eu-audit-mcp
eu-audit-mcp
Tamper-evident audit trail MCP server for EU AI Act and GDPR compliance. Designed to be integrated into a local desktop application via stdio transport.
Features
Tamper-evident logging — HMAC-SHA256 hash chain over all events
PII scanning — Automatic detection and redaction via Microsoft Presidio (EU patterns)
GDPR erasure — Article 17 right-to-erasure support with audit trail
Compliance checks — Technical checklist against EU AI Act Articles 12/19 and GDPR Article 30
Local-first — All data stays on your machine in a single SQLite file
Regulatory context
This server implements technical measures for the following EU regulations:
Regulation | Articles | What it requires |
EU AI Act (2024/1689) | Automatic recording of events (logs) for high-risk AI systems | |
Retention of automatically generated logs for at least 6 months | ||
GDPR (2016/679) | Right to erasure of personal data ("right to be forgotten") | |
Records of processing activities, including purposes and data categories |
The EU AI Act high-risk obligations enter into force on 2 August 2026.
See LEGAL_REFERENCES.md for the full article texts and a detailed mapping of how each tool addresses each requirement.
Disclaimer: This tool provides a technical checklist, not legal advice. Consult qualified legal counsel for compliance decisions.
Quick start
pip install -e ".[dev]"Run the server (stdio)
python -m eu_audit_mcp.serverMCP client configuration
{
"mcpServers": {
"eu-audit": {
"command": "python",
"args": ["-m", "eu_audit_mcp.server"],
"env": {
"AUDIT_CONFIG": "./audit_config.yaml"
}
}
}
}Run tests
pytest tests/MCP Tools
Tool | Description |
| Record an audit event with automatic PII scanning |
| Log an LLM inference call (model, tokens, cost) |
| Log a document/data access event |
| Search events by time range, type, session |
| Full ordered trace of a session |
| Summary statistics over a time period |
| Check against EU AI Act Art. 12/19 and GDPR Art. 30 |
| GDPR Article 17 right-to-erasure |
| Summary of detected PII types (counts only) |
| Verify hash chain integrity |
Configuration
Copy the example config and customize:
cp audit_config.example.yaml audit_config.yamlSet the AUDIT_CONFIG environment variable to point to your config file. Do not commit audit_config.yaml if it contains a chain_secret — it is in .gitignore by default.
Security
See SECURITY.md for the threat model, security measures, and vulnerability reporting.
License
Apache-2.0
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jellewas/eu-audit-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server