PQC-Khepra-MCP
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@PQC-Khepra-MCPRun compliance scan on my server and generate a Godfather Report"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
PQC-Khepra-MCP
Post-Quantum Cryptographic & Autonomous Flight Recording Kernel for AI Agents.
Air-gappable. Zero cloud telemetry. Zero token overhead.
Provides FIPS 203 (ML-KEM-768) and FIPS 204 (ML-DSA-65) post-quantum cryptographic signatures on every tool call, autonomous client-side NDJSON flight recording, and local host/asset discovery. Completely free and open-source under Apache 2.0.
Patent Reference: U.S. Prov. App. No. 63/942,886 (KHEPRA Protocol & Post-Quantum Evidence Weave)
Corporate Identity: SecRed Knowledge Inc. (operating as NouchiX) — Delaware C-Corp (EIN 99-0529252), SDVOSB (Active Self-Certified / SBA VetCert in review), Active Secret Clearance.
Live hosted endpoint:https://mcp.souhimbou.ai/sse— zero install, connect in 30 seconds.
Self-host for sovereign/air-gap: Docker or binary.
Architecture: Free Community Kernel vs. KTOS Commercial Platform
To ensure clean commercial boundaries for partners, defense contractors, and developers, the KHEPRA ecosystem operates across two distinct layers:
Layer | Product | License | Scope & Capabilities |
Layer 1 | PQC-Khepra-MCP (This Repo) | Apache 2.0 (Open Source) | Free Community Kernel: ML-DSA-65 / ML-KEM-768 PQC cryptographic signing, client-side autonomous flight logging, agent registration, local host/asset enumeration, and threat lookup. Zero STIG or compliance databases. |
Layer 2 | KHEPRA Trust OS (KTOS) | Commercial ($499/mo to $250K/yr) | Sovereign Proof-and-Actuation OS: 36,195 cross-framework compliance mappings, live DISA STIGViewer API v2 batch crosswalks, CMMC Level 2/3 assessments, ERT multi-package engines, automated C3PAO evidence packages (OSCAL, DISA CKLB, signed POA&Ms), and bounded autonomous host remediation. |
Related MCP server: swt3-mcp
Tiers & Gating (The 4-Tier Commercial & Sovereign Model)
Tier | Price Point | Quota | Gated Tools & Capabilities | Focus |
Community | $0 / Free (Open-Core) | 500 Credits | 14 Core Tools ( | Open-source PQC signing, flight logging, local discovery |
Platform | $499 / mo (Self-Serve) | 3,000 Credits | 50+ Tools (+ OmniScan multi-lane sweep, Shadow AI discovery, live STIGViewer API v2, OCSF SIEM stream) | Engineering teams & commercial SOC operations |
Enterprise | $2,999 / mo | 15,000 Credits | 85+ Tools (+ Full Agentic SOC, SEKHEM L7 PQC-WAF, PTY Enclave Supervisor, ASAF Remediation Daemon, Z3 SMT proofs) | Enterprise agent fleets & compliance automation |
Sovereign | $45K – $250K / yr | 100,000+ Credits | All 100 Tools (+ Bare-metal air-gap, osquery Fleet Manager, CMMC L2/L3 autopilot, Tactical RF anti-jamming, Windows EventLog telemetry) | Defense contractors, C3PAOs, federal primes & GovCloud |
What It Does (Free Community Kernel)
PQC-Khepra-MCP connects your AI assistant (Claude Code, Cursor, Antigravity, Cline) directly to a post-quantum cryptographic security layer:
ML-DSA-65 / ML-KEM-768 Signing: FIPS 203/204 post-quantum signing on every tool call and DAG attestation.
Autonomous Flight Recording: Automatically logs all agent tool invocations, inputs, and outcomes to tamper-evident NDJSON hash chains.
Local Host & Asset Discovery: Enumerate system runtimes, network interfaces, and environment properties locally.
Air-Gap & Sovereign Operation: Runs 100% offline with zero cloud telemetry or egress calls.
Permissive Apache 2.0 License: Safe for commercial embed, partner integrations, and enterprise deployment.
