Developer Tools
MCP Server: AI-Native Compliance via Cursor and Claude
Why leave your IDE to check your compliance posture? EuroCompliant features a native Model Context Protocol server that lets Cursor, Claude Desktop and any MCP-compatible tool query your live compliance data in natural language, right where you write code. Connect once via SSE transport, then ask what you would otherwise click through a dashboard to find.
Transcript
You should not have to leave your editor to check your compliance posture. EuroCompliant ships a Model Context Protocol server, so Cursor or Claude Desktop can query your live compliance data in plain language.
In Settings, open API Keys and MCP. Generate an API key for your editor and copy the configuration snippet. It contains the MCP endpoint and your key, and it is scoped to your organisation.
Open your Cursor MCP config, or the Claude Desktop config file, and paste the snippet. Save, and the client connects and lists three tools: system compliance status, open security findings, and Shadow AI status.
Now just ask it: are there any open high severity findings affecting our ISO 27001 score?
The assistant calls the findings tool over an encrypted connection with your key, reads live results from your workspace, and answers with the real findings, their severity and their framework. No dashboard to open, no export to chase.
Ask for your overall score and it returns risk classifications and checklist progress. Ask about Shadow AI and it lists the systems discovered by scans. Everything is read only, and every query is written to your audit trail.
Why this is required
Developers lose flow context-switching between IDE and GRC dashboard. Compliance checks that live in the same workflow where code is written, reviewed and shipped get run; checks that require a separate login get postponed. An MCP integration makes the live posture queryable from the place where remediation actually happens.
Natural-language access matters because compliance questions are ad-hoc: 'Are there any open high-severity findings blocking our ISO 27001 score?' is not a dashboard filter you pre-build, it is a question you ask when you need to ship. A read-only tool that answers it from live data removes the latency between asking and knowing.
Engineering-led organisations on the Business plan and above already run the automated scanning pipeline and the Gantt roadmaps; exposing that data via MCP turns every IDE into a compliance-aware surface without duplicating data or creating a new privileged access path.
What EuroCompliant does
Model Context Protocol integration via SSE transport, The server is exposed at /api/mcp/sse (GET for the event stream, POST for JSON-RPC messages over the same connection, per the MCP SSE spec). Any MCP client that speaks SSE can connect: Cursor (via mcp.json), Claude Desktop (via claude_desktop_config.json), or VS Code with an MCP extension. The same EuroCompliant tenant isolation that gates the REST API gates the MCP server, every tool call is scoped to the organisation whose API key authenticated it.
Authentication, In Settings → API Keys & MCP, generate a tenant API key (ApiKey model: name, key_hash = SHA-256 of the raw key, key_prefix for display, permissions=read, active flag). Copy the raw key once (it is hashed at rest, like a password). Every MCP request carries it as X-API-Key header (or Authorization: Bearer <key> for the streamed SSE GET). The key's value is never logged; only the prefix and company_id are. Scoping is enforced per-request via the same company_id filter that backs every tenant query, so two tenants sharing the same MCP server never see each other's findings.
Available tools, Three read-only tools, all live-database queries, no mutations: get_system_compliance_status (params: system_name?, returns risk classification, checklist progress per framework, framework scores, and the single next deadline for that system; omit system_name for the global posture), list_open_security_findings (params: severity in [high,critical]?, framework in [GDPR, EU AI Act, DORA, ISO_27001, CRA]?, returns title, severity, framework, article_reference, finding_type, description, status=open, created_at, blocking the ISO 27001 score exactly as the dashboard does), and check_shadow_ai_status (no params, returns counts of systems discovered by syft_ai_framework vs manually registered, with the promoted system names and the SBOM evidence that triggered promotion). Each tool returns JSON that the LLM then narrates back in natural language.
Compliance summary resource, Beyond tools, the MCP server exposes a single resource, compliance://summary, that any client can subscribe to: a high-level JSON snapshot (active frameworks, global compliance score, urgent findings count, pending obligations count). Poll it for continuous monitoring without re-asking the question.
Read-only, scoped, and plan-gated, All MCP tools are read-only (they query AuditLog, ScanFinding, AISystem, RiskAssessment, ComplianceChecklist but never write). Access is included with the Business plan (899 EUR/mo) and above; Free and Starter see an upgrade prompt in the same API Keys tab. Every call is logged to the hash-chained AuditLog as audit.export or mcp.query, so the fact that an auditor queried via MCP is itself evidenced.
Deadlines
Walking through it
Generate an API key in Settings → API Keys & MCP
Open Settings → API Keys & MCP → Generate Key. Name it 'Cursor, local' or 'Claude Desktop', leave permissions on read, and copy the raw key and the configuration snippet the UI shows (it contains the SSE URL and the header). The snippet is tenant-specific and already scoped, you do not choose a system at this stage.
Open /settings/integrations?tab=api-keys →Paste the snippet into your MCP client config
Cursor: open .cursor/mcp.json or Settings → MCP → Add server, paste the snippet (url: https://eurocompliant.com/api/mcp/sse, headers: {"X-API-Key": "..."}). Claude Desktop: open claude_desktop_config.json, add an mcpServers.eurocompliant entry with command/url and env X_API_KEY. Save, the client will open an SSE connection and list three tools plus the compliance summary resource.
Open /settings/integrations?tab=api-keys →Ask a live question in natural language
In the Cursor chat or Claude Desktop, type: 'Are there any open high-severity findings blocking our ISO 27001 score?' Watch the AI call list_open_security_findings with severity=high and framework=ISO_27001, then narrate the live rows it just read from your ScanFinding table, no mock data, no stale export, the same rows the dashboard shows, returned as JSON and then spoken. Try the other two: 'What is our overall compliance score?' (get_system_compliance_status with no args) and 'Which systems were discovered by Shadow AI?' (check_shadow_ai_status).
Open /settings/integrations?tab=api-keys →Subscribe to compliance://summary for continuous monitoring
In any MCP client that supports resources, subscribe to compliance://summary. The server will push the high-level snapshot on connect and on every mutation (new finding, status change), so your IDE's compliance view stays live without re-querying.
Open /settings/integrations?tab=api-keys →The law
Risk management system
Continuous visibility into AI system risk posture, get_system_compliance_status supports the iterative process Article 9 requires.
Data and data governance
Visibility into whether training data scans (presidio_pii + GLiNER) are clean, list_open_security_findings surfaces that in the IDE.
Security of processing
Checking open GDPR findings from where the code is written keeps the Article 32 testing loop tight.
Monitoring, measurement, analysis and evaluation
Continuous monitoring of ISMS controls, the compliance summary resource is that monitoring, queryable via MCP.
Penalties for non-compliance
MCP access itself carries no direct penalty, it is a read-only view. The value is indirect: faster detection of Article 9/10/15 gaps before they become Article 99 fines (up to €15M or 3%).
Frequently asked
Which MCP clients are supported?
Any client that speaks SSE transport and the Model Context Protocol: Claude Desktop (via claude_desktop_config.json), Cursor (via mcp.json), VS Code with an MCP extension, and any future SSE-compliant client. The server is transport-agnostic beyond SSE; the same three tools work identically in each.
Where do I find the SSE URL?
Settings → API Keys & MCP → AI and IDE Integrations. The URL shown is https://<your-tenant>.eurocompliant.com/api/mcp/sse (or https://eurocompliant.com/api/mcp/sse for the cloud). The snippet the UI copies already includes it with the correct header, paste it verbatim.
How is the API key passed?
As X-API-Key header on both the initial SSE GET and every subsequent POST. The raw key is shown only once at generation, hashed as SHA-256 (key_hash) at rest, with a visible key_prefix for identification. Rotate it from the same tab; old keys stop working immediately and the SSE stream drops.
Can MCP tools modify my data?
No. All three tools plus the compliance summary resource are read-only. They query your live database via the same company_id-scoped reads that back the REST API, but they never write. Creation, updates and deletions remain dashboard-only and are separately permission-gated.
Is MCP access available on all plans?
No. MCP access is included with the Business plan (899 EUR/mo) and above. Free and Starter see an upgrade prompt in the same API Keys tab. The same gate that guards scan connectors and evidence vault guards MCP.
What permissions does the API key need?
Read (permissions=read on the ApiKey row). The MCP server rejects keys with write or admin scopes. The key is also tenant-scoped: even with a valid key, you only see your organisation's systems, findings and scores, tenant isolation is enforced per tool call, not just at connection time.
Related guides
Automated Scanning: Continuous Telemetry and Scan Pipelines
How scheduled scan jobs, 12 scan engines and local PII scrubbing produce dated Article 10/15 evidence without moving data outside the EEA.
Compliance Roadmaps: Gantt Plans and Corrective Actions
Turn unfinished obligations and scan findings into a Gantt-tracked plan with owners, dates, and evidence-required closure.
The compliance calendar and reporting dashboard
The cross-framework view: every deadline in one calendar, and where your overall compliance posture is measured.
Agent Runtime Telemetry
Stream signed execution decisions from your autonomous-agent runtime firewall straight into tamper-evident audit evidence.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial