MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
CalendlyDocs ↗
15 med 7 low · 22 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (0 of 22)

None — every tool is low-risk, high-confidence, and outside PCI/HIPAA payload scope.
All other tools (22)
calendly-api.availability-list_user_busy_times low conf mediumallow
Lists a user's busy time blocks within a date range, revealing when they are unavailable.
calendly-api.event_types-create_event_type low conf mediumallow
Creates a new bookable event type, adding a scheduling offering to the account.
calendly-api.event_types-update_event_type medium conf mediumaudit
Updates an existing event type's configuration, changing how and when it can be booked.
calendly-api.event_types-update_event_type_availability_schedule medium conf mediumaudit
Changes the availability schedule tied to an event type, altering the windows when it can be booked.
calendly-api.meetings-cancel_event medium conf highaudit
Cancels a scheduled event, notifying invitees and freeing the booked time slot.
calendly-api.meetings-create_invitee medium conf highaudit
Books a meeting on an event type, recording the invitee's name, email, and responses to booking questions.
calendly-api.meetings-create_invitee_no_show low conf mediumallow
Flags an invitee as a no-show for a scheduled event, recording attendance behavior against that person.
calendly-api.meetings-delete_invitee_no_show low conf mediumallow
Clears the no-show flag on an invitee, restoring their attendance record for the event.
calendly-api.meetings-get_event low conf mediumallow
Returns details of one scheduled event including its time, location, and membership.
calendly-api.meetings-get_event_invitee medium conf highaudit
Returns one invitee's booking details including name, email, and answers to scheduling questions.
calendly-api.meetings-list_event_invitees medium conf highaudit
Lists all invitees for a scheduled event with their names, emails, and question responses, enabling bulk read of attendee PII.
calendly-api.meetings-list_events medium conf highaudit
Lists scheduled events across a user or organization with their times, locations, and status.
calendly-api.organizations-create_organization_invitation medium conf highaudit
Emails an organization invitation that provisions a new member into the Calendly org once accepted, writing the invitee's email address.
calendly-api.organizations-get_organization_membership medium conf highaudit
Returns one organization member's profile, role, and email address.
calendly-api.organizations-list_organization_invitations medium conf highaudit
Lists pending organization invitations, exposing the email addresses of everyone invited but not yet joined.
calendly-api.organizations-list_organization_memberships medium conf highaudit
Lists every member of the organization with their names, email addresses, and roles, enabling bulk extraction of the member directory.
calendly-api.organizations-revoke_organization_invitation medium conf highaudit
Revokes a pending organization invitation, removing a prospective member's access before they can join.
calendly-api.routing_forms-get_routing_form_submission medium conf highaudit
Retrieves a single routing form submission with the respondent's answers and contact information.
calendly-api.routing_forms-list_routing_form_submissions medium conf highaudit
Lists submissions to a routing form, exposing in bulk the contact details and answers respondents entered.
calendly-api.scheduling_links-create_single_use_scheduling_link low conf mediumallow
Generates a single-use scheduling link for an event type that lets one recipient book a meeting.
calendly-api.shares-create_share low conf mediumallow
Creates a customized single-use scheduling link from an event type for sharing with a recipient.
calendly-api.users-get_user medium conf highaudit
Returns a specific user's profile including name, email, timezone, and scheduling URL.