MCP Server

ampel

io.tooloracle/ampel

What this MCP does

Assesses regulated entities and providers against DORA and related ESG, MiCA, and AML requirements, with contract analysis, evidence collection, audit trails, risk findings, and regulatory report generation.

article_status
Detailed Ampel for a specific DORA article. Each check with GREEN/YELLOW/RED conditions and evidence.
Input schema
{'type': 'object', 'properties': {'article': {'type': 'string', 'description': 'e.g. Art. 28'}, 'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
assess_all
Re-run full assessment for an entity. Recomputes Ampel statuses from all available evidence.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
audit_trail
Chain-linked audit log with integrity check.
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'description': 'Max entries'}, 'entity_id': {'type': 'string'}}, 'additionalProperties': False}
azure_ad_check
Live Azure AD integration: MFA registration %, risky users, conditional access policies. DORA Art. 9 evidence. Requires Azure AD config in integrations_config.json.
Input schema
{'type': 'object', 'properties': {'force_refresh': {'type': 'boolean', 'description': 'Force fresh API call (default true)'}}, 'additionalProperties': False}
bafin_approve_send
Approve BaFin report for submission (4-eyes principle). Creates signed approval evidence.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string'}, 'report_id': {'type': 'string'}, 'approver_name': {'type': 'string'}, 'approver_role': {'type': 'string'}}, 'additionalProperties': False}
bafin_report_draft
Generate ITS 2024/1772 compliant BaFin incident report draft. All mandatory fields per DORA Art. 19/20. Preview mode — requires board approval.
Input schema
{'type': 'object', 'properties': {'title': {'type': 'string'}, 'entity_id': {'type': 'string'}, 'root_cause': {'type': 'string'}, 'description': {'type': 'string'}, 'incident_id': {'type': 'string'}, 'remediation': {'type': 'string'}, 'report_type': {'type': 'string', 'description': 'initial | intermediate | final'}, 'classification': {'type': 'string', 'description': 'major | significant | minor'}, 'affected_clients': {'type': 'string'}, 'affected_services': {'type': 'string'}}, 'additionalProperties': False}
board_summary
Executive board summary: overall score, top 5 risks, overdue findings, SLA breaches, concentration risk, evidence health, owner workload. Designed for management/board reporting.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
bridge_approve
Approve or reject a bridge resolution. On approval: creates signed evidence, upgrades Ampel to GREEN, logs to audit chain.
Input schema
{'type': 'object', 'properties': {'reject': {'type': 'boolean', 'description': 'Set true to reject instead of approve'}, 'approved_by': {'type': 'string', 'description': 'Name + role of approver (e.g. Dr. Mueller, CISO)'}, 'resolution_id': {'type': 'string', 'description': 'Resolution ID from bridge_resolve'}, 'rejection_reason': {'type': 'string', 'description': 'Reason for rejection (if rejecting)'}}, 'additionalProperties': False}
bridge_report
Bridge gap analysis: classifies gaps by DATA/EVIDENCE/POLICY/WORKFLOW with closure path, owner, effort level.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
bridge_resolve
Start bridge resolution workflow. Generates templates (Risk Acceptance, Contract Renegotiation, Concentration Policy, Exit Strategy), tracks approval process. Call bridge_approve to sign off.
Input schema
{'type': 'object', 'properties': {'check_id': {'type': 'string', 'description': 'Check to resolve: art30_c1, art30_c2, art30_c3, art8_c3, art31_c1'}, 'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}, 'expiry_days': {'type': 'integer', 'description': 'Days until resolution expires (default 30)'}}, 'additionalProperties': False}
bridge_status
Check status of all bridge resolution workflows for an entity. Shows open, pending, closed, rejected.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
bus_status
Oracle Event Bus status: events, cross-refs, connected oracles.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID for cross-refs'}}, 'additionalProperties': False}
check_contract
Check DORA Art. 30 contract clauses for a provider. Returns PASS/WARN/BLOCK with missing clauses and bridge classification.
Input schema
{'type': 'object', 'properties': {'is_cif': {'type': 'boolean', 'description': 'Is this a CIF (Critical/Important Function) provider?'}, 'entity_id': {'type': 'string'}, 'cif_clauses': {'type': 'array', 'items': {'type': 'string'}, 'description': 'CIF clauses if applicable'}, 'provider_id': {'type': 'string', 'description': 'Provider ID'}, 'exit_strategy': {'type': 'boolean', 'description': 'Exit strategy documented?'}, 'standard_clauses': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Present standard clauses: service_description, data_location, data_protection, service_availability_sla, incident_notification, audit_right, termination_notice, cooperation_with_authorities'}}, 'additionalProperties': False}
collect_art10
Collect live Art. 10 evidence from NVD, CISA KEV, CERT-Bund. Auto-assesses.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
contract_analyze
Analyze contract against 15 DORA Art. 30 mandatory clauses. Returns compliance status per clause with confidence score, extracted text, gap reasoning, suggested fix.
Input schema
{'type': 'object', 'properties': {'document_id': {'type': 'string', 'description': 'Document ID from contract_upload'}}, 'additionalProperties': False}
contract_status
Overview of all analyzed contracts per entity. Shows clause gaps, review status, document versions.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
contract_upload
Upload contract text for DORA Art. 30 analysis. Creates document record with SHA-256 hash, version tracking, audit trail.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}, 'file_name': {'type': 'string', 'description': 'Original file name'}, 'contract_text': {'type': 'string', 'description': 'Contract text (extracted from PDF)'}, 'document_type': {'type': 'string', 'description': 'ict_outsourcing_agreement | dpa | sla | master_service_agreement'}, 'provider_name': {'type': 'string', 'description': 'Provider name'}}, 'additionalProperties': False}
create_entity
Register a new regulated entity.
Input schema
{'type': 'object', 'properties': {'lei': {'type': 'string'}, 'name': {'type': 'string', 'description': 'Entity name'}, 'entity_type': {'type': 'string', 'description': 'Type'}, 'jurisdiction': {'type': 'string'}}, 'additionalProperties': False}
create_trial
Create temporary trial entity (48h) for self-service DORA assessment. No login needed.
Input schema
{'type': 'object', 'properties': {'providers': {'enum': ['AWS', 'SWIFT'], 'type': 'string', 'description': 'Comma-separated provider names: AWS,SWIFT,Finastra'}, 'entity_name': {'type': 'string', 'description': 'Institute name'}, 'entity_type': {'type': 'string', 'description': 'credit_institution|payment_institution|insurance_undertaking|asset_management|credit_institution_casp'}, 'jurisdiction': {'type': 'string', 'description': 'DE|AT|FR|etc'}}, 'additionalProperties': False}
cross_oracle_assess
Enterprise cross-oracle assessment. Runs 18 checks across CyberShield (NIS2/ISO 27001), SupplyChainOracle (LkSG/CSRD), HealthGuard (MDR/GDPR), CFOCoPilot (XRechnung), TaxOracle (DAC6), LegalTechOracle (DORA contracts). Auto-stores evidence and updates Ampel status.
Input schema
{'type': 'object', 'properties': {'checks': {'type': 'string', 'description': 'Comma-separated check IDs or omit for all'}, 'entity_id': {'type': 'string', 'description': 'Entity to assess'}}, 'additionalProperties': False}
cross_regulation_check
Tag findings with cross-regulation impact (DORA + MiCA + AMLR). Shows which DORA findings also affect MiCA insider info or AMLR screening.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
cve_asset_map
Map CVE/vulnerability to internal ICT providers and systems. Auto-creates findings for critical matches. DORA Art. 10.
Input schema
{'type': 'object', 'properties': {'cve_id': {'type': 'string', 'description': 'CVE identifier'}, 'vendor': {'type': 'string', 'description': 'Vendor/software name to check'}, 'entity_id': {'type': 'string'}}, 'additionalProperties': False}
dependency_graph
Full provider dependency graph: providers, systems, checks, blast radius, SPOF detection.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
entity_list
List all registered regulated entities.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
escalation_status
Get findings, SLA breaches, escalation status per entity.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (empty=all)'}}, 'additionalProperties': False}
evidence_pack
Export evidence pack for article/check/entity. Pruefer-ready: evidence, assessments, findings, audit trail, signatures.
Input schema
{'type': 'object', 'properties': {'article': {'type': 'string', 'description': 'DORA article e.g. Art. 10'}, 'check_id': {'type': 'string', 'description': 'Specific check ID'}, 'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
evidence_summary
All evidence artefacts for an entity with hashes and expiry dates.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
freshness_check
Run freshness watchdog. Expires stale evidence, downgrades GREEN->YELLOW->GREY if evidence too old.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional, checks all)'}}, 'additionalProperties': False}
gap_report
DORA compliance gaps. RED/GREY/YELLOW items with priority and required actions.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
generate_report
Generate data-driven DORA Ampel PDF report. Score, gap analysis, provider register, audit trail integrity.
Input schema
{'type': 'object', 'properties': {'format': {'type': 'string', 'default': 'json', 'description': 'json (meta) or pdf (download)'}, 'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
generate_trial_report
Generate watermarked trial report with score, gaps, and CTA.
Input schema
{'type': 'object', 'properties': {'trial_id': {'type': 'string'}, 'entity_id': {'type': 'string'}}, 'additionalProperties': False}
health_check
Server + DB status.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
incident_flow
DORA incident lifecycle: log, classify, notify (BaFin), close. Each step creates signed evidence.
Input schema
{'type': 'object', 'properties': {'title': {'type': 'string'}, 'action': {'type': 'string', 'description': 'log | classify | notify | close'}, 'severity': {'type': 'string'}, 'entity_id': {'type': 'string', 'description': 'Entity ID'}, 'root_cause': {'type': 'string'}, 'description': {'type': 'string'}, 'incident_id': {'type': 'string'}, 'report_type': {'type': 'string'}, 'classification': {'type': 'string'}, 'lessons_learned': {'type': 'string'}}, 'additionalProperties': False}
llm_clause_check
LLM-based DORA Art. 30 contract analysis. Paste contract text, get clause-by-clause PRESENT/PARTIAL/MISSING for all 15 mandatory clauses. Uses Claude API.
Input schema
{'type': 'object', 'properties': {'contract_text': {'type': 'string', 'description': 'Contract text (plain text from PDF). Paste key sections.'}, 'provider_name': {'type': 'string', 'description': 'Provider name e.g. Salesforce'}}, 'additionalProperties': False}
onboard_entity
Full entity onboarding: creates initial RED assessments for all 39 checks, collects auto-evidence from live sources, re-assesses, and returns readiness score.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID to onboard'}}, 'additionalProperties': False}
ping
Quick connectivity test.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
policy_draft
Generate DORA policy/framework document draft for a specific article. 8 templates available (Art. 5,6,8,10,11,17,28,30). Uses entity data for customization.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string'}, 'dora_article': {'type': 'string', 'description': 'dora_art5|dora_art6|dora_art8|dora_art10|dora_art11|dora_art17|dora_art28|dora_art30'}}, 'additionalProperties': False}
provider_country_risk
Enrich provider dependencies with OECD economic risk: GDP, unemployment, CLI per provider country. DORA Art. 28-31 relevant.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
readiness_check
Full DORA readiness score + Ampel per article. Returns GREEN/YELLOW/RED/GREY for all 26 articles, score 0-100, days until deadline.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID (optional)'}}, 'additionalProperties': False}
register_provider
Register an ICT third-party provider for DORA Art. 28 Register of Information. Stores provider data and creates evidence.
Input schema
{'type': 'object', 'properties': {'lei': {'type': 'string', 'description': 'Legal Entity Identifier'}, 'services': {'type': 'string', 'description': 'Services provided'}, 'entity_id': {'type': 'string'}, 'criticality': {'type': 'string', 'description': 'critical, important, standard'}, 'contract_end': {'type': 'string'}, 'headquarters': {'type': 'string', 'description': 'Country e.g. Luxembourg, Germany'}, 'data_location': {'type': 'string', 'description': 'Where data is stored e.g. EU (Frankfurt)'}, 'provider_name': {'type': 'string', 'description': 'Provider name e.g. Amazon Web Services EMEA SARL'}, 'provider_type': {'type': 'string', 'description': 'cloud_infrastructure, saas_application, core_banking, cybersecurity, etc.'}, 'certifications': {'type': 'string'}, 'contract_start': {'type': 'string'}, 'annual_cost_eur': {'type': 'number'}, 'substitutability': {'type': 'string'}}, 'additionalProperties': False}
regulation_impact
Show cross-regulation impacts for a specific DORA article. Maps DORA → MiCA + AMLR.
Input schema
{'type': 'object', 'properties': {'dora_article': {'type': 'string', 'description': 'DORA article ID (e.g. dora_art28)'}}, 'additionalProperties': False}
