Skip to main content
Glama
CSOAI-ORG

DORA Compliance MCP

README.md
<!-- mcp-name: io.github.CSOAI-ORG/dora-compliance-mcp -->

> ### ๐Ÿ” Free tier: 50 calls/day. Need audit-ready proof?
> **Pro (ยฃ199/mo)** turns every result into an **HMAC-signed attestation** with a **public verify URL**
> your auditor validates without an account โ€” EU AI Act Art 11/12 ready.
> โ†’ Start: **https://proofof.ai**  ยท  `pip install meok-attestation-verify` to verify any cert.

[![MCP Scorecard: 90/100](https://img.shields.io/badge/proofof.ai-90%2F100-5b21b6)](https://proofof.ai/scorecard/dora-compliance-mcp.html)

# Dora Compliance MCP

[![MEOK AI Labs](https://img.shields.io/badge/MEOK-AI%20Labs-667eea)](https://meok.ai)
[![PAYG enabled](https://img.shields.io/badge/PAYG-%C2%A30.05%2Fcall-7c3aed?logo=stripe&logoColor=white&labelColor=1a1a2e)](https://councilof.ai/payg)
[![EU AI Act](https://img.shields.io/badge/EU%20AI%20Act-Compliant-22c55e)](https://councilof.ai)
[![License](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)
[![PyPI](https://img.shields.io/badge/PyPI-Install-3775a9)](https://pypi.org/project/dora_compliance_mcp/)

> DORA (Regulation EU 2022/2554) compliance MCP for financial entities

DORA (Regulation EU 2022/2554) compliance MCP for financial entities. ICT risk, incident classification, reporting workflows. MIT

---

## ๐Ÿš€ Quick Start

```bash
# Install via pip
pip install dora_compliance_mcp

# Or install via Smithery
npx -y @smithery/cli@latest install dora-compliance-mcp --client claude
```

## โšก Pay-per-call (PAYG) โ€” no subscription

This MCP supports universal pay-per-call billing across the MEOK compliance fleet:

```bash
# One-time setup
export MEOK_PAYG_KEY="your_topup_token"

# Every tool call now deducts ยฃ0.05 from your balance.
# When balance hits zero, the tool returns a top-up URL.
# Works across all 7 MEOK compliance MCPs with the same token.
```

- **No subscription** โ€” top up once, deduct per call.
- **ยฃ0.05/call default** (configurable via `MEOK_PAYG_RATE_GBP`).
- **USDC on Base L2 accepted** โ€” set `MEOK_X402_RECEIVER` and pay via stablecoin.
- **Backward-compatible** โ€” when `MEOK_PAYG_KEY` is unset, behaviour is unchanged.

**Get a token**: [councilof.ai/payg](https://councilof.ai/payg) (ยฃ10 / ยฃ50 / ยฃ200 top-up tiers).


## โœจ Features

- MCP protocol compliant
- Easy installation
- Well-documented API
- Production-ready
- Active maintenance

## ๐Ÿ“– Documentation

- [Full Documentation](https://docs.meok.ai/dora-compliance-mcp)
- [API Reference](https://meok-attestation-api.vercel.app)
- [EU AI Act Compliance Guide](https://councilof.ai)

## ๐Ÿ›ก๏ธ Compliance

This MCP server is built with **EU AI Act compliance** built-in:

- โœ… Article 9 โ€” Risk Management System
- โœ… Article 13 โ€” Transparency & Instructions for Use
- โœ… Article 15 โ€” Bias Detection & Testing
- โœ… Article 26 โ€” FRIA Support (where applicable)
- โœ… Article 50 โ€” AI Content Watermarking (where applicable)

Need help getting compliant? **[Book a free 15-min diagnostic โ†’](mailto:nicholas@meok.ai?subject=Compliance%20diagnostic)**

## ๐Ÿข Enterprise

Need custom development, SLA guarantees, or white-label deployment?

- **Pro:** ยฃ79/mo โ€” Full MCP suite + EU AI Act tracking
- **Enterprise:** ยฃ499/mo โ€” Custom dev + SLA + Dedicated support

[View Pricing โ†’](https://councilof.ai/payg) | [Contact Sales โ†’](mailto:sales@meok.ai)

## ๐Ÿค Part of the MEOK Ecosystem

This server is part of the **[MEOK AI Labs](https://meok.ai)** ecosystem โ€” 26 PyPI packages ยท ~16,300 monthly installs.

| Domain | Purpose |
|--------|---------|
| [councilof.ai](https://councilof.ai) | EU AI Act compliance marketplace |
| [safetyof.ai](https://safetyof.ai) | AI safety & monitoring |
| [meok.ai](https://meok.ai) | Sovereign AI platform |
| [cobolbridge.ai](https://cobolbridge.ai) | Legacy modernization |

## ๐Ÿ“œ License

MIT ยฉ [CSOAI-ORG](https://github.com/CSOAI-ORG)

---

<p align="center">
  <sub>Built with ๐Ÿ’œ by <a href="https://meok.ai">MEOK AI Labs</a> ยท UK Companies House 16939677</sub>
</p>


## Configuration

Add to your `claude_desktop_config.json` (Claude Desktop) or your MCP client config:

```json
{
  "mcpServers": {
    "dora-compliance-mcp": {
      "command": "uvx",
      "args": ["dora-compliance-mcp"]
    }
  }
}
```

Or: `pip install dora-compliance-mcp` then run the `dora-compliance-mcp` command (stdio transport).

## Examples

Once configured, ask your assistant, for example:
- "Use `classify_entity` to โ€ฆ"
- "Use `list_pillars` to โ€ฆ"
- "Use `audit_pillar` to โ€ฆ"

TDQS

A4.2/5.0

Scored across 9 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: auditing all or specific pillars, classifying entities or incidents, checking enforcement status, generating certificates, listing pillars, providing template, and TLPT readiness. No two tools overlap in functionality.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern in snake_case (e.g., audit_pillar, classify_incident, list_pillars). Naming is predictable and immediately conveys the action and target.

Tool Count5/5

9 tools is well-scoped for a DORA compliance server. Each tool earns its place, covering auditing, classification, status, certificate, and documentation needs without bloat or deficiency.

Completeness4/5

The tool set covers the core DORA compliance workflow: entity classification, pillar audits, incident classification, enforcement status, certificate generation, and templates. Minor gaps exist (e.g., no tool for tracking remediation or generating full reports), but the surface is largely complete for assessment and documentation.

Maintenance

ActivityMaintained
ResponsivenessSlow