MCP-Server

Moltline RegClock

com.moltlinestudio/regclock
Recht & Compliance Öffentlich und erreichbar MCP 2025-11-25

Was dieses MCP kann

Classifies reportable incidents and calculates, explains, tracks, validates, and exports regulatory reporting deadlines across multiple legal regimes.

classify_event
Classify Event
Apply a regime's statutory criteria to yes/no facts and name the event type. FREE. Typical input {"regime": "eu_dora", "facts": {"critical_services_affected": true, "duration_or_downtime": true, "geographic_spread": true}} returns {"reportable": true, "event_type": "major_ict_incident", "reasoning": [...], "criteria": {...}}. Unanswered questions are listed under "missing" so the caller can go and find out. Use when deciding whether an incident triggers a regime at all. Not for judging severity in the abstract: it only applies the written criteria to the facts given. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "facts must be an object of question id -> answer"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'required': ['regime', 'facts'], 'properties': {'facts': {'type': 'object', 'description': 'answers keyed by the question ids returned for the regime (booleans; integers for counts).', 'additionalProperties': True}, 'regime': {'type': 'string', 'description': 'regime id from list_regimes.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'additionalProperties': True}
compute_deadlines
Compute Deadlines
Compute every reporting deadline of one regime from the moment of awareness. FREE. Typical input {"regime": "eu_nis2", "event_type": "significant_incident", "awareness_at": "2026-09-14T09:30:00+02:00"} returns {"deadlines": [{"obligation": "early_warning", "due_at": "2026-09-15T09:30+02:00", "citation": "Art. 23(4)(a)", ...}, ...]}. Later clocks that run from an earlier submission are estimated from that report's due time until you pass the actual time in submitted. DORA needs classification_at and a country for the bank-holiday rule; the SEC needs materiality_determined_at; HIPAA takes discovery_date and flags.individuals_affected. Use when an incident has just been identified and the agent needs the instants. Not for several regimes at once: use compute_deadlines_multi. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "flags must be an object"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'required': ['regime', 'awareness_at'], 'properties': {'flags': {'type': 'object', 'default': {}, 'description': 'condition answers: high_risk, processor, ongoing, handled_at, individuals_affected, max_residents_of_one_state, business_associate.', 'additionalProperties': True}, 'regime': {'type': 'string', 'description': 'regime id from list_regimes.'}, 'subdiv': {'type': 'string', 'default': '', 'description': 'optional subdivision code for the holiday calendar (e.g. BY for Bavaria).'}, 'country': {'type': 'string', 'default': '', 'description': 'ISO 3166-1 alpha-2 code for the public-holiday calendar (DORA weekend rule; SEC uses US).'}, 'submitted': {'type': 'object', 'default': {}, 'description': 'actual submission times of earlier reports, e.g. {"initial_notification": "..."}.', 'additionalProperties': True}, 'event_type': {'type': 'string', 'default': '', 'description': 'event type within the regime; optional when the regime has one.'}, 'awareness_at': {'type': 'string', 'description': 'when the entity became aware, ISO 8601 with a UTC offset.'}, 'entity_class': {'type': 'string', 'default': '', 'description': 'e.g. trust_service_provider (NIS2), credit_institution / central_counterparty / trading_venue_operator / nis2_essential_or_important (DORA), business_associate (HIPAA).'}, 'discovery_date': {'type': 'string', 'default': '', 'description': 'HIPAA - the date the breach is treated as discovered (defaults to awareness date).'}, 'classification_at': {'type': 'string', 'default': '', 'description': 'DORA - when the incident was classified as major.'}, 'measure_available_at': {'type': 'string', 'default': '', 'description': 'CRA - when a corrective or mitigating measure became available.'}, 'materiality_determined_at': {'type': 'string', 'default': '', 'description': 'SEC - when the incident was determined to be material.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'additionalProperties': True}
compute_deadlines_multi
Compute Deadlines Multi
One merged timeline across several regimes for the same incident. PREMIUM (license). Typical input {"regimes": [{"regime": "eu_nis2"}, {"regime": "eu_gdpr"}, {"regime": "eu_dora", "entity_class": "credit_institution"}], "awareness_at": "2026-09-14T09:30:00+02:00", "country": "DE"} returns {"timeline": [rows sorted by due_at, each tagged with regime], "first_due": {...}, "per_regime": {...}}. Each entry may carry its own event_type and entity_class; the anchors and flags are shared. Use when one incident triggers several regimes and the agent needs a single ordered list. Not for one regime: compute_deadlines is free. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "regimes must be a non-empty list of <value>"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'required': ['regimes', 'awareness_at'], 'properties': {'flags': {'type': 'object', 'default': {}, 'description': 'condition answers shared by all regimes (see compute_deadlines).', 'additionalProperties': True}, 'subdiv': {'type': 'string', 'default': '', 'description': 'optional subdivision code for the holiday calendar.'}, 'country': {'type': 'string', 'default': '', 'description': 'ISO 3166-1 alpha-2 code for the public-holiday calendar.'}, 'regimes': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'list of {"regime": id, "event_type"?: ..., "entity_class"?: ...} (1-10 entries).'}, 'submitted': {'type': 'object', 'default': {}, 'description': 'actual submission times keyed by "regime/obligation" or obligation id.', 'additionalProperties': True}, 'awareness_at': {'type': 'string', 'description': 'when the entity became aware, ISO 8601 with a UTC offset.'}, 'entity_class': {'type': 'string', 'default': '', 'description': 'default entity class for entries that do not set their own.'}, 'discovery_date': {'type': 'string', 'default': '', 'description': 'HIPAA discovery date (defaults to the awareness date).'}, 'classification_at': {'type': 'string', 'default': '', 'description': 'DORA classification instant.'}, 'measure_available_at': {'type': 'string', 'default': '', 'description': 'CRA corrective-measure instant.'}, 'materiality_determined_at': {'type': 'string', 'default': '', 'description': 'SEC materiality determination instant.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'additionalProperties': True}
deadline_status
Deadline Status
Mark each computed deadline open, due soon, overdue or submitted as of now. FREE. Typical input {"deadlines": <rows from compute_deadlines>, "now": "2026-09-15T08:00:00+02:00"} returns {"items": [{"obligation": "early_warning", "status": "due_soon", "hours_remaining": 1.5, ...}], "overdue": 0, "next_due": {...}}. Use when polling an incident timeline or deciding what to escalate next. Not for computing the deadlines themselves. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "deadlines must be a non-empty list of rows from compute_deadlines"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'required': ['deadlines', 'now'], 'properties': {'now': {'type': 'string', 'description': 'the current instant, ISO 8601 with a UTC offset.'}, 'deadlines': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'rows from compute_deadlines / compute_deadlines_multi (each with obligation and due_at).'}, 'submitted': {'type': 'object', 'default': {}, 'description': 'actual submission times keyed by obligation id (or "regime/obligation").', 'additionalProperties': True}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'additionalProperties': True}
explain_rule
Explain Rule
Quote the time limit, citation and required content for an obligation. FREE. Typical input {"regime": "eu_cra", "event_type": "severe_incident", "obligation": "final_report"} returns {"citation": "Art. 14(4)(c)", "rule": "within one month after ...", "required_content": [...]}. Leave obligation empty to get every obligation of the event type; leave event_type empty on single-event regimes. Use when a caller needs the rule's own words next to a computed date. Not for computing dates: use compute_deadlines. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "unknown obligation '<value>' for <value>/<value>; one of <value>"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'required': ['regime'], 'properties': {'regime': {'type': 'string', 'description': 'regime id from list_regimes (eu_cra, eu_nis2, eu_dora, eu_gdpr, uk_gdpr, us_hipaa, us_sec_8k).'}, 'event_type': {'type': 'string', 'default': '', 'description': 'event type within the regime (see list_regimes); optional when the regime has one.'}, 'obligation': {'type': 'string', 'default': '', 'description': 'obligation id (for example early_warning); empty for all.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'additionalProperties': True}
holiday_calendar
Holiday Calendar