Quickstart — Hosted Endpoint (Zero Install)
The fastest path to a live compliance tool in your AI client. No Docker, no binary, no build:
{
"mcpServers": {
"khepra": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://mcp.souhimbou.ai/sse"]
}
}
}Or if your client supports native SSE transport:
https://mcp.souhimbou.ai/sseHealth check: https://mcp.souhimbou.ai/mcp/v1/health
Data note: The hosted endpoint runs in
edgemode — DAG is in-memory and ephemeral. For persistent, signed audit trails and air-gap deployment, use the self-hosted options below.
Self-Hosted Installation
For sovereign/air-gap deployment: Docker (recommended, no build required) or compiled binary (fastest startup, SCIF-ready). Both support the same environment variables and all MCP clients.
Choose your path:
Method | Best For | Startup |
Fastest start, cloud tools | Instant | |
Most users, easiest self-host | ~2s | |
Air-gap, SCIF, performance | ~300ms |
Option A: Docker (Recommended)
Requires Docker Desktop or Docker Engine. The image is pre-built and ships the full compliance database — no additional downloads in sovereign mode.
# Pull once
docker pull ghcr.io/nouchix/pqc-khepra-mcp:latest
# Test it (should print the initialize response and exit)
echo '{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}},"id":0}' \
| docker run --rm -i -e KHEPRA_MODE=sovereign ghcr.io/nouchix/pqc-khepra-mcp:latestOption B: Compiled Binary
Requires Go 1.21+ for building, or download a pre-built release from GitHub Releases.
git clone https://github.com/nouchix/PQC-Khepra-MCP.git
cd PQC-Khepra-MCP
# Build (cross-compile for your OS)
go build -o khepra-mcp ./cmd/khepra-mcp # Linux / macOS
go build -o khepra-mcp.exe ./cmd/khepra-mcp # Windows
# Test the binary
echo '{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}},"id":0}' \
| KHEPRA_MODE=sovereign ./khepra-mcpWindows — using the batch launcher
The repo ships a run-mcp.bat launcher for Windows. It uses the pre-built binary (fast path) and falls back to go run automatically:
:: run-mcp.bat is already in the repo at the root of PQC-Khepra-MCP
:: Point your MCP client to: cmd /c C:\path\to\PQC-Khepra-MCP\run-mcp.batAdding to Your AI Client
Claude Desktop
Config file location:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.jsonLinux:
~/.config/Claude/claude_desktop_config.json
Community tier — Docker (macOS / Linux)
{
"mcpServers": {
"khepra": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "KHEPRA_MODE=sovereign",
"-v", "/var/lib/khepra:/var/lib/khepra",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
]
}
}
}Community tier — Docker (Windows)
{
"mcpServers": {
"khepra": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "KHEPRA_MODE=sovereign",
"-v", "C:\\Users\\YourName\\.khepra:/var/lib/khepra",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
]
}
}
}Community tier — Binary (Windows, fastest startup)
{
"mcpServers": {
"khepra": {
"command": "C:\\path\\to\\PQC-Khepra-MCP\\khepra-mcp.exe",
"args": [],
"env": {
"KHEPRA_MODE": "sovereign",
"KHEPRA_NETWORK_POLICY": "lan",
"MCP_PQC_ENABLED": "true",
"KHEPRA_MANIFEST_PATH": "C:\\path\\to\\PQC-Khepra-MCP\\manifest.json"
}
}
}
}Community tier — Binary via batch launcher (Windows)
{
"mcpServers": {
"khepra": {
"command": "cmd",
"args": ["/c", "C:\\path\\to\\PQC-Khepra-MCP\\run-mcp.bat"],
"env": {
"KHEPRA_MODE": "sovereign",
"KHEPRA_NETWORK_POLICY": "lan",
"MCP_PQC_ENABLED": "true"
}
}
}
}Pro / Enterprise / Sovereign tier (with license key)
{
"mcpServers": {
"khepra": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "KHEPRA_LICENSE_KEY",
"-e", "KHEPRA_MODE=sovereign",
"-v", "/var/lib/khepra:/var/lib/khepra",
"-v", "/var/log/khepra:/var/log/khepra",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
],
"env": {
"KHEPRA_LICENSE_KEY": "YOUR_LICENSE_KEY_HERE"
}
}
}
}After editing, restart Claude Desktop. Verify in Settings → Developer — you should see khepra with status running and all tools listed.
