Security & Compliance MCP servers

Code scanning, dependency checks, secrets and compliance tooling.

Updated 4 Oct 2026

23 servers

Results

  • Read Android Enterprise devices, policies, apps and web apps to audit device fleets and policy compliance.

    Sign-in (You sign in with the vendor the first time you connect)
    mcp.tc/i/android-management
  • Inspect Arcjet security decisions, bot and attack traffic, and remote rules, and manage sites and rules from your AI assistant.

    Sign-in (You sign in with the vendor the first time you connect)
    mcp.tc/i/arcjet
  • Auth0, verified

    by Auth0 (Okta)

    Manage Auth0 applications, APIs, actions, logs, forms and client grants in your tenant using natural language.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/auth0
  • Black Duck Signal

    by Black Duck

    Scan code changes or specific files for security vulnerabilities with Black Duck Signal AI analysis, from your coding assistant.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/black-duck
  • Burp Suite

    by PortSwigger

    Drive Burp Suite from AI clients through an extension that exposes Burp over MCP, with an SSE endpoint and a bundled stdio proxy.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/burp-suite
  • Query CrowdStrike Falcon detections, hosts, threat intel, vulnerabilities and more from your AI assistant.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/crowdstrike-falcon
  • Scan code for leaked secrets, manage security incidents and create honeytokens with GitGuardian's detectors.

    Sign-in (You sign in with the vendor the first time you connect)
    mcp.tc/i/gitguardian
  • IDA Pro MCP

    by mrexodia

    Reverse engineer binaries in IDA Pro: decompile, rename, comment and retype functions through your AI assistant.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/ida-pro
  • Manage JumpCloud users, devices, groups and other directory resources from your AI assistant.

    Sign-in (You sign in with the vendor the first time you connect)
    mcp.tc/i/jumpcloud
  • Query Microsoft Entra tenant data such as users, groups, apps and devices in natural language through Microsoft Graph.

    Sign-in (You sign in with the vendor the first time you connect)
    mcp.tc/i/microsoft-entra
  • Search for relevant tables and retrieve security data from the Microsoft Sentinel data lake using natural language.

    Sign-in (You sign in with the vendor the first time you connect)
    mcp.tc/i/microsoft-sentinel
  • Manage Okta users, groups, applications, policies and system logs from your assistant using natural language.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/okta
  • Scan code for security issues and bugs with Semgrep static analysis rules from your AI assistant.

    Sign-in (You sign in with the vendor the first time you connect)
    mcp.tc/i/semgrep
  • Scan code, dependencies, containers, IaC and secrets for vulnerabilities with Snyk from your AI assistant.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/snyk
  • Onboard scan targets, run DAST scans and triage vulnerability findings in Snyk API & Web from your AI assistant.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/snyk-api-web
  • Check supply-chain security scores for npm, PyPI, Maven, Go and other packages, and inspect package files before installing.

    No sign-in (No account or key needed)
    mcp.tc/i/socket
  • SonarQube, verified

    by SonarSource

    Check code quality and security issues, quality gates and code snippets with SonarQube Server or SonarQube Cloud from your AI assistant.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/sonarqube
  • Query code quality and security issues, quality gates, hotspots and metrics from SonarQube Cloud in your AI assistant.

    API key (Needs an API key from the vendor)
    mcp.tc/i/sonarqube-cloud
  • Sonatype Guide

    by Sonatype

    Look up open-source component versions, vulnerabilities and Trust Score upgrade recommendations from Sonatype.

    API key (Needs an API key from the vendor)
    mcp.tc/i/sonatype
  • Set up StackHawk, run security scans and triage findings from your IDE or chat.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/stackhawk
  • Query Vanta controls, failing tests, vendors and compliance data, and remediate failing tests from your AI assistant.

    Sign-in (You sign in with the vendor the first time you connect)
    mcp.tc/i/vanta
  • Manage WorkOS organizations, users, SSO connections, Directory Sync and AuthKit branding from your assistant.

    Sign-in (You sign in with the vendor the first time you connect)
    mcp.tc/i/workos
  • Manage Zscaler Zero Trust Exchange services such as ZPA, ZIA, ZDX and ZCC through more than 400 tools, read-only by default.

    Local (Runs on your machine: its page has the install command)
    mcp.tc/i/zscaler-zero-trust-exchange