bidda-mcp
Bidda Sovereign Intelligence MCP Server
10,000+ source-verified regulatory compliance nodes across 39 sovereign pillars. Built to reduce hallucination by grounding every node in primary legal sources.
Actively maintained. Last reviewed 2026-07-19 - 10,000+ nodes across 39 pillars, 25 MCP tools (server v1.6.0). Live counts always available via list_pillars() and GET https://bidda.com/mcp.
What is Bidda?
Bidda is a sovereign compliance intelligence registry. Every node traces to a primary legal source (avg 7 citations per node) and contains machine-executable deterministic logic, not summaries, not PDFs, not paraphrased commentary.
Pillars covered: EU AI Act · GDPR · NIST AI 600-1 · Basel III · HIPAA · DORA · FATF · SOC 2 · ISO 27001 · CCPA · PIPEDA · APRA CPS 234 · MiCA · POPIA · plus a MITRE layer across ATT&CK Enterprise/Mobile/ICS, D3FEND, ATLAS and CAPEC, and 150+ others across 39 compliance domains.
Related MCP server: Nexus Finance
MCP Endpoint
POST https://bidda.com/mcp
GET https://bidda.com/mcp (server info, open this in a browser to inspect)Transport: Streamable HTTP (MCP 2025-03-26). No API key required for the discovery tier.
Tools (25)
Free discovery and intelligence (no key required)
Tool | Description |
| List all 39 compliance pillars with live node counts |
| Search by keyword across 10,000+ nodes; returns title, ID, pillar, and BLUF (plain-language obligation) |
| Fetch a specific node by ID; returns summary plus link to machine-executable workflow |
| Walk the prerequisite chain for a node (1 to 4 hops). Plan a full compliance posture from one entry node. |
| Cross-framework mapping dimensions for a node (e.g. GDPR Art 17 to CCPA right-to-delete to POPIA Sec 24) |
| Regulatory change feed: most recently updated nodes, optional pillar filter |
| All nodes that apply in a specific jurisdiction (EU, US, UK, AU, SG, IN, CA, CN, ZA, JP, BR and others) |
| MITRE technique ID to Bidda node plus mapped NIST/ISO/PCI/HIPAA/NIS2/DORA controls. Across 6 frameworks. |
| Pre-flight runtime check. Describe an intended action in natural language; get ranked applicable regulations plus LOW/MODERATE/HIGH risk indicator. |
| Browse the registry by cross-cutting compliance topic (e.g. data breach notification, AI transparency) across every pillar and jurisdiction |
Subscriber tools (pass your Bidda key as api_key; a free trial counts)
Tool | Description |
| Compare how jurisdictions address a topic side by side, including where their numeric thresholds differ (e.g. a breach-notification deadline of 72 hours versus 30 days). Does not rank which is stricter. |
| Create a signed, time-stamped record of which rules a person or AI agent relied on for a decision, with a public verify URL |
| Signed record of which committed version of a rule was authoritative at a past date, anchored to the public history chain |
| Subscribe to email or webhook alerts when a watched rule or pillar's primary source changes |
| Open a run ledger for a whole task or conversation (for example a support-bot chat). Returns a run_id. |
| Append one tamper-evident entry to an open run: the rules consulted, the decision, and the user input as text or a private hash |
| Seal a run into one signed run receipt covering every entry, with a public verify URL anyone can check against Bidda's public key |
| Fetch a run and its entries; a sealed run is publicly readable and reports whether its signature is valid |
| Governed runs: fetch a full node and record a verified, hash-pinned entry in an open run in one call, so the sealed receipt proves exactly which version of the rule the agent read |
| Export a sealed run as one auditor-ready evidence pack: the signed receipt, the entry chain, and an independent integrity self-check |
| Check whether a cached compliance snapshot is still current: pass node ids (optionally with version or content hash) and get fresh, drifted, or withdrawn per node |
| Signed record mapping one of your internal controls to the Bidda obligations it addresses, with owner, framework, status, and a public verify URL. An audit trail, not a determination of compliance. |
| Walk the public dependency graph from the nodes you cover to surface prerequisite obligations you may be missing |
| Obligation-level feed of which primary sources changed or were withdrawn since a date, filterable by pillar or node |
| Export a sealed governed run as a NIST OSCAL assessment-results document for GRC tooling |
The discovery responses for every free tool are free. Full vault unlock (deterministic_workflow, actionable_schema, full primary_citations) costs $0.01 per node via Skyfire JWT or USDC on Base. The subscriber tools require an active Bidda subscription, which includes a free trial.
Quick Start: Claude.ai / Claude Desktop / Cursor / any MCP HTTP client
Point your MCP client at:
https://bidda.com/mcpThat is it: no install, no API key, no config file for the discovery tier. The full server-info manifest is available at GET https://bidda.com/mcp (open in a browser to inspect available tools).