Cursor
Config file: .cursor/mcp.json in your project root, or ~/.cursor/mcp.json globally.
Docker (macOS / Linux)
{
"servers": {
"khepra": {
"type": "stdio",
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "KHEPRA_MODE=sovereign",
"-v", "/var/lib/khepra:/var/lib/khepra",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
]
}
}
}Binary (macOS / Linux)
{
"servers": {
"khepra": {
"type": "stdio",
"command": "/path/to/khepra-mcp",
"args": [],
"env": {
"KHEPRA_MODE": "sovereign",
"KHEPRA_MANIFEST_PATH": "/path/to/PQC-Khepra-MCP/manifest.json"
}
}
}
}Binary (Windows)
{
"servers": {
"khepra": {
"type": "stdio",
"command": "C:\\path\\to\\PQC-Khepra-MCP\\khepra-mcp.exe",
"args": [],
"env": {
"KHEPRA_MODE": "sovereign",
"KHEPRA_MANIFEST_PATH": "C:\\path\\to\\PQC-Khepra-MCP\\manifest.json"
}
}
}
}VS Code (with GitHub Copilot or Cline extension)
Config file: .vscode/mcp.json in your project, or user settings.
{
"servers": {
"khepra": {
"type": "stdio",
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "KHEPRA_MODE=sovereign",
"-v", "${env:HOME}/.khepra:/var/lib/khepra",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
]
}
}
}Or via user settings.json for the Cline extension:
{
"cline.mcpServers": {
"khepra": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "KHEPRA_MODE=sovereign",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
]
}
}
}Windsurf
Config file: ~/.codeium/windsurf/mcp_config.json
{
"mcpServers": {
"khepra": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "KHEPRA_MODE=sovereign",
"-v", "/var/lib/khepra:/var/lib/khepra",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
]
}
}
}Continue.dev
Config file: ~/.continue/config.json — add to the experimental.modelContextProtocolServers array:
{
"experimental": {
"modelContextProtocolServers": [
{
"name": "khepra",
"transport": {
"type": "stdio",
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "KHEPRA_MODE=sovereign",
"ghcr.io/nouchix/pqc-khepra-mcp:latest"
]
}
}
]
}
}Cloud / SaaS AI Tools (Claude.ai, ChatGPT, Gemini, etc.)
Use the live hosted endpoint at mcp.souhimbou.ai — no setup required:
Option 1 — Live hosted endpoint (recommended, zero setup)
{
"mcpServers": {
"khepra": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://mcp.souhimbou.ai/sse"]
}
}
}Or direct SSE URL for tools that accept it:
https://mcp.souhimbou.ai/sseCloud Tool | Where to add MCP URL |
Claude.ai (Pro/Team) | Settings → Integrations → MCP Servers |
Cursor |
|
OpenAI Assistants | API |
Glama.ai | Workspace → MCP Servers |
Smithery.ai | Catalog → Self-hosted server |
Option 2 — mcp-remote proxy (local binary behind the bridge)
If you need sovereign mode (zero egress) proxied to a cloud tool:
# Install once
npm install -g mcp-remote
# Bridge your local sovereign instance
KHEPRA_MODE=sovereign mcp-remote \
--server "docker run --rm -i -e KHEPRA_MODE=sovereign ghcr.io/nouchix/pqc-khepra-mcp:latest" \
--port 3000
# Point cloud tool to:
# http://localhost:3000/sseSecurity note: In
sovereign/ironbankmode, KHEPRA makes zero egress calls — only the bridge connection to the cloud tool carries data.
Option 3 — Smithery / MCP Registries (Community tier)
KHEPRA is listed across all major MCP discovery platforms. Cloud tools that support registry-based discovery can install it directly:
Registry | URL |
Smithery.ai | |
MCP Registry (official) | |
mcpservers.org | |
Cline Marketplace | |
Live Hosted Endpoint |
Registry ID: io.github.nouchix/pqc-khepra-mcpValidation — Test Your Installation
Run this from your terminal to verify the server responds correctly:
# Docker
echo '{"jsonrpc":"2.0","method":"tools/list","params":{},"id":1}' \
| docker run --rm -i -e KHEPRA_MODE=sovereign ghcr.io/nouchix/pqc-khepra-mcp:latest
# Binary (Linux / macOS)
echo '{"jsonrpc":"2.0","method":"tools/list","params":{},"id":1}' \
| KHEPRA_MODE=sovereign ./khepra-mcp
# Binary (Windows PowerShell)
'{"jsonrpc":"2.0","method":"tools/list","params":{},"id":1}' \
| & ".\khepra-mcp.exe"Expected output: a JSON-RPC response listing all available tools. If you see "tools": [...] with 12+ entries — you're connected.
Full protocol validation (Windows)
# Runs the complete Claude Desktop handshake sequence and validates all responses
.\scripts\test-mcp-handshake.ps1 -BinaryPath ".\khepra-mcp.exe"
# Expected output:
# [PASS] initialize | protocolVersion=2025-11-25 | listChanged=False
# [PASS] tools/list | count=34
# TRL-10 READY - Server passes full Claude Desktop protocol validationMCP Tools
Community Tier (Free — No License Key)
pqc_stig — World's First DoD PQC STIG ⭐
Assesses a source code directory against PQC-01-STIG-V1R1: 12 controls covering CNSA 2.0 algorithm approval, ML-DSA-65 key strength, ML-KEM-768 encapsulation, hybrid cryptography, key storage, constant-time implementation, and certificate chain requirements.
pqc_stig(scan_path?: string, profile?: "quick" | "full" | "executive")Example: "Run pqc_stig on my project and tell me if I'm CNSA 2.0 compliant"
nist_map
Map CCI identifiers or STIG findings to NIST 800-53 Rev 5 controls.
khepra_query_stig
Query the 36,195-row STIG/CCI/NIST/CMMC compliance database by control ID.
dark_crypto_contribute (opt-in)
Contribute anonymized cryptographic algorithm telemetry to the SouHimBou AI Dark Crypto Intelligence Network. No PII. Opt-in only — never fires without explicit invocation.
Pro / Enterprise / Sovereign Tier
ert_scan
Enterprise Risk & Threat scan across STIG, NIST 800-53, NIST 800-171, CMMC, and FedRAMP. Returns Godfather Report with dollar-denominated business impact.
ert_scan(target: string, frameworks?: string[], output_format?: "godfather" | "json" | "csv")Example: "Run ert_scan on /etc and generate a Godfather Report"
stig_check
Automated RHEL-09-STIG-V1R3 compliance scan against a live system or configuration path.
cmmc_assess
Full CMMC Level 1, 2, or 3 assessment with gap analysis and POA&M generation.
godfather_report
Generate an executive Godfather Report from prior scan results: top 10 findings ranked by dollar exposure, remediation ROI, and FAIR model business impact.
+ 20 additional tools
agent_record, dag_attestation, flight_export, khepra_get_dag_chain, nhi_inventory, acp_status, owasp_agent_assess, khepra_export_attestation, khepra_export_poam, khepra_get_compliance_score, ert_crypto, ert_readiness, stig_benchmark, ir_analysis, vuln_hunter, sbom_generate, threat_model, khepra_query_threat_intel, discover_assets, and more.
The Godfather Report
Unlike compliance scanners that output a wall of CVEs, KHEPRA translates findings into the language executives care about:
Finding: RHEL-09-212030 — No FIPS-validated crypto on /etc/ssh
Severity: CAT I (HIGH)
Business Impact: $2.4M estimated breach exposure (FAIR model)
Remediation Cost: $800 (4 hours engineer time)
ROI: 3,000xEvery finding includes control ID, framework mapping, business impact in dollars, remediation cost estimate, and ROI.
