Skip to main content

MCP server for soc2 compliance ai. Features assess trust principles, control gap analysis, generate control matrix. From MEOK AI Labs.

Project description

soc2-compliance-ai-mcp MCP server

PyPI Downloads GitHub stars License: MIT

SOC 2 Compliance MCP

Assess AI/ML systems against all 5 Trust Service Criteria with gap analysis, control matrices, and HMAC-signed attestations.

MEOK AI Labs

Install · Tools · Pricing · Attestation API


Why This Exists

SOC 2 Type II reports are the baseline trust signal for any SaaS or AI vendor selling into enterprise. But AI systems introduce control gaps that traditional SOC 2 assessments miss: model provenance, training data governance, drift monitoring, and explainability obligations.

Most compliance teams either bolt AI onto existing SOC 2 control matrices by hand or pay $40K+ for a consultancy engagement. This MCP maps AI/ML-specific risks to the 5 Trust Service Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy), generates control matrices aligned to AICPA 2023 guidance, and crosswalks to ISO 27001 for organisations holding both certifications.

Install

pip install soc2-compliance-ai-mcp

Tools

Tool TSC Reference What it does
assess_trust_principles CC1-CC9, A1, PI1, C1, P1 Full assessment against all 5 Trust Service Criteria
control_gap_analysis CC6, CC7, CC8 Identify missing or weak controls for AI systems
generate_control_matrix All TSC Produce a control matrix mapping AI risks to SOC 2 criteria
risk_assessment CC3, CC4 AICPA-aligned risk assessment for AI/ML workloads
crosswalk_to_iso27001 Annex A mapping Map SOC 2 controls to ISO 27001:2022 Annex A
readiness_checklist Type I / Type II Pre-audit readiness checklist with remediation priorities

Example

Prompt: "Assess our customer-facing LLM chatbot against SOC 2 Trust Service
Criteria. It processes financial data, stores conversation logs for 90 days,
and uses a third-party model API."

Result: Assessment across all 5 TSC with findings on third-party model API
vendor risk, missing drift monitoring, undocumented retention policy.
Each finding includes remediation steps and control references.

Pricing

Tier Price What you get
Free £0 10 calls/day — trust principles assessment + gap analysis
Pro £199/mo Unlimited + HMAC-signed attestations + verify URLs
Enterprise £1,499/mo Multi-tenant + co-branded reports + webhooks

Subscribe to Pro · Enterprise

Attestation API

Every Pro/Enterprise audit produces a cryptographically signed certificate:

POST https://meok-attestation-api.vercel.app/sign
GET  https://meok-attestation-api.vercel.app/verify/{cert_id}

Zero-dep verifier: pip install meok-attestation-verify

Links

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

soc2_compliance_ai_mcp-1.0.2.tar.gz (14.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

soc2_compliance_ai_mcp-1.0.2-py3-none-any.whl (16.3 kB view details)

Uploaded Python 3

File details

Details for the file soc2_compliance_ai_mcp-1.0.2.tar.gz.

File metadata

  • Download URL: soc2_compliance_ai_mcp-1.0.2.tar.gz
  • Upload date:
  • Size: 14.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.15

File hashes

Hashes for soc2_compliance_ai_mcp-1.0.2.tar.gz
Algorithm Hash digest
SHA256 0a2fbac803c4ecea3bd60a8f06e673c5591b4f7391fe2c85709c1e8319097dd4
MD5 a627ebf39a3f843103956b3269dceab6
BLAKE2b-256 ff5f9b5f375a802daa6294dd22b76dcd8beb6e7fed149ebfe8f187cb3fa3a629

See more details on using hashes here.

File details

Details for the file soc2_compliance_ai_mcp-1.0.2-py3-none-any.whl.

File metadata

File hashes

Hashes for soc2_compliance_ai_mcp-1.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 738b05051f8b25686a21626ee36e0d26266d8cea3121d90867195326ae303dcd
MD5 d8a5054b61388dc50056526458c417ee
BLAKE2b-256 a001b21e19e9933b4a9be89cc2dc6778919fe522c4089ffeca64007537452eab

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page