MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Magic Patterns
23 tools · footprint 28
2 high 8 med 13 low
WordPress.com
19 tools · footprint 28
3 high 6 med 10 low COSOSOX
Grain
15 tools · footprint 27
1 high 10 med 4 low
Oracle NetSuite
11 tools · footprint 27
3 high 3 med 5 low COSOSOX
Databricks
5 tools · footprint 26
1 critical 2 high 2 med COSOSOX
Lusha
22 tools · footprint 26
1 critical 6 high 15 low
Outlook Mail
10 tools · footprint 26
6 high 4 med
Airwallex Developer MCP
18 tools · footprint 25
1 critical 8 med 9 low COSOGLBA+3 more
Calendly
22 tools · footprint 25
15 med 7 low
Metabase
13 tools · footprint 25
1 critical 4 high 8 low
Atlassian Rovo
54 tools · footprint 24
13 med 41 low
Cognito Forms
9 tools · footprint 24
2 high 6 med 1 low HIPAA
Local Falcon
25 tools · footprint 24
1 high 9 med 15 low
ZoomInfo
15 tools · footprint 24
5 high 4 med 6 low
Braze
40 tools · footprint 23
1 high 5 med 34 low COSOSOX
Glean
11 tools · footprint 23
3 high 7 med 1 low
‹ PrevPage 5 of 19Next ›
GleanDocs ↗
3 high 7 med 1 low · 11 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (3 of 11)

glean.search high conf highOBO
Queries every connected enterprise source at once — documents, tickets, email indexes, HR content — so a single query can surface personal and confidential material from systems the agent was never pointed at directly.
glean.gmail_search high conf mediumOBO
Reads private mailbox threads, exposing correspondent identities, message bodies, and attachments that routinely carry personal data and privileged business discussion.
glean.outlook_search high conf mediumOBO
Reads Outlook mail and calendar entries, revealing private correspondence plus meeting attendees, times, and subjects that map an individual's relationships and movements.
All other tools (8)
glean.chat medium conf mediumaudit
Routes a free-form prompt through Glean's assistant, which synthesizes answers from indexed corporate content and can restate confidential material outside its original access context.
glean.code_search medium conf mediumaudit
Returns proprietary source code and repository contents, exposing implementation details and any credentials or keys that were committed into the codebase.
glean.employee_search medium conf mediumaudit
Reads employee directory profiles — names, roles, reporting lines, and expertise signals — producing staff personal data that feeds org-chart reconstruction and targeting.
glean.meeting_lookup medium conf mediumaudit
Surfaces meeting recordings and notes containing recorded speech and named participants, a category of personal data that often carries consent obligations of its own.
glean.memory medium conf mediumaudit
Reads and rewrites the persisted memory store for a user, so personal preferences and retained facts can be disclosed, altered, or erased without the user's involvement.
glean.memory_schema low conf mediumallow
Returns memory category and schema metadata only; no personal content is read, though it maps what personalization data the tenant stores.
glean.read_document medium conf highaudit
Pulls the full body of a named internal document into the agent context, where confidential contract, roadmap, or HR content can be reproduced downstream.
glean.user_activity medium conf mediumaudit
Returns a behavioral trail of what the user recently searched, opened, and worked on, which doubles as a productivity-monitoring record if repurposed.