Back to Browse

Soc2 Compliance Ai MCP Server

SecurityUse Caution2.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

SOC 2 Type II compliance for trust services criteria (security, availability, processing

About

SOC 2 Type II compliance for trust services criteria (security, availability, processing

Security Report

2.2
Use Caution2.2Critical Risk

This SOC 2 compliance MCP server has multiple security concerns that prevent a higher score. The most critical issue is the unvalidated network call to an external metering/verification endpoint (proofof.ai/verify) that exfiltrates API keys and user data in POST requests without explicit user consent or documented data handling. Additional concerns include weak authentication implementation with environment variable fallback, inadequate error handling, and excessive permissions (network_http, env_vars) that exceed typical SOC 2 assessment tool scope. The code quality issues and missing input validation further reduce confidence. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity). Package verification found 1 issue.

4 files analyzed · 15 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-csoai-org-soc2-compliance-ai-mcp": {
      "args": [
        "-y",
        "soc2-compliance-ai-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

MCP Scorecard: 86/100

Soc2 Compliance Ai MCP

⚖️ Built by MEOK AI Labs / CSOAI. Need this applied to your system fast? Book a 30-min Founder Office Hour (£29) → https://meok.ai/work · Full governance platform → https://meok.ai

MEOK AI Labs EU AI Act License PyPI

SOC 2 Type II compliance MCP — Trust Service Criteria audit, access review, change management, co... mcp-name: io.github.CSOAI-ORG/soc2-compliance-ai-mcp

SOC 2 Compliance MCP

SOC 2 Trust Service Criteria — Security, Availability, Processing Integrity, Confidentiality, Privacy

MCP License

SOC 2 Type II compliance MCP — Trust Service Criteria audit, access review, change management, control evidence automation.


🚀 Quick Start

# Install via pip
pip install soc2_compliance_ai_mcp

# Or install via Smithery
npx -y @smithery/cli@latest install soc2-compliance-ai-mcp --client claude

✨ Features

  • MCP protocol compliant
  • Easy installation
  • Well-documented API
  • Production-ready
  • Active maintenance

📖 Documentation

🛡️ Compliance

This MCP server is built with EU AI Act compliance built-in:

  • ✅ Article 9 — Risk Management System
  • ✅ Article 13 — Transparency & Instructions for Use
  • ✅ Article 15 — Bias Detection & Testing
  • ✅ Article 26 — FRIA Support (where applicable)
  • ✅ Article 50 — AI Content Watermarking (where applicable)

Need help getting compliant? Book a free 15-min diagnostic →

🏢 Enterprise

Need custom development, SLA guarantees, or white-label deployment?

  • Pro: $99/mo — Full MCP suite + EU AI Act tracking
  • Enterprise: $499/mo — Custom dev + SLA + Dedicated support

View Pricing → | Contact Sales →

🤝 Part of the MEOK Ecosystem

This server is part of the MEOK AI Labs ecosystem — 300+ MCP servers for sovereign AI governance.

DomainPurpose
councilof.aiEU AI Act compliance marketplace
safetyof.aiAI safety & monitoring
meok.aiSovereign AI platform
cobolbridge.aiLegacy modernization

📜 License

MIT © CSOAI-ORG


Tools

ToolDescriptionParameters
assess_trust_principlesAssess controls against all 5 TSC principlesprinciple, controls
control_gap_analysisIdentify gaps between existing controls and SOC 2current_controls, principle
generate_control_matrixGenerate a SOC 2 control matrixprinciple, controls, evidence
audit_readinessOverall SOC 2 audit readiness scoreall_controls, principles
evidence_checklistGenerate evidence checklist by principleprinciple (str, required)
remediation_planPrioritized remediation plan for gapsfindings, timeline

Installation

pip install mcp

Claude Desktop / Cursor / VS Code / Windsurf

{
  "mcpServers": {
    "soc2-compliance": {
      "command": "python",
      "args": ["path/to/server.py"]
    }
  }
}

Usage Examples

Assess security principle

{
  "principle": "security",
  "controls": ["firewall", "encryption", "access control", "no monitoring"]
}

Generate control matrix

{
  "principle": "availability",
  "controls": ["redundant servers", "backup power", "DR plan"],
  "evidence": ["uptime reports", "DR test results"]
}

Pricing

  • Free: 10 assessments/day
  • Pro: $99/mo — unlimited assessments + matrices
  • Enterprise: $499/mo — full audit trail + readiness scoring

Built by MEOK AI Labs | meok.ai

💸 Try MEOK in 30 seconds — instant buy ladder

TierPriceWhat you getStripe
Smoke test£1Signed sample MCP-Hardening report + Article 50 PDFhttps://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j
Quick Kit£9EU AI Act Article 50 implementation guide (C2PA + EU-Icon)https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j
Founder Call£2930-min 1-on-1 with the founderhttps://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j

Refundable. UK Stripe — VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.

Reviews

No reviews yet

Be the first to review this server!

Soc2 Compliance Ai MCP Server - SOC 2 Type II compliance for trust services criteria | MCP Marketplace