Skip to main content
Glama
GJB65

compliance-intelligence

TheArtOfService Compliance Intelligence MCP Server

This repository contains the source of an MCP (Model Context Protocol) server implementation, under npm/. It speaks MCP over stdio to any MCP client and is published as @theartofservice/compliance-mcp.

Alongside it, python/ holds a LangChain toolkit for the same API. That one is not an MCP server, it is an SDK, and it is here because it targets the same graph.

The server exposes a compliance knowledge graph of 686 frameworks, 21,696+ controls and 300K+ cross-framework mappings, where a mapping records what one standard already evidences of another, along with the reasoning and the rejections.

The server implementation

what it is

source

published as

Node

MCP server, stdio

npm/src/index.js

@theartofservice/compliance-mcp

Python

LangChain toolkit, not MCP

python/src/theartofservice_compliance/

theartofservice-compliance

The Node implementation is built on the official @modelcontextprotocol/sdk, registering its tools through Server and serving them over StdioServerTransport.

Related MCP server: WhisperGraph

Tools

tool

what it answers

search_frameworks

find a standard by name or subject

get_framework

one framework in full, with its domains

get_framework_controls

the control set of a framework

search_controls

find controls by text across the graph

cross_framework_map

what standard A already evidences of standard B

coverage_report

how much of a target standard a source covers

Run it locally

npx -y @theartofservice/compliance-mcp

Tools list without a key, so any client can inspect the server. Calling one needs THEARTOFSERVICE_API_KEY. If you would rather not sign up for anything, the hosted endpoint below serves the same graph anonymously.

Claude Desktop, Claude Code, Cursor, Windsurf and any other MCP client can launch either one directly. Add to your client config:

{
  "mcpServers": {
    "compliance": {
      "command": "npx",
      "args": ["-y", "@theartofservice/compliance-mcp"]
    }
  }
}

Or use the hosted endpoint

If you would rather not run anything, the same server is hosted:

https://api.theartofservice.com/mcp

Streamable HTTP, anonymous access. It is listed in the official MCP registry as com.theartofservice/compliance-intelligence.

Counts

The figures above are read from the live graph. They move, so treat them as a floor rather than a fixed number, and read the current values from:

https://api.theartofservice.com/api/agent/stats

Licence

MIT. See LICENSE.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    Cross-repository code knowledge graph MCP server for Java, Kotlin, JavaScript, and TypeScript. Indexes source code into embedded KuzuDB via tree-sitter and exposes 30+ tools for call-flow tracing, multi-hop taint analysis (OWASP/CWE/PCI/STIG), entry-point reachability filtering, performance hotspot detection, and license compliance — without reading source files. 95% fewer tokens vs source-read
    33
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Self-hostable MCP server for WhisperGraph — a graph of 7.39B nodes / 39B edges mapping DNS, BGP, GeoIP, WHOIS, and threat intelligence. Six read-only tools (Cypher query + schema introspection + threat assessment), six resources, eight investigation prompts. stdio and Streamable HTTP transports.
    8
    61 npm
    1
    Apache 2.0
  • F
    license
    Not graded
    quality
    D
    maintenance
    Free hosted MCP server for EU compliance, enabling search across 8 frameworks, cross-framework mapping, policy generation, and gap assessment via natural language.
    -
  • A
    license
    Not graded
    quality
    A
    maintenance
    Offline MCP server that checks and scans your own AI prompts and outputs against a local compliance rule corpus. Returns rule ID, severity, citation, and remediation per finding — no API key, Apache 2.0.
    4
    Apache 2.0