Run it locally (Node or Docker)
This repo also ships a small local stdio MCP server (server.js) that implements the free discovery and intelligence tools by calling the public Bidda REST API - no API key required. Use it when you want the server running on your own machine or CI.
With Node (18+):
npm install
node server.jsWith Docker:
docker build -t bidda-mcp .
docker run -i --rm bidda-mcpClaude Desktop / Cursor config:
{
"mcpServers": {
"bidda": {
"command": "node",
"args": ["/absolute/path/to/bidda-mcp/server.js"]
}
}
}The local server exposes seven tools: list_pillars, search_nodes, get_node, get_dependency_chain, get_latest_changes, browse_topics, and check_action_compliance. The subscriber, vault, and attestation tools are available only on the hosted endpoint at https://bidda.com/mcp.
Example Queries
list_pillars()
search_nodes("GDPR data breach notification 72 hours")
search_nodes("Basel III capital requirements", pillar="Banking & Global Finance")
get_node("eu-ai-act-article-13-transparency")
get_dependency_chain("nist-csf-2-0-govern", max_depth=3)
get_crosswalk("gdpr-article-17-right-to-erasure")
get_jurisdiction_bundle("singapore", limit=25)
get_mitre_mapping("T1566") # ATT&CK Enterprise (phishing)
get_mitre_mapping("AML.T0020") # ATLAS (AI-specific)
check_action_compliance("process EU resident biometric data", jurisdiction="eu")
browse_topics("data breach notification")
compare_jurisdictions("data breach notification", api_key="YOUR_BIDDA_KEY")
create_attestation(agent="loan-bot-v2", nodes=["gdpr-article-22-automated-decisions"], api_key="YOUR_BIDDA_KEY")
open_run(agent="acme-support-bot", label="chat 8f21", api_key="YOUR_BIDDA_KEY")
record_run_entry(run_id="run_...", nodes=["gdpr-article-17-right-to-erasure"], note="User: delete my data", api_key="YOUR_BIDDA_KEY")
seal_run(run_id="run_...", api_key="YOUR_BIDDA_KEY")Coverage (live numbers via list_pillars())
Pillar | Approx. nodes |
Cybersecurity | ~1,900 |
Legal & IP Sovereignty | ~700 |
Banking & Global Finance | ~580 |
AI Governance & Law | ~570 |
Medical & Healthcare | ~325 |
Sustainability & ESG | ~285 |
Workplace | ~280 |
+ 32 more pillars | (call list_pillars) |
For exact live counts, call list_pillars(). The manifest at GET https://bidda.com/mcp returns the current totals dynamically.
Full coverage browser: bidda.com/intelligence
How Bidda reduces hallucination
Nodes are produced by Bidda's internal deterministic pipeline: source parsers and verification scripts do the heavy lifting, AI assists only in a small, tightly-gated drafting step, and every node passes multiple independent verification gates before publication. The whole design exists to keep drift to a minimum.
Every node has:
Primary legal citations: real instruments, real URLs, real section numbers (avg 7 per node)
Deterministic workflow: machine-executable steps, not prose summaries
Integrity hash: a cryptographic fingerprint of the node content
Source integrity watcher: regular TLS and content fingerprint checks against live regulator URLs, results published at
/api/v1/registry-health.jsonVerbatim mandate on amendments: every regulatory amendment is quote-justified against the source text before it can change a node
No inference without a regulatory anchor. No blog posts. No secondary commentary. No Wikipedia. Bidda is an information tool, not legal advice; review each rule and its primary source before relying on it.
CISA Secure by Design
Bidda has publicly attested to the CISA Secure by Design Pledge, the seven public goals the U.S. Cybersecurity and Infrastructure Security Agency asks software manufacturers to commit to. Additional Bidda and CISA mappings:
CISA CPG crosswalk: bidirectional mapping between Bidda compliance nodes and CISA's Cybersecurity Performance Goals: bidda.com/cisa/cpg-crosswalk
CISA Free Tools catalogue: no-cost capabilities Bidda offers federal, SLTT and critical-infrastructure defenders: bidda.com/cisa/free
Registry Health
GET https://bidda.com/api/v1/registry-health.jsonLive integrity-check results: source URL liveness, verification coverage percentage, regulatory change detection categories, with a public timestamp on the last sweep.
Links
Website: bidda.com
Developer docs: bidda.com/developers
Full node registry: bidda.com/intelligence
CISA programs: bidda.com/cisa
Verify a node: bidda.com/verify
Methodology: bidda.com/methodology
Contact: info@bidda.com
Maintenance
Tools
Latest Blog Posts
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Bidda-Ai/bidda-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server