Security & Compliance MCP servers
Code scanning, dependency checks, secrets and compliance tooling.
Updated 4 Oct 2026
Access
23 serversClear filters
Results
-
Sign-in (You sign in with the vendor the first time you connect)
Android Management API, verified
by GoogleRead Android Enterprise devices, policies, apps and web apps to audit device fleets and policy compliance.
mcp.tc/i/android-management -
Sign-in (You sign in with the vendor the first time you connect)
Inspect Arcjet security decisions, bot and attack traffic, and remote rules, and manage sites and rules from your AI assistant.
mcp.tc/i/arcjet -
Local (Runs on your machine: its page has the install command)
Auth0, verified
by Auth0 (Okta)Manage Auth0 applications, APIs, actions, logs, forms and client grants in your tenant using natural language.
mcp.tc/i/auth0 -
Local (Runs on your machine: its page has the install command)
Black Duck Signal
by Black DuckScan code changes or specific files for security vulnerabilities with Black Duck Signal AI analysis, from your coding assistant.
mcp.tc/i/black-duck -
Local (Runs on your machine: its page has the install command)
Burp Suite
by PortSwiggerDrive Burp Suite from AI clients through an extension that exposes Burp over MCP, with an SSE endpoint and a bundled stdio proxy.
mcp.tc/i/burp-suite -
Local (Runs on your machine: its page has the install command)
CrowdStrike Falcon, verified
by CrowdStrikeQuery CrowdStrike Falcon detections, hosts, threat intel, vulnerabilities and more from your AI assistant.
mcp.tc/i/crowdstrike-falcon -
Sign-in (You sign in with the vendor the first time you connect)
Scan code for leaked secrets, manage security incidents and create honeytokens with GitGuardian's detectors.
mcp.tc/i/gitguardian -
Local (Runs on your machine: its page has the install command)
IDA Pro MCP
by mrexodiaReverse engineer binaries in IDA Pro: decompile, rename, comment and retype functions through your AI assistant.
mcp.tc/i/ida-pro -
Sign-in (You sign in with the vendor the first time you connect)
Manage JumpCloud users, devices, groups and other directory resources from your AI assistant.
mcp.tc/i/jumpcloud -
Sign-in (You sign in with the vendor the first time you connect)
Microsoft MCP Server for Enterprise, verified
by MicrosoftQuery Microsoft Entra tenant data such as users, groups, apps and devices in natural language through Microsoft Graph.
mcp.tc/i/microsoft-entra -
Sign-in (You sign in with the vendor the first time you connect)
Microsoft Sentinel Data Exploration, verified
by MicrosoftSearch for relevant tables and retrieve security data from the Microsoft Sentinel data lake using natural language.
mcp.tc/i/microsoft-sentinel -
Local (Runs on your machine: its page has the install command)
Manage Okta users, groups, applications, policies and system logs from your assistant using natural language.
mcp.tc/i/okta -
Sign-in (You sign in with the vendor the first time you connect)
Scan code for security issues and bugs with Semgrep static analysis rules from your AI assistant.
mcp.tc/i/semgrep -
Local (Runs on your machine: its page has the install command)
Scan code, dependencies, containers, IaC and secrets for vulnerabilities with Snyk from your AI assistant.
mcp.tc/i/snyk -
Local (Runs on your machine: its page has the install command)
Snyk API & Web
by SnykOnboard scan targets, run DAST scans and triage vulnerability findings in Snyk API & Web from your AI assistant.
mcp.tc/i/snyk-api-web -
No sign-in (No account or key needed)
Check supply-chain security scores for npm, PyPI, Maven, Go and other packages, and inspect package files before installing.
mcp.tc/i/socket -
Local (Runs on your machine: its page has the install command)
SonarQube, verified
by SonarSourceCheck code quality and security issues, quality gates and code snippets with SonarQube Server or SonarQube Cloud from your AI assistant.
mcp.tc/i/sonarqube -
API key (Needs an API key from the vendor)
SonarQube Cloud, verified
by SonarSourceQuery code quality and security issues, quality gates, hotspots and metrics from SonarQube Cloud in your AI assistant.
mcp.tc/i/sonarqube-cloud -
API key (Needs an API key from the vendor)
Sonatype Guide
by SonatypeLook up open-source component versions, vulnerabilities and Trust Score upgrade recommendations from Sonatype.
mcp.tc/i/sonatype -
Local (Runs on your machine: its page has the install command)
Set up StackHawk, run security scans and triage findings from your IDE or chat.
mcp.tc/i/stackhawk -
Sign-in (You sign in with the vendor the first time you connect)
Query Vanta controls, failing tests, vendors and compliance data, and remediate failing tests from your AI assistant.
mcp.tc/i/vanta -
Sign-in (You sign in with the vendor the first time you connect)
Manage WorkOS organizations, users, SSO connections, Directory Sync and AuthKit branding from your assistant.
mcp.tc/i/workos -
Local (Runs on your machine: its page has the install command)
Zscaler Zero Trust Exchange
by ZscalerManage Zscaler Zero Trust Exchange services such as ZPA, ZIA, ZDX and ZCC through more than 400 tools, read-only by default.
mcp.tc/i/zscaler-zero-trust-exchange No servers match. Try a vendor name such as “Cloudflare”, or clear the filters. If it’s an MCP server we haven’t listed yet, submit its URL.