MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
FreshserviceDocs ↗
5 high 12 med 6 low · 23 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (5 of 23)

freshservice.fetchOffboardingRequests high conf highOBO
Returns every offboarding request, exposing who is leaving the organization along with their personal data — sensitive HR and access-lifecycle detail at scale.
freshservice.fetchAgents high conf highOBO
Returns the full directory of support agents, exposing staff names, emails, and role assignments across the account.
freshservice.fetchRequesters high conf highOBO
Returns the full requester directory — potentially every end user in the organization — exposing names and contact details at scale.
freshservice.fetchTickets high conf highOBO
Returns all existing tickets, exposing requester identities and free-text support content that routinely contains personal data across the whole helpdesk.
freshservice.fetchTicketFilter high conf highOBO
Runs an arbitrary field filter across tickets and returns every match, enabling bulk extraction of support records and the personal data they hold.
All other tools (18)
freshservice.createAsset medium conf mediumaudit
Adds a new asset to the configuration database, altering the recorded IT estate that change and audit processes rely on.
freshservice.createOffboardingRequest medium conf mediumaudit
Initiates an employee offboarding request that drives deprovisioning of a departing worker's accounts and access; a leaver's personal data flows through it.
freshservice.createOnboardingRequest medium conf mediumaudit
Initiates an employee onboarding request carrying new-hire personal data that drives account, access, and equipment provisioning downstream.
freshservice.createSolutionArticle low conf highallow
Publishes a new knowledge-base article; reversible content write to the solutions library.
freshservice.createSolutionFolder low conf highallow
Creates a folder in a knowledge-base category; low-impact organizational write.
freshservice.createTicket low conf highallow
Opens a new support ticket; routine, reversible helpdesk write with limited blast radius.
freshservice.createTicketNote low conf highallow
Appends a note to a ticket; reversible, low-impact addition to a support record.
freshservice.fetchAgent medium conf highaudit
Returns one agent's profile, including personal contact details and role assignment.
freshservice.fetchAsset low conf mediumallow
Returns a single asset record by ID from the configuration database.
freshservice.fetchAssets medium conf mediumaudit
Returns the full asset inventory (CMDB), exposing hardware, software, and configuration records across the estate.
freshservice.fetchOffboardingRequestTickets medium conf highaudit
Returns the tickets tied to offboarding requests, revealing deprovisioning tasks and the personal data of departing workers.
freshservice.fetchOnboardingRequest medium conf highaudit
Returns a single onboarding request containing a new hire's personal details and planned access grants.
freshservice.fetchRequester medium conf highaudit
Returns one requester's profile including personal contact details.
freshservice.fetchTicket medium conf highaudit
Returns a single ticket by ID, including the requester's identity and support conversation, which may contain personal data.
freshservice.placeRequestServiceCatalogItem medium conf mediumaudit
Places a service-catalog request that can trigger fulfillment such as software, hardware, or access provisioning depending on the catalog item.
freshservice.updateAsset medium conf mediumaudit
Modifies an existing asset record, changing configuration-database state that downstream change management depends on.
freshservice.updateSolutionArticle low conf highallow
Edits an existing knowledge-base article; reversible change to published support guidance.
freshservice.updateTicket medium conf highaudit
Modifies an existing ticket's fields and state, changing support-record status, assignment, or priority.