MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
GoCardlessDocs ↗
2 critical 3 high 1 med 3 low · 9 tools · 1 SoD-flagged
regimes CCPACOSOGDPRGLBAISO_27001PIPEDAPSD2SOC2SOXUK_GDPR

Tools needing tighter control (5 of 9)

gocardless.payments critical conf mediumhuman approval
Creates, retries, and cancels bank debits against live customer mandates — money moves out of a payer's account and the collection lands in the merchant's revenue ledger.
gocardless.refunds critical conf mediumhuman approval
Issues refunds that return collected funds to a payer, reversing recognised revenue and disbursing money with a single actor and no second approver.
gocardless.mandates high conf mediumOBO
Cancels a customer's Direct Debit authorisation, permanently ending the merchant's right to collect from that payer until a new mandate is signed.
gocardless.subscriptions high conf mediumOBO
Creates recurring billing schedules that draw funds from a payer on every interval, committing future revenue without further review.
gocardless.customers high conf mediumOBO
Browses the full payer list and individual customer records, surfacing personal and banking-relationship data at list scale even with sensitive fields masked.
All other tools (4)
gocardless.events low conf mediumallow
Reads the lifecycle history of payments and mandates, revealing when each was submitted, confirmed, or failed.
gocardless.integration_guidance low conf mediumallow
Returns GoCardless API reference material, integration patterns, and code samples; no account data is touched.
gocardless.payment_links medium conf mediumaudit
Generates shareable billing request flows that solicit payment authorisation from customers under the merchant's brand.
gocardless.payouts low conf mediumallow
Reads settlement amounts and dates paid into the merchant's bank account, exposing revenue volumes to whoever holds the connection.