reads cookies awaiting categorization along with suggested and existing consent rules; cookie-configuration metadata, read-only.
datagrail.fetch_integration_catalog low conf mediumallow
Browses the catalog of available and discovered integrations; product-catalog metadata, read-only.
datagrail.fetch_integration_errors low conf mediumallow
Retrieves integration errors grouped by integration and type with sample details for troubleshooting; operational diagnostics, read-only.
datagrail.fetch_tags low conf mediumallow
Reads tags (services) that still need a consent category assigned; configuration metadata, read-only.
datagrail.get_banner_status low conf mediumallow
Reports consent banner and container status, publish state, consent categories, and deployed domains; deployment configuration, read-only.
datagrail.get_consent_privacy_policies low conf mediumallow
Reads consent privacy policies defining banner behavior per framework, including consent modes and GPC/DNT settings; configuration metadata, read-only.
datagrail.get_consent_updates low conf mediumallow
Reads the consent configuration change timeline, including publish events, draft changes, and failed publishes; change-history metadata, read-only.
datagrail.get_request_policies low conf mediumallow
Reads the configured privacy request policies, including legal frameworks, verification methods, and supported rights; configuration metadata with no individual personal data.
datagrail.get_ticket_activity_log medium conf mediumaudit
Exposes a privacy request's full activity trail including state changes and emails sent to the data-subject, revealing that individual's personal data and handling history.
datagrail.search_assessment_templates low conf mediumallow
Lists prebuilt and custom assessment templates and their IDs; template metadata with no sensitive data.
datagrail.search_assessments low conf mediumallow
Reads completed and in-progress assessments with deadlines and contributors; internal governance metadata, read-only.
datagrail.search_inventory low conf mediumallow
Reads the Live Data Map inventory of detected systems and data stores with risk indicators; system-level metadata, read-only.
datagrail.search_knowledgebase_docs low conf mediumallow
Runs a semantic search over DataGrail's knowledgebase documentation; public product content, read-only.
datagrail.search_opt_outs medium conf mediumaudit
Returns opt-out (do-not-sell/share) requests keyed to requester identifiers such as email; a broad filter exposes many consumers' opt-out choices at once.
datagrail.search_risks low conf mediumallow
Reads the risk register listing identified risks and their mitigation status; internal governance data with no individual personal data.
datagrail.search_tickets medium conf mediumaudit
Returns privacy request (DSAR) tickets containing requester personal data such as names and emails; a broad filter can surface many data-subjects at once.
datagrail.submit_product_feedback low conf mediumallow
Submits product feedback, a feature request, or a bug report on behalf of the user; low-impact and reversible.
datagrail.update_assessment medium conf mediumaudit
Changes an assessment's name, due date, or status; altering status can prematurely mark a DPIA or vendor review complete and distort compliance tracking.