Deployment Modes
Mode | Air-Gap | Egress | Telemetry | Use Case |
| ✅ Yes | Zero | Zero | On-prem, SCIF, classified (DEFAULT) |
| ✅ Yes | Zero | Zero | DoD/IC production, FIPS-only |
| ❌ No | LAN | Zero | Edge + cloud coordination |
| ❌ No | Unrestricted | Zero | Fully stateless SaaS |
Set via KHEPRA_MODE environment variable. Unknown values are rejected at startup and fall back to sovereign (fail-closed).
Environment Variables
Variable | Required | Default | Description |
| Pro/Enterprise/Sovereign only | — | License key. Community tier runs without one. Get at nouchix.com |
| No |
| Deployment mode: |
| No |
| Path to signed tool manifest file |
| No |
| Data and compliance DB directory |
| No |
| Log directory |
| No |
| DAG audit chain storage path |
| No |
| Signed audit log path |
| No |
| Max concurrent tool calls per agent |
| No |
| Network scope: |
| No |
| Enable ML-DSA-65 PQC attestation on all responses |
Air-Gap & SCIF Deployment
KHEPRA makes zero external network calls in sovereign and ironbank modes:
License validated offline via ML-DSA-65 signed
license.adinkheprafileCompliance databases (36,195 mappings) bundled in container — no external downloads
No telemetry, no heartbeat, no egress — verified at the transport layer
# Transfer image to air-gapped network
docker save ghcr.io/nouchix/pqc-khepra-mcp:latest | gzip > khepra-mcp.tar.gz
# On air-gapped host:
docker load < khepra-mcp.tar.gzNote on telemetry: The
dark_crypto_contributetool (Community tier) sends anonymized cryptographic algorithm telemetry to the SouHimBou AI intelligence network only when explicitly invoked by the user. It is never triggered automatically. In sovereign/ironbank mode, all network calls are blocked at the transport layer regardless.
Compliance Coverage
Framework | Version | Mappings |
STIG (RHEL 9) | V1R3 | Automated scanning |
NIST 800-53 | Rev 5 | 2,120 CCIs |
NIST 800-171 | Rev 2 | 320 controls |
CMMC | Level 3 | Full practice set |
FedRAMP | High | Baseline scanning |
PQC-01-STIG-V1R1 | V1R1 | 17 PQC controls (CNSA 2.0) |
Total | 36,195+ mappings |
Licensing
No per-token or per-query charges on any paid tier.
Tier | Cost | License Key | Tools |
Community | Free | Not required |
|
Pro | $19/mo | Required | Compliance reporting, ACP, NHI inventory, autopilot |
Enterprise | $499/mo | Required | All 76 tools, autopilot |
Sovereign | Custom — Contact Sales | Required | All 76 tools + air-gap/offline licensing + HSM, autopilot |
Community tier is permanently free — contribute to open-source PQC adoption
Pro/Enterprise: self-serve billing
Sovereign: contact contact@nouchix.com or visit nouchix.com
Security
Reporting Vulnerabilities
Do not open public issues for security vulnerabilities.
Report privately via GitHub Security Advisories or email support@nouchix.com.
SLA | Target |
Acknowledgement | 24 hours |
Initial assessment | 5 business days |
Patch / mitigation (Critical) | 30 days |
We accept encrypted reports via PGP (keys/security_contact.asc) and Post-Quantum channels (Dilithium / ML-DSA-65 keys in keys/). See SECURITY.md for the full disclosure policy and ASAF event taxonomy.
Security Posture
Deploying advanced post-quantum cryptography, air-gapped isolation, and comprehensive STIG mappings — built in direct alignment with NSA & ASD Model Context Protocol guidelines.