reg_watchdog
AI Regulatory Watchdog: scrapes EBA/ESMA/BaFin/CERT-Bund for DORA updates. Returns alerts with affected articles and severity. Run daily via cron or on-demand.
Input schema
{'type': 'object', 'properties': {'days_back': {'type': 'integer', 'description': 'Check items from last N days (default: 7)'}}, 'additionalProperties': False}
retest_finding
Re-test a finding: collect fresh evidence, reassess check, auto-close if GREEN. Full closed-loop.
Input schema
{'type': 'object', 'properties': {'finding_id': {'type': 'string', 'description': 'Finding ID to re-test'}}, 'additionalProperties': False}
run_escalation
Trigger escalation engine: auto-create findings, check SLA, escalate.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
run_trial_assessment
Run complete DORA+MiCA assessment for trial entity. Returns score, gaps, automation potential.
Input schema
{'type': 'object', 'properties': {'trial_id': {'type': 'string'}, 'entity_id': {'type': 'string'}}, 'additionalProperties': False}
score_trend
Score trend over time: weekly deltas, trajectory, peer benchmark. Shows improvement or decline.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
servicenow_sync
ServiceNow incident + change management sync. DORA Art. 17/21 evidence. Returns 30-day incident stats, classification, resolution rates.
Input schema
{'type': 'object', 'properties': {'days_back': {'type': 'integer', 'description': 'Days to look back (default 30)'}}, 'additionalProperties': False}
update_finding
Update finding lifecycle: claim, set remediation plan, request re-test, close, or accept risk. Status flow: open -> in_progress -> retest_pending -> closed | risk_accepted.
Input schema
{'type': 'object', 'properties': {'actor': {'type': 'string', 'description': 'Who is performing this action'}, 'owner': {'type': 'string', 'description': 'New owner (for claim)'}, 'action': {'type': 'string', 'description': 'claim | plan | request_retest | close | accept_risk'}, 'reason': {'type': 'string', 'description': 'Close reason (for close)'}, 'finding_id': {'type': 'string', 'description': 'Finding ID'}, 'accepted_by': {'type': 'string', 'description': 'Name (for accept_risk)'}, 'expiry_days': {'type': 'integer', 'description': 'Risk acceptance expiry days (default 90)'}, 'remediation_plan': {'type': 'string', 'description': 'Remediation plan text (for plan)'}}, 'additionalProperties': False}
whatif_provider
Simulate provider failure: which articles/checks are affected, score impact, risk level.
Input schema
{'type': 'object', 'properties': {'entity_id': {'type': 'string', 'description': 'Entity ID'}, 'provider_name': {'type': 'string', 'description': 'Provider name (e.g. AWS, Finastra)'}}, 'additionalProperties': False}
whatif_stale
Simulate stale evidence: what happens if a check stays stale for N days.
Input schema
{'type': 'object', 'properties': {'days': {'type': 'integer', 'description': 'Days stale (default 30)'}, 'check_id': {'type': 'string', 'description': 'Check ID'}, 'entity_id': {'type': 'string', 'description': 'Entity ID'}}, 'additionalProperties': False}
Added
generate_trial_report
Sept. 17, 2026, 12:53 p.m.
Added
run_trial_assessment
Sept. 17, 2026, 12:53 p.m.
Added
create_trial
Sept. 17, 2026, 12:53 p.m.
Added
policy_draft
Sept. 17, 2026, 12:53 p.m.
Added
cve_asset_map
Sept. 17, 2026, 12:53 p.m.
Added
bafin_approve_send
Sept. 17, 2026, 12:53 p.m.
Added
bafin_report_draft
Sept. 17, 2026, 12:53 p.m.
Added
regulation_impact
Sept. 17, 2026, 12:53 p.m.
Added
cross_regulation_check
Sept. 17, 2026, 12:53 p.m.
Added
contract_status
Sept. 17, 2026, 12:53 p.m.
Added
contract_analyze
Sept. 17, 2026, 12:53 p.m.
Added
contract_upload
Sept. 17, 2026, 12:53 p.m.
Added
provider_country_risk
Sept. 17, 2026, 12:53 p.m.
Added
evidence_pack
Sept. 17, 2026, 12:53 p.m.
Added
incident_flow
Sept. 17, 2026, 12:53 p.m.
Added
dependency_graph
Sept. 17, 2026, 12:53 p.m.
Added
score_trend
Sept. 17, 2026, 12:53 p.m.
Added
retest_finding
Sept. 17, 2026, 12:53 p.m.
Added
update_finding
Sept. 17, 2026, 12:53 p.m.
Added
board_summary
Sept. 17, 2026, 12:53 p.m.
Added
whatif_stale
Sept. 17, 2026, 12:53 p.m.
Added
whatif_provider
Sept. 17, 2026, 12:53 p.m.
Added
run_escalation
Sept. 17, 2026, 12:53 p.m.
Added
escalation_status
Sept. 17, 2026, 12:53 p.m.
Added
bus_status
Sept. 17, 2026, 12:53 p.m.
Added
ping
Sept. 17, 2026, 12:53 p.m.
Added
health_check
Sept. 17, 2026, 12:53 p.m.
Added
cross_oracle_assess
Sept. 17, 2026, 12:53 p.m.
Added
llm_clause_check
Sept. 17, 2026, 12:53 p.m.
Added
servicenow_sync
Sept. 17, 2026, 12:53 p.m.

