Skip to main content
Glama
CSOAI-ORG

SOC2 Compliance AI MCP

Official

soc2-compliance-ai-mcp MCP-Server MCP-Registry PyPI

soc2-compliance-ai-mcp MCP-Server

PyPI Downloads GitHub stars License: MIT

SOC 2 Compliance MCP

Bewerten Sie KI/ML-Systeme anhand aller 5 Trust Service Criteria mit Lückenanalysen, Kontrollmatrizen und HMAC-signierten Attestierungen.

MEOK AI Labs

Installation · Tools · Preise · Attestierungs-API


Warum existiert dieses Projekt?

SOC 2 Typ II-Berichte sind das grundlegende Vertrauenssignal für jeden SaaS- oder KI-Anbieter, der an Unternehmen verkauft. KI-Systeme führen jedoch Kontrolllücken ein, die bei herkömmlichen SOC 2-Bewertungen übersehen werden: Modellherkunft, Governance von Trainingsdaten, Drift-Überwachung und Verpflichtungen zur Erklärbarkeit.

Die meisten Compliance-Teams fügen KI entweder manuell in bestehende SOC 2-Kontrollmatrizen ein oder zahlen über 40.000 $ für eine Beratung. Dieses MCP ordnet KI/ML-spezifische Risiken den 5 Trust Service Criteria (Sicherheit, Verfügbarkeit, Verarbeitungsintegrität, Vertraulichkeit, Datenschutz) zu, generiert Kontrollmatrizen gemäß der AICPA 2023-Richtlinien und erstellt Querverweise zu ISO 27001 für Organisationen, die beide Zertifizierungen halten.

Related MCP server: EU AI Act Compliance MCP

Installation

pip install soc2-compliance-ai-mcp

Tools

Tool

TSC-Referenz

Funktion

assess_trust_principles

CC1-CC9, A1, PI1, C1, P1

Vollständige Bewertung anhand aller 5 Trust Service Criteria

control_gap_analysis

CC6, CC7, CC8

Identifizierung fehlender oder schwacher Kontrollen für KI-Systeme

generate_control_matrix

Alle TSC

Erstellung einer Kontrollmatrix zur Zuordnung von KI-Risiken zu SOC 2-Kriterien

risk_assessment

CC3, CC4

AICPA-konforme Risikobewertung für KI/ML-Workloads

crosswalk_to_iso27001

Anhang A Mapping

Zuordnung von SOC 2-Kontrollen zu ISO 27001:2022 Anhang A

readiness_checklist

Typ I / Typ II

Checkliste für die Audit-Bereitschaft mit Prioritäten für die Nachbesserung

Beispiel

Prompt: "Assess our customer-facing LLM chatbot against SOC 2 Trust Service
Criteria. It processes financial data, stores conversation logs for 90 days,
and uses a third-party model API."

Result: Assessment across all 5 TSC with findings on third-party model API
vendor risk, missing drift monitoring, undocumented retention policy.
Each finding includes remediation steps and control references.

Preise

Stufe

Preis

Was Sie erhalten

Kostenlos

£0

10 Aufrufe/Tag — Bewertung der Vertrauensprinzipien + Lückenanalyse

Pro

£199/Monat

Unbegrenzt + HMAC-signierte Attestierungen + Verifizierungs-URLs

Enterprise

£1.499/Monat

Multi-Mandanten-fähig + Co-Branding-Berichte + Webhooks

Pro abonnieren · Enterprise

Attestierungs-API

Jedes Pro/Enterprise-Audit erstellt ein kryptografisch signiertes Zertifikat:

POST https://meok-attestation-api.vercel.app/sign
GET  https://meok-attestation-api.vercel.app/verify/{cert_id}

Zero-Dep-Verifizierer: pip install meok-attestation-verify

Lizenz

MIT

Install Server
A
license - permissive license
A
quality
B
maintenance

Maintenance

Maintainers
Response time
6wRelease cycle
2Releases (12mo)
Commit activity
Issues opened vs closed

Related MCP Servers

View all related MCP servers

Related MCP Connectors

  • MEOK MCP Hardening MCP — automated security red-team for any MCP server. Maps OWASP LLM Top 10

  • Agent Orchestrator MCP Server by MEOK AI Labs

  • MCP server teaching AI agents to implement TideCloak: auth, E2EE, IGA, security analysis

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/CSOAI-ORG/soc2-compliance-ai-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server