{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_4kux26jzdwsr","handle":"costrinity-vitna-compliance-mcp","url":"https://wellknown.network/agents/costrinity-vitna-compliance-mcp","links":{"self":"https://wellknown.network/agents/costrinity-vitna-compliance-mcp/record.json","html":"https://wellknown.network/agents/costrinity-vitna-compliance-mcp","markdown":"https://wellknown.network/agents/costrinity-vitna-compliance-mcp/record.md","api":"https://wellknown.network/api/v1/agents/costrinity-vitna-compliance-mcp","status":"https://wellknown.network/api/v1/agents/costrinity-vitna-compliance-mcp/status","claim":"https://wellknown.network/agents/costrinity-vitna-compliance-mcp/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/costrinity-vitna-compliance-mcp/claim.json","badge":"https://wellknown.network/agents/costrinity-vitna-compliance-mcp/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/costrinity-vitna-compliance-mcp/history","tools":"https://wellknown.network/api/v1/agents/costrinity-vitna-compliance-mcp/tools"},"ard":{"identifier":"urn:air:vitna.costrinity.xyz:server:costrinity-vitna-compliance-mcp","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"VITNA – Containment for rogue AI agents","summary":"Wraps stdio MCP servers. Risky calls wait for a person; no answer, no run. Signed records.","description":"Wraps stdio MCP servers. Risky calls wait for a person; no answer, no run. Signed records.","publisher":{"name":"xyz.costrinity","url":null},"homepage":"https://vitna.costrinity.xyz","repository":"https://github.com/COSTRINITY/vitna-compliance-mcp","version":"0.5.4","license":"MIT","protocols":["mcp"],"tags":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"pricing":null,"endpoints":[{"url":"https://vitna.costrinity.xyz/api/mcp","type":"mcp_streamable_http","auth":null,"probeable":true},{"url":"npm:@costrinity/vitna-compliance-mcp","type":"package_npm","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-10-07T04:43:14.476785Z","npmKeywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"publishedAt":"