New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Developer Tools

MCP Server: AI-Native Compliance via Cursor and Claude

Why leave your IDE to check your compliance posture? EuroCompliant features a native Model Context Protocol server that lets Cursor, Claude Desktop and any MCP-compatible tool query your live compliance data in natural language, right where you write code. Connect once via SSE transport, then ask what you would otherwise click through a dashboard to find.

Transcript

You should not have to leave your editor to check your compliance posture. EuroCompliant ships a Model Context Protocol server, so Cursor or Claude Desktop can query your live compliance data in plain language.

In Settings, open API Keys and MCP. Generate an API key for your editor and copy the configuration snippet. It contains the MCP endpoint and your key, and it is scoped to your organisation.

Open your Cursor MCP config, or the Claude Desktop config file, and paste the snippet. Save, and the client connects and lists three tools: system compliance status, open security findings, and Shadow AI status.

Now just ask it: are there any open high severity findings affecting our ISO 27001 score?

The assistant calls the findings tool over an encrypted connection with your key, reads live results from your workspace, and answers with the real findings, their severity and their framework. No dashboard to open, no export to chase.

Ask for your overall score and it returns risk classifications and checklist progress. Ask about Shadow AI and it lists the systems discovered by scans. Everything is read only, and every query is written to your audit trail.

Why this is required

Developers lose flow context-switching between IDE and GRC dashboard. Compliance checks that live in the same workflow where code is written, reviewed and shipped get run; checks that require a separate login get postponed. An MCP integration makes the live posture queryable from the place where remediation actually happens.

Natural-language access matters because compliance questions are ad-hoc: 'Are there any open high-severity findings blocking our ISO 27001 score?' is not a dashboard filter you pre-build, it is a question you ask when you need to ship. A read-only tool that answers it from live data removes the latency between asking and knowing.

Engineering-led organisations on the Business plan and above already run the automated scanning pipeline and the Gantt roadmaps; exposing that data via MCP turns every IDE into a compliance-aware surface without duplicating data or creating a new privileged access path.

What EuroCompliant does

Model Context Protocol integration via SSE transport, The server is exposed at /api/mcp/sse (GET for the event stream, POST for JSON-RPC messages over the same connection, per the MCP SSE spec). Any MCP client that speaks SSE can connect: Cursor (via mcp.json), Claude Desktop (via claude_desktop_config.json), or VS Code with an MCP extension. The same EuroCompliant tenant isolation that gates the REST API gates the MCP server, every tool call is scoped to the organisation whose API key authenticated it.

Authentication, In Settings → API Keys & MCP, generate a tenant API key (ApiKey model: name, key_hash = SHA-256 of the raw key, key_prefix for display, permissions=read, active flag). Copy the raw key once (it is hashed at rest, like a password). Every MCP request carries it as X-API-Key header (or Authorization: Bearer <key> for the streamed SSE GET). The key's value is never logged; only the prefix and company_id are. Scoping is enforced per-request via the same company_id filter that backs every tenant query, so two tenants sharing the same MCP server never see each other's findings.

Available tools, Three read-only tools, all live-database queries, no mutations: get_system_compliance_status (params: system_name?, returns risk classification, checklist progress per framework, framework scores, and the single next deadline for that system; omit system_name for the global posture), list_open_security_findings (params: severity in [high,critical]?, framework in [GDPR, EU AI Act, DORA, ISO_27001, CRA]?, returns title, severity, framework, article_reference, finding_type, description, status=open, created_at, blocking the ISO 27001 score exactly as the dashboard does), and check_shadow_ai_status (no params, returns counts of systems discovered by syft_ai_framework vs manually registered, with the promoted system names and the SBOM evidence that triggered promotion). Each tool returns JSON that the LLM then narrates back in natural language.

Compliance summary resource, Beyond tools, the MCP server exposes a single resource, compliance://summary, that any client can subscribe to: a high-level JSON snapshot (active frameworks, global compliance score, urgent findings count, pending obligations count). Poll it for continuous monitoring without re-asking the question.

Read-only, scoped, and plan-gated, All MCP tools are read-only (they query AuditLog, ScanFinding, AISystem, RiskAssessment, ComplianceChecklist but never write). Access is included with the Business plan (899 EUR/mo) and above; Free and Starter see an upgrade prompt in the same API Keys tab. Every call is logged to the hash-chained AuditLog as audit.export or mcp.query, so the fact that an auditor queried via MCP is itself evidenced.

Deadlines

On every code changeQuery before you ship: 'any critical findings on this system?' is a pre-merge check that costs one natural-language question, not a dashboard detour.

Walking through it

1

Generate an API key in Settings → API Keys & MCP

Open Settings → API Keys & MCP → Generate Key. Name it 'Cursor, local' or 'Claude Desktop', leave permissions on read, and copy the raw key and the configuration snippet the UI shows (it contains the SSE URL and the header). The snippet is tenant-specific and already scoped, you do not choose a system at this stage.

Open /settings/integrations?tab=api-keys →
2

Paste the snippet into your MCP client config

Cursor: open .cursor/mcp.json or Settings → MCP → Add server, paste the snippet (url: https://eurocompliant.com/api/mcp/sse, headers: {"X-API-Key": "..."}). Claude Desktop: open claude_desktop_config.json, add an mcpServers.eurocompliant entry with command/url and env X_API_KEY. Save, the client will open an SSE connection and list three tools plus the compliance summary resource.

Open /settings/integrations?tab=api-keys →
3

Ask a live question in natural language

In the Cursor chat or Claude Desktop, type: 'Are there any open high-severity findings blocking our ISO 27001 score?' Watch the AI call list_open_security_findings with severity=high and framework=ISO_27001, then narrate the live rows it just read from your ScanFinding table, no mock data, no stale export, the same rows the dashboard shows, returned as JSON and then spoken. Try the other two: 'What is our overall compliance score?' (get_system_compliance_status with no args) and 'Which systems were discovered by Shadow AI?' (check_shadow_ai_status).

Open /settings/integrations?tab=api-keys →
4

Subscribe to compliance://summary for continuous monitoring

In any MCP client that supports resources, subscribe to compliance://summary. The server will push the high-level snapshot on connect and on every mutation (new finding, status change), so your IDE's compliance view stays live without re-querying.

Open /settings/integrations?tab=api-keys →

The law

Penalties for non-compliance

MCP access itself carries no direct penalty, it is a read-only view. The value is indirect: faster detection of Article 9/10/15 gaps before they become Article 99 fines (up to €15M or 3%).

Frequently asked

Which MCP clients are supported?

Any client that speaks SSE transport and the Model Context Protocol: Claude Desktop (via claude_desktop_config.json), Cursor (via mcp.json), VS Code with an MCP extension, and any future SSE-compliant client. The server is transport-agnostic beyond SSE; the same three tools work identically in each.

Where do I find the SSE URL?

Settings → API Keys & MCP → AI and IDE Integrations. The URL shown is https://<your-tenant>.eurocompliant.com/api/mcp/sse (or https://eurocompliant.com/api/mcp/sse for the cloud). The snippet the UI copies already includes it with the correct header, paste it verbatim.

How is the API key passed?

As X-API-Key header on both the initial SSE GET and every subsequent POST. The raw key is shown only once at generation, hashed as SHA-256 (key_hash) at rest, with a visible key_prefix for identification. Rotate it from the same tab; old keys stop working immediately and the SSE stream drops.

Can MCP tools modify my data?

No. All three tools plus the compliance summary resource are read-only. They query your live database via the same company_id-scoped reads that back the REST API, but they never write. Creation, updates and deletions remain dashboard-only and are separately permission-gated.

Is MCP access available on all plans?

No. MCP access is included with the Business plan (899 EUR/mo) and above. Free and Starter see an upgrade prompt in the same API Keys tab. The same gate that guards scan connectors and evidence vault guards MCP.

What permissions does the API key need?

Read (permissions=read on the ApiKey row). The MCP server rejects keys with write or admin scopes. The key is also tenant-scoped: even with a valid key, you only see your organisation's systems, findings and scores, tenant isolation is enforced per tool call, not just at connection time.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial