MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
incident.ioDocs ↗
1 high 6 med 18 low · 25 tools · 0 SoD-flagged
regimes APPICCPAGDPRISO_27001LGPDPIPEDAPIPLPOPIASOC2UK_GDPR

Tools needing tighter control (1 of 25)

incident-io.investigation_sync high conf highOBO
Downloads a complete incident investigation as an archive of timeline, telemetry, and communications, creating an offline copy of potentially sensitive operational and personal data outside incident.io's controls.
All other tools (24)
incident-io.alert_list low conf highallow
Searches and browses alerts across configured sources.
incident-io.alert_show low conf highallow
Returns full alert details and its linked incidents for one alert.
incident-io.analysis_start low conf highallow
Kicks off a structured operational analysis using playbooks and a report template, creating a new analysis workspace.
incident-io.ask medium conf mediumaudit
Runs the on-call AI agent that answers queries and takes schedule-management actions, giving broad natural-language reach across on-call state in a single call.
incident-io.ask_incident medium conf mediumaudit
Runs the incident AI agent that investigates and takes management actions on incidents, so a single prompt can mutate live incident state.
incident-io.ask_telemetry medium conf mediumaudit
Queries logs, metrics, traces, and dashboards through the telemetry AI agent, exposing observability data that may include internal identifiers or secrets.
incident-io.catalog_entry_show low conf highallow
Returns a full catalog entry with all attributes, exposing service or ownership metadata for one resource.
incident-io.catalog_type_list low conf highallow
Lists catalog types such as Service and Team defined in the organisation.
incident-io.escalation_list low conf highallow
Searches escalations (pages), surfacing recent and active paging activity.
incident-io.escalation_path_show low conf highallow
Reveals who would be paged at each level of an escalation path, exposing the responder contact chain.
incident-io.escalation_respond medium conf highaudit
Acknowledges or declines a page, redirecting who owns the live response to an escalation.
incident-io.escalation_stats low conf highallow
Returns paging counts by path, priority, and time of day, exposing on-call load patterns.
incident-io.feedback low conf highallow
Submits feedback about the MCP tools back to incident.io.
incident-io.follow_up_create low conf highallow
Adds a post-incident follow-up item, recording a remediation commitment against the incident.
incident-io.incident_create medium conf highaudit
Opens a new incident record, kicking off on-call paging and response workflows for the affected team.
incident-io.incident_list low conf highallow
Lists and filters incidents, surfacing the incident backlog and its workload distribution.
incident-io.incident_show low conf highallow
Returns full incident details including investigation notes and post-mortem, exposing the complete response record for one incident.
incident-io.incident_stats low conf highallow
Returns aggregate incident counts and workload across many dimensions, revealing operational health metrics.
incident-io.incident_update medium conf highaudit
Changes incident status, severity, roles, or custom fields, altering both the live response and the post-incident record.
incident-io.resource_show low conf highallow
Reads organisation configuration, analysis playbooks, or telemetry datasources, exposing platform setup details.
incident-io.schedule_list low conf highallow
Lists on-call schedules configured across the organisation.
incident-io.schedule_show low conf highallow
Shows an on-call schedule with current and upcoming shifts, revealing which named individuals are on call and when.
incident-io.team_list low conf highallow
Lists teams defined in the organisation.
incident-io.team_show low conf highallow
Returns team details including owned escalation paths, alert sources, and schedules.