Back to Browse

Eu Audit MCP Server

Developer ToolsUse Caution1.5MCP RegistryLocal
Free

Server data from the Official MCP Registry

Tamper-evident audit trail MCP server for EU AI Act & GDPR compliance.

About

Tamper-evident audit trail MCP server for EU AI Act & GDPR compliance.

Security Report

1.5
Use Caution1.5Critical Risk

Valid MCP server (1 strong, 4 medium validity signals). 8 known CVEs in dependencies (1 critical, 6 high severity) Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

12 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

What You'll Need

Set these up before or after installing:

Path to the YAML configuration fileOptional

Environment variable: AUDIT_CONFIG

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-jellewas-eu-audit-mcp": {
      "env": {
        "AUDIT_CONFIG": "your-audit-config-here"
      },
      "args": [
        "eu-audit-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

eu-audit-mcp

Tamper-evident audit trail MCP server for EU AI Act and GDPR compliance. Designed to be integrated into a local desktop application via stdio transport.

Features

  • Tamper-evident logging — HMAC-SHA256 hash chain over all events
  • PII scanning — Automatic detection and redaction via Microsoft Presidio (EU patterns)
  • GDPR erasure — Article 17 right-to-erasure support with audit trail
  • Compliance checks — Technical checklist against EU AI Act Articles 12/19 and GDPR Article 30
  • Local-first — All data stays on your machine in a single SQLite file

Regulatory context

This server implements technical measures for the following EU regulations:

RegulationArticlesWhat it requires
EU AI Act (2024/1689)Art. 12Automatic recording of events (logs) for high-risk AI systems
Art. 19Retention of automatically generated logs for at least 6 months
GDPR (2016/679)Art. 17Right to erasure of personal data ("right to be forgotten")
Art. 30Records of processing activities, including purposes and data categories

The EU AI Act high-risk obligations enter into force on 2 August 2026.

See LEGAL_REFERENCES.md for the full article texts and a detailed mapping of how each tool addresses each requirement.

Disclaimer: This tool provides a technical checklist, not legal advice. Consult qualified legal counsel for compliance decisions.

Quick start

pip install -e ".[dev]"

Run the server (stdio)

python -m eu_audit_mcp.server

MCP client configuration

{
  "mcpServers": {
    "eu-audit": {
      "command": "python",
      "args": ["-m", "eu_audit_mcp.server"],
      "env": {
        "AUDIT_CONFIG": "./audit_config.yaml"
      }
    }
  }
}

Run tests

pytest tests/

MCP Tools

ToolDescription
log_eventRecord an audit event with automatic PII scanning
log_inferenceLog an LLM inference call (model, tokens, cost)
log_data_accessLog a document/data access event
query_logSearch events by time range, type, session
get_session_traceFull ordered trace of a session
get_statsSummary statistics over a time period
compliance_checkCheck against EU AI Act Art. 12/19 and GDPR Art. 30
execute_erasureGDPR Article 17 right-to-erasure
get_pii_summarySummary of detected PII types (counts only)
verify_chainVerify hash chain integrity

Configuration

Copy the example config and customize:

cp audit_config.example.yaml audit_config.yaml

Set the AUDIT_CONFIG environment variable to point to your config file. Do not commit audit_config.yaml if it contains a chain_secret — it is in .gitignore by default.

Security

See SECURITY.md for the threat model, security measures, and vulnerability reporting.

License

Apache-2.0

Reviews

No reviews yet

Be the first to review this server!