MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
DataGrail (Vera)Docs ↗
8 med 15 low · 23 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (0 of 23)

None — every tool is low-risk, high-confidence, and outside PCI/HIPAA payload scope.
All other tools (23)
datagrail.add_system medium conf mediumaudit
Adds a new system to the Live Data Map inventory, changing the record of where the organization processes and stores data for its RoPA and audits.
datagrail.answer_assessment_question medium conf mediumaudit
Records an answer to a question within a risk assessment, directly populating the compliance documentation that DPIA and vendor-review conclusions rest on.
datagrail.associate_processing_activity medium conf mediumaudit
Links processing activities to an inventory system in the Live Data Map, reshaping the record-of-processing that regulators and auditors rely on.
datagrail.create_assessment medium conf mediumaudit
Creates a new privacy/risk assessment (PIA, DPIA, or vendor review) record from a template, establishing a governance artifact in the compliance program.
datagrail.fetch_configured_integration_catalog low conf mediumallow
Lists the organization's connected integrations with connection status and capabilities, revealing which systems are wired to DataGrail; configuration only.
datagrail.fetch_cookies low conf mediumallow
Reads cookies awaiting categorization along with suggested and existing consent rules; cookie-configuration metadata, read-only.
datagrail.fetch_integration_catalog low conf mediumallow
Browses the catalog of available and discovered integrations; product-catalog metadata, read-only.
datagrail.fetch_integration_errors low conf mediumallow
Retrieves integration errors grouped by integration and type with sample details for troubleshooting; operational diagnostics, read-only.
datagrail.fetch_tags low conf mediumallow
Reads tags (services) that still need a consent category assigned; configuration metadata, read-only.
datagrail.get_banner_status low conf mediumallow
Reports consent banner and container status, publish state, consent categories, and deployed domains; deployment configuration, read-only.
datagrail.get_consent_privacy_policies low conf mediumallow
Reads consent privacy policies defining banner behavior per framework, including consent modes and GPC/DNT settings; configuration metadata, read-only.
datagrail.get_consent_updates low conf mediumallow
Reads the consent configuration change timeline, including publish events, draft changes, and failed publishes; change-history metadata, read-only.
datagrail.get_request_policies low conf mediumallow
Reads the configured privacy request policies, including legal frameworks, verification methods, and supported rights; configuration metadata with no individual personal data.
datagrail.get_ticket_activity_log medium conf mediumaudit
Exposes a privacy request's full activity trail including state changes and emails sent to the data-subject, revealing that individual's personal data and handling history.
datagrail.search_assessment_templates low conf mediumallow
Lists prebuilt and custom assessment templates and their IDs; template metadata with no sensitive data.
datagrail.search_assessments low conf mediumallow
Reads completed and in-progress assessments with deadlines and contributors; internal governance metadata, read-only.
datagrail.search_inventory low conf mediumallow
Reads the Live Data Map inventory of detected systems and data stores with risk indicators; system-level metadata, read-only.
datagrail.search_knowledgebase_docs low conf mediumallow
Runs a semantic search over DataGrail's knowledgebase documentation; public product content, read-only.
datagrail.search_opt_outs medium conf mediumaudit
Returns opt-out (do-not-sell/share) requests keyed to requester identifiers such as email; a broad filter exposes many consumers' opt-out choices at once.
datagrail.search_risks low conf mediumallow
Reads the risk register listing identified risks and their mitigation status; internal governance data with no individual personal data.
datagrail.search_tickets medium conf mediumaudit
Returns privacy request (DSAR) tickets containing requester personal data such as names and emails; a broad filter can surface many data-subjects at once.
datagrail.submit_product_feedback low conf mediumallow
Submits product feedback, a feature request, or a bug report on behalf of the user; low-impact and reversible.
datagrail.update_assessment medium conf mediumaudit
Changes an assessment's name, due date, or status; altering status can prematurely mark a DPIA or vendor review complete and distort compliance tracking.