Skip to main content

MCP server for soc2 compliance ai. Features assess trust principles, control gap analysis, generate control matrix. From MEOK AI Labs.

Project description

soc2-compliance-ai-mcp MCP server

PyPI Downloads GitHub stars License: MIT

SOC 2 Compliance MCP

Assess AI/ML systems against all 5 Trust Service Criteria with gap analysis, control matrices, and HMAC-signed attestations.

MEOK AI Labs

Install · Tools · Pricing · Attestation API


Why This Exists

SOC 2 Type II reports are the baseline trust signal for any SaaS or AI vendor selling into enterprise. But AI systems introduce control gaps that traditional SOC 2 assessments miss: model provenance, training data governance, drift monitoring, and explainability obligations.

Most compliance teams either bolt AI onto existing SOC 2 control matrices by hand or pay $40K+ for a consultancy engagement. This MCP maps AI/ML-specific risks to the 5 Trust Service Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy), generates control matrices aligned to AICPA 2023 guidance, and crosswalks to ISO 27001 for organisations holding both certifications.

Install

pip install soc2-compliance-ai-mcp

Tools

Tool TSC Reference What it does
assess_trust_principles CC1-CC9, A1, PI1, C1, P1 Full assessment against all 5 Trust Service Criteria
control_gap_analysis CC6, CC7, CC8 Identify missing or weak controls for AI systems
generate_control_matrix All TSC Produce a control matrix mapping AI risks to SOC 2 criteria
risk_assessment CC3, CC4 AICPA-aligned risk assessment for AI/ML workloads
crosswalk_to_iso27001 Annex A mapping Map SOC 2 controls to ISO 27001:2022 Annex A
readiness_checklist Type I / Type II Pre-audit readiness checklist with remediation priorities

Example

Prompt: "Assess our customer-facing LLM chatbot against SOC 2 Trust Service
Criteria. It processes financial data, stores conversation logs for 90 days,
and uses a third-party model API."

Result: Assessment across all 5 TSC with findings on third-party model API
vendor risk, missing drift monitoring, undocumented retention policy.
Each finding includes remediation steps and control references.

Pricing

Tier Price What you get
Free £0 10 calls/day — trust principles assessment + gap analysis
Pro £199/mo Unlimited + HMAC-signed attestations + verify URLs
Enterprise £1,499/mo Multi-tenant + co-branded reports + webhooks

Subscribe to Pro · Enterprise

Attestation API

Every Pro/Enterprise audit produces a cryptographically signed certificate:

POST https://meok-attestation-api.vercel.app/sign
GET  https://meok-attestation-api.vercel.app/verify/{cert_id}

Zero-dep verifier: pip install meok-attestation-verify

Links

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

soc2_compliance_ai_mcp-1.0.5.tar.gz (25.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

soc2_compliance_ai_mcp-1.0.5-py3-none-any.whl (17.2 kB view details)

Uploaded Python 3

File details

Details for the file soc2_compliance_ai_mcp-1.0.5.tar.gz.

File metadata

  • Download URL: soc2_compliance_ai_mcp-1.0.5.tar.gz
  • Upload date:
  • Size: 25.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for soc2_compliance_ai_mcp-1.0.5.tar.gz
Algorithm Hash digest
SHA256 ce20692b74f276d8b60528ce0cc9d1e390a65e4c6d47895cd1610cba7cd67a54
MD5 2a00b521fc1aa72264e046e3fe131619
BLAKE2b-256 e85d5875662a9eb6f94f7f9703134f070f125448964a61387edc6c13bf2c2d3e

See more details on using hashes here.

File details

Details for the file soc2_compliance_ai_mcp-1.0.5-py3-none-any.whl.

File metadata

File hashes

Hashes for soc2_compliance_ai_mcp-1.0.5-py3-none-any.whl
Algorithm Hash digest
SHA256 55a782a1ae742d78f163d0055f71f4c619af4053ecbb5e8baef020c92e74a90f
MD5 75b9ee2dbfcf8a505a93ac28eacce0bc
BLAKE2b-256 458f0037c623841ac9d7fd46ceeef5d9f5b016595c35ff1ef71f5f85a9eb7eed

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page