List the public holidays the engine uses for a country and year. FREE. Typical input {"country": "IE", "year": 2026} returns {"holidays": [{"date": "2026-01-01", "name": "New Year's Day"}, ...]}. Use when checking why a business-day or bank-holiday adjustment landed where it did, or to see whether a country/subdivision is supported. Not a legal register of bank holidays: it is the `holidays` package's public-holiday calendar, which is what compute_deadlines uses. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "country is required"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'required': ['country', 'year'], 'properties': {'year': {'type': 'integer', 'maximum': 2100, 'minimum': 1990, 'description': 'calendar year.'}, 'subdiv': {'type': 'string', 'default': '', 'description': 'optional subdivision code (state, province, region).'}, 'country': {'type': 'string', 'description': 'ISO 3166-1 alpha-2 code (DE, FR, IE, US, ...).'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'additionalProperties': True}
list_regimes
List Regimes
List the reporting regimes this server can compute, with citations. FREE. Typical input {} returns {"regimes": [{"id": "eu_nis2", "name": ..., "instrument": ..., "applies_from": ..., "event_types": [...]}, ...], "verified_on": "2026-09-06"}. Use when choosing the regime id and event_type for compute_deadlines or classify_event. Not for legal advice: it reports what the instruments say and when the entry was last checked. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'additionalProperties': True}
timeline_export
Timeline Export
Export computed deadlines as an iCalendar file and CSV rows. PREMIUM (license). Typical input {"deadlines": <rows from compute_deadlines or the timeline from compute_deadlines_multi>, "incident_ref": "INC-2026-041"} returns {"ics": "BEGIN:VCALENDAR...", "csv": "regime,obligation,...", "events": 4}. Each dated deadline becomes a VEVENT with the citation in the description and an alarm alarm_hours_before it; rows without a fixed time limit are listed in the CSV only. Use when the timeline needs to land in a calendar or a ticket. Not for computing deadlines. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "deadlines must be a non-empty list of rows from compute_deadlines"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'required': ['deadlines'], 'properties': {'deadlines': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'rows from compute_deadlines / compute_deadlines_multi.'}, 'incident_ref': {'type': 'string', 'default': '', 'description': 'your incident reference, prefixed to every event summary.'}, 'calendar_name': {'type': 'string', 'default': 'Incident reporting deadlines', 'description': 'X-WR-CALNAME for the calendar file.'}, 'alarm_hours_before': {'type': 'number', 'default': 4, 'maximum': 720, 'minimum': 0, 'description': 'hours before each due instant to fire a VALARM (0 disables).'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'additionalProperties': True}
validate_report
Validate Report
Check a draft report against the statutory content list and its deadline. PREMIUM (license). Typical input {"regime": "eu_gdpr", "obligation": "supervisory_authority_notification", "report": {"nature": "...", "contact": "...", "consequences": "...", "measures": "..."}} returns {"checklist": [{"item": "...", "found": true, "evidence": [...]}, ...], "missing": [...], "coverage": 0.75, "timing": {...}}. The content check is a keyword heuristic over the report text, reported as such; the timing check compares submitted_at with due_at and, for GDPR, flags a late notification that gives no reasons for the delay. Use before a report is sent. Not a legal review, and it cannot judge quality, only presence. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"} (for example {"error": "unknown obligation '<value>' for <value>/<value>; one of <value>"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'required': ['regime', 'obligation', 'report'], 'properties': {'due_at': {'type': 'string', 'default': '', 'description': 'the computed due instant (from compute_deadlines), optional.'}, 'regime': {'type': 'string', 'description': 'regime id from list_regimes.'}, 'report': {'type': 'object', 'description': 'the draft, as an object of section name -> text (any keys).', 'additionalProperties': True}, 'event_type': {'type': 'string', 'default': '', 'description': 'event type within the regime; optional when the regime has one.'}, 'obligation': {'type': 'string', 'description': 'obligation id (for example incident_notification).'}, 'submitted_at': {'type': 'string', 'default': '', 'description': 'when the report was or will be submitted, optional.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'additionalProperties': True}
Hinzugefügt
timeline_export
17. September 2026 12:36
Hinzugefügt
validate_report
17. September 2026 12:36
Hinzugefügt
compute_deadlines_multi
17. September 2026 12:36
Hinzugefügt
holiday_calendar
17. September 2026 12:36
Hinzugefügt
deadline_status
17. September 2026 12:36
Hinzugefügt
compute_deadlines
17. September 2026 12:36
Hinzugefügt
classify_event
17. September 2026 12:36
Hinzugefügt
explain_rule
17. September 2026 12:36
Hinzugefügt
list_regimes
17. September 2026 12:36