MCP compliance catalog

Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
303MCP servers
4476tools
Reset 303 of 303 servers
Intuit QuickBooks
51 tools · footprint 188
15 critical 10 high 17 med 9 low COSOGLBA+3 more
PayPal
33 tools · footprint 86
6 critical 7 high 9 med 11 low COSOGLBA+3 more
Stripe
26 tools · footprint 77
3 critical 7 high 10 med 6 low COSOPCI+2 more
Qonto
25 tools · footprint 76
15 high 9 med 1 low COSOGLBA+3 more
PostHog
36 tools · footprint 69
6 high 22 med 8 low
Supabase
32 tools · footprint 69
4 critical 4 high 8 med 16 low COSOSOX
Datadog
25 tools · footprint 68
1 critical 12 high 11 med 1 low
PostHog
25 tools · footprint 66
3 critical 12 high 10 med
Adobe Workfront
25 tools · footprint 65
2 critical 7 high 13 med 3 low
MailerLite
25 tools · footprint 63
1 critical 11 high 12 med 1 low
MongoDB
25 tools · footprint 63
2 critical 7 high 12 med 4 low
MotherDuck
21 tools · footprint 62
4 critical 5 high 9 med 3 low
Salesforce
32 tools · footprint 60
4 critical 2 high 9 med 17 low COSOSOX
Close
64 tools · footprint 59
5 high 22 med 37 low COSOSOX
Cloudflare
26 tools · footprint 58
3 critical 4 high 6 med 13 low
Webflow
23 tools · footprint 57
2 critical 5 high 10 med 6 low
‹ PrevPage 1 of 19Next ›
QontoDocs ↗
15 high 9 med 1 low · 25 tools · 7 SoD-flagged
regimes APPICCPACOSOGDPRGLBAISO_27001LGPDNIST_CSFPCIPIPEDAPIPLPOPIAPSD2SOC2SOXUK_GDPR

Tools needing tighter control (18 of 25)

qonto.create_membership high conf mediumOBO
Invites a new member into the banking organization and sends an activation email, expanding who can access company financial data and act within the org.
qonto.list_memberships high conf mediumhuman approval
Exposes the full member roster including role, birthdate, and nationality, a bulk read of employee personal data across the organization.
qonto.create_multi_transfer_request high conf mediumOBO
Bundles up to 400 SEPA transfers into a single approval batch, staging outbound payments that an approver later signs with strong customer authentication.
qonto.change_client_invoice_status high conf mediumOBO
Finalizes or cancels a client invoice; finalizing locks it against edits and recognizes it as issued revenue with audit-trail impact.
qonto.mark_client_invoice_as_paid high conf mediumOBO
Records a client invoice as paid and stamps the payment date, directly affecting accounts-receivable and revenue reconciliation.
qonto.create_credit_note high conf mediumOBO
Issues a credit note against an existing invoice, recording a partial or full refund that reduces recognized revenue.
qonto.change_supplier_invoice_status high conf mediumhuman approval
Marks a supplier invoice paid or rejects it, an accounts-payable control action a single actor can take without a second approver.
qonto.create_card high conf mediumOBO redact
Issues a new payment card of the selected level, creating a live spending instrument tied to the organization's funds.
qonto.change_card_status high conf mediumOBO redact
Locks, unlocks, or permanently terminates a card as lost, stolen, or closed, altering an active payment instrument's usability.
qonto.get_card_iframe_url high conf mediumhuman approval redact
Returns a short-lived URL that renders the card's full PAN, expiry, and CVV, exposing sensitive cardholder data as a credential.
qonto.update_client high conf mediumOBO
Patches a client's stored personal data, a single-record write to name, contact, and tax-identifier fields.
qonto.delete_client high conf mediumhuman approval
Permanently deletes a client and auto-cancels its recurring invoices, an irreversible single-actor erasure of personal data.
qonto.list_transactions high conf mediumhuman approval
Reads a paginated feed of a bank account's transactions, a bulk pull of sensitive banking activity.
qonto.list_statements high conf mediumhuman approval
Lists monthly account statements, each carrying a short-lived presigned URL to the downloadable bank statement file.
qonto.get_statement high conf mediumhuman approval
Fetches a bank statement whose presigned file URL is a credential granting direct download of the statement document.
qonto.create_payment_link medium conf mediumaudit redact
Creates a customer-facing payment link that collects card or bank payments into a Qonto account.
qonto.update_card medium conf mediumaudit redact
Changes a card's nickname or its ATM, NFC, online, and foreign-payment option flags, adjusting spending controls on a live card.
qonto.create_card_request medium conf mediumaudit redact
Creates a flash or virtual card request for the authenticated member, pending approval before a card is issued.
All other tools (7)
qonto.approve_request low conf mediumallow
Returns a link to the web approval page for a pending expense or transfer request without executing the approval itself.
qonto.create_client medium conf mediumaudit
Creates a client record holding personal data such as name, email, phone, and tax identification number.
qonto.create_client_invoice medium conf mediumaudit
Creates a draft client invoice tied to an existing client, seeding accounts-receivable and revenue records.
qonto.decline_request medium conf mediumaudit
Declines a pending expense or transfer request, moving it to declined so the underlying financial action never runs.
qonto.delete_client_invoice medium conf mediumaudit
Deletes a draft client invoice; only drafts are accepted, but removes a nascent financial record before it is issued.
qonto.get_attachment medium conf mediumaudit
Fetches a transaction attachment via a short-lived presigned URL, exposing receipts and invoices that may contain financial detail.
qonto.get_organization medium conf mediumaudit
Returns the organization's bank accounts including IBAN, BIC, and current balance, exposing sensitive banking identifiers.