Didit

io.github.pipeworx-io/didit

Provides identity and compliance capabilities including AML screening against sanctions and PEP lists, business verification, ben…

Compliance & Sanções

io.github.mcp-dir/compliance-mcp

Performs Brazilian due-diligence checks across PEP, sanctions, criminal, regulatory, fraud, tax, and government restriction datab…

WhiteIntel — Ownership Intelligence

dev.whiteintel/whiteintel

Resolves companies and people and maps ownership, beneficial ownership, sanctions, offshore exposure, financials, corporate filin…

outris-identity-mcp

io.github.outris-dev-user/outris-identity-mcp

Performs identity, KYC, fraud, business, phone, email, bank-account, PAN, GST, vehicle, and due-diligence lookups, including digi…

Ni Biashara Shelves — Africa FX, freight & compliance checks (x402)

biz.nibiashara/shelves

Provides African FX rates, freight carrier and broker authority checks, safety checks, OFAC sanctions screening, and Texas insura…

tlpt

io.tooloracle/tlpt

Supports TIBER-EU and DORA threat-led penetration testing with scenario generation, MITRE mapping, findings, evidence, scheduling…

Stipple — Document Verification & Extraction

sh.stipple/openwarrant

Inspects documents for authenticity, tampering, AI-generation indicators, extracted fields, citations, identity evidence, sanctio…

ContinueOps Public MCP

com.continueops/continueops-public

Provides compliance framework information, DORA readiness checks, business continuity plan structures, runbook templates, and res…