NSA & ASD MCP Security Alignment
The NSA and Australian Signals Directorate (ASD) have published specific threat vectors for AI systems interacting with local environments. KHEPRA MCP is explicitly designed to mitigate every identified vector:
NSA/ASD Requirement | KHEPRA Implementation |
Cryptographic validation of tool responses | ML-DSA-65 (Dilithium) signatures on all JSON-RPC 2.0 payloads |
Input validation & sanitization | Parameter injection resistance via strict JSON Schema validation |
Principle of least privilege credentials | Short-lived ephemeral tokens tied to specific task execution windows |
Comprehensive audit logging | Tamper-evident events compiled into an immutable DAG structure |
Resource consumption limits | Rate limiting + backpressure for LLM request loops |
Authorization gates for sensitive actions | Human-in-the-loop gate for destructive state changes |
Environment isolation | Containerized execution with zero-egress sovereign mode |
Software supply chain integrity | Manifest pinning for all loaded tools and dependencies |
Network exposure reduction | Air-gappable — zero internet transit in |
Post-quantum resilience | PQC-signed DAG trail protecting against harvest-now-decrypt-later |
Compliance Certifications
Framework | Status | Coverage |
CMMC Level 2 | ✅ | Automates evidence collection for AU, CM, SI, SC domains |
NIST SP 800-171 Rev 2 | ✅ | Logging, accountability, system integrity |
NIST SP 800-53 Rev 5 | ✅ | Continuous monitoring (AU-2, SI-4) |
FIPS 203 (ML-KEM) | ✅ | Key encapsulation for secure transit |
FIPS 204 (ML-DSA) | ✅ | Digital signatures for payload authentication |
NSM-10 PQC Mandate | ✅ | National Security Memorandum 10 compliance |
DFARS 252.204-7012 | ✅ | Immutable forensic trails for cyber incident reporting |
NSA MCP Security Guidelines | ✅ | Direct mapping to all published AI agent threat mitigations |
Live Deployment — Physical Edge
Running continuously on constrained edge hardware since May 12, 2026 to prove efficiency in sovereign environments:
Hardware: Raspberry Pi 2 · 1 GB RAM · 900 MHz ARM · Live Spectrum Router
SCADA Pod: STM32U585 / QRB2210 · Modbus TCP · MQTT · Zephyr RTOS 3.4+ · Live Dilithium Signature Verification
Controls active: 3 open ports secured · 12 STIG violations detected · 100% file integrity monitoring (AIDE) · 24/7 continuous operation
Academic Validation
Event | Date | Institution |
UAlbany AI Plus Symposium 2026 — "KHEPRA Protocol: Quantum-Resilient Agentic AI Security Using Cultural Cryptography" | March 7, 2026 | NSA CAE-CDE Institution · 200+ audience |
SUNY Albany Cybersecurity Showcase — First PQC key ceremony on STM32-class device (SCADA Pod) | May 12–13, 2026 | Live demo · SCADA architecture poster |
USPTO Provisional Patent Application No. 63/942,886 — pending.
🔒 Iron Bank containers in DISA vetting process.
Open-Core Architecture Notice
PQC-Khepra-MCP is an open-source Model Context Protocol server providing Post-Quantum Cryptographic primitives (ML-DSA-65, ML-KEM-768) and compliance tooling.
Proprietary runtime governance engines—including the KHEPRA Trust Operating System (KTOS), the ASAF Policy Declaration Language (APDL) Compiler, the Evolutionary Algorithm Lattice Auto-Tuning Kernel, the SEKHEM Polymorphic WAF Gateway, and the Full-Stealth Sovereign Mesh—are components of Khepra Enterprise and are licensed under commercial terms.
Find Us — MCP Registry Listings
PQC-Khepra-MCP is listed on every major MCP discovery platform:
Platform | Link | Notes |
Smithery.ai | One-click install for Claude, Cursor, Windsurf | |
MCP Registry (official) | Anthropic-curated registry — Registry ID: | |
mcpservers.org | Community discovery index | |
Cline Marketplace | VS Code / Cline extension marketplace | |
Live Hosted Endpoint | Zero-install SSE endpoint — connect in 30 seconds |
About NouchiX
Veteran-led advisory firm translating CMMC, NIST, and STIG mandates into executive roadmaps.
