MCP server registry
Security & governancePublic source

Compliance MCP Server

Regulatory compliance engine for ADK-Rust Enterprise agents. Provides 27 MCP tools covering the full compliance lifecycle — frameworks, policies, controls, audits, findings, evidence collection, risk assessments, gap…

What it gives an agent

A purpose-built capability behind one MCP connection.

The server owns its domain logic and publishes a tool contract an MCP client can discover. ADK-Rust can load that contract into an agent, normalize each schema for the chosen model provider, and keep the connection lifecycle outside the agent’s business logic.

01

Framework-driven — map policies and controls to any regulatory framework

02

Audit lifecycle — plan, execute, find, remediate, close

03

Evidence-based — collect and link evidence to controls for audit readiness

04

Risk matrix — likelihood x impact scoring with auto-classification

05

Gap analysis — identify missing controls, untested controls, missing evidence

06

GDPR built-in — DSAR management with 30-day SLA tracking

07

Incident response — report, investigate, contain, resolve

Architecture

How Compliance MCP Server fits into an agent system.

The model never needs the implementation details or credentials of the system behind the server. It sees reviewed tool definitions. The MCP client handles discovery and calls, while the server keeps ownership of validation, policy, and communication with its domain system.

01

ADK-Rust agent

Chooses a capability from the reviewed tool catalog.

02

MCP client

Discovers schemas, sends calls, and receives typed content.

03

Compliance MCP Server

Validates the request and owns 27 documented tool contracts.

04

Domain system

Keeps the API, data, credentials, and business rules behind the server.

Connection: stdio · Server framework: rmcp

This repository does not currently publish a dedicated architecture SVG. The integration diagram above is generated from its documented transport and server boundary; use the official README for implementation-specific details.

Tool catalog

What can an agent ask Compliance MCP Server to do?

Each tool has a stable name, a human-readable purpose, and a JSON input contract discovered during MCP initialization. Risk classes come from the project’s registry manifest when one is available.

27 named tools

framework_create

Register framework (GDPR, SOX, HIPAA, ISO27001, PCI-DSS, SOC2, NIST, custom)

see documentation
framework_list

List all registered frameworks

see documentation
policy_create

Create policy (data protection, access control, incident response, etc)

see documentation
policy_list

List policies with review status

see documentation
control_create

Create control (preventive, detective, corrective) linked to policy

see documentation
control_list

List controls with testing status

see documentation
control_test

Mark control as tested

see documentation
audit_create

Create audit (internal, external, certification)

see documentation
audit_list

List audits with findings count

see documentation
finding_create

Record finding (critical, high, medium, low)

see documentation
finding_update

Update status (open, in_progress, remediated, accepted, closed)

see documentation
finding_list

List findings with open count

see documentation

Governance

Understand the effect of every tool.

A server connection inherits the authority of its credentials and deployment environment. The declarations below come from this project’s README and MCP registry manifest; your application still decides which tools an agent receives and where approval is required.

27 see documentation
  • Audit lifecycle — plan, execute, find, remediate, close
  • Evidence-based — collect and link evidence to controls for audit readiness
  • Incident response — report, investigate, contain, resolve

MCP surface

What the current documentation declares.

MCP can carry tools, resources, prompts, structured results, progress, cancellation, and long-running work. This record highlights the modern protocol features explicitly mentioned by this repository.

Completion
rmcp

Install and connect

Follow the project’s documented starting point.

Install the server in the environment that owns its credentials and domain access. Add it to your MCP host, verify the discovered tools, and narrow the toolset before giving it to a production agent.

Install
cargo install mcp-compliance
MCP client configuration
{
  "mcpServers": {
    "compliance": { "command": "mcp-compliance" }
  }
}

Commands and configuration are extracted from the public README. Confirm prerequisites, environment variables, and release-specific options in the official documentation before deployment.

Official documentation

Continue with the project maintainers’ source of truth.

This page provides an approachable map of the server. The repository remains authoritative for exact schemas, prerequisites, configuration, examples, tests, releases, and security updates.

Source record

Release and repository metadata for this catalog entry.

View public repository ↗
Version
1.0.0
License
Apache-2.0
Tools
27
Revision
71e62a746de7
Updated
May 27, 2026
Transportsstdio