Sales / General: contact@nouchix.com
Support: support@nouchix.com
Website: https://nouchix.com
Phone: (518) 304-4450
Developed by SecRed Knowledge Inc. dba NouchiX, Albany, NY.
📋 TC-25 Operator Manual & Developer Runbook
PQC-Khepra-MCP is the open-core agent channel of the KHEPRA Trust OS (KTOS) architecture:
TC-25 Technical Operator & Maintenance Manual — Training Circular No. 25-KTOS-001 covering Four-Layer Sovereign Architecture, Tactical RF anti-jamming suite, Windows Event Viewer hierarchy (IDs 1001–1050), and Dual-Engine Adversarial Neutralization (58/58 Verified).
Developer Installation & Troubleshooting Runbook — Step-by-step runbook for Master Dev Machines, Antigravity IDE (
mcp_config.json), Claude Code (.claude.json), and Sovereign Linux VPS deployment.
Unified KTOS Product Surfaces
Layer 4 — KTOS-MCP Master-Kernel (
mcp.souhimbou.ai): 100 native tools, ML-DSA-65 post-quantum signing, SEKHEM L7 WAF prompt defense, Event Viewer logging, Tactical RF suite.Layer 3a — KTOS CMMC Hub & Fleet Engine (
adinkhepra.com): Sovereign bare-metal & osquery Fleet Manager for CMMC/STIG compliance audits.Layer 3b — KTOS Agentic SOC (
souhimbou.ai): Cloud Agentic SOC & AI Security Architect with autonomous Flight Recorder SDK and KASA threat detector.Layer 2 — Shared Trust Substrate: 36,195 cross-framework compliance mappings, ML-DSA-65 / ML-KEM-1024, immutable DAG attestation.
Layer 1 — KHEPRA Protocol: Patent-pending non-linear cryptographic attestation (USPTO #73565085).
Dual-Engine Pentest Neutralization (58/58 Verified · 100.00% Zero-Bypass Rate)
CyberStryke Automated Assault (30/30): SQLi, XSS, Path Traversal, Null Byte Escapes, Prompt Injections, Egress Data Disclosure neutralized.
AgentHound Offensive Security Framework (28/28): MCP Tool Description Poisoning (
POISONED_DESCRIPTION), Tool Shadowing (SHADOWS), A2A Impersonation (CAN_IMPERSONATE), Indirect Tool Execution (CAN_EXECUTE), Context Window Taint (TAINTS), and Information Flow Control Violations (IFC_VIOLATION) neutralized.
This server cannot be deployed
Maintenance
Related MCP Connectors
Compliance frameworks (SOC 2, ISO 27001, CMMC, NIST, more) delivered to AI agents as MCP tools.
10,065 source-verified compliance nodes, 39 pillars, 25 MCP tools (EU AI Act, GDPR, NIST, MITRE).
Governance copilot for AI-assisted coding. 72 packs, 532 rules, proof bundles.
HIPAA compliance AI agent — scan, grade, SRA, and generate compliance docs.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables authorized compliance verification and security auditing through natural language, bridging AI assistants with industry-standard security tools for enterprise audits.24-
- AlicenseNot gradedqualityAmaintenanceCryptographic AI governance and compliance attestation. 75 tools across 80 regulatory frameworks including EU AI Act, NIST AI RMF, NERC CIP, 3GPP R19, OWASP MCP Top 10, CMMC, and SR 11-7. Full OWASP MCP Top 10 coverage. Witness Middleware for zero-code transport-layer compliance. Runtime containment attestation. Distillation provenance. Incident lifecycle chains.350 npmApache 2.0

teralynk-mcp-serverofficial
AlicenseAqualityBmaintenance102-tool MCP server for AI-native compliance. PII scanning, HIPAA/GDPR/PCI-DSS/SOX/CCPA automation, file intelligence, workflow execution, audit trails, security events, and team management.1320 npmMIT- AlicenseNot gradedqualityBmaintenanceEnables AI agents and builders to run local, audit-traceable governance assessments, including an A³ scorecard, ISO/IEC 42001 and NIST evidence templates, compliance checklists, passport lookup, and sensitive-text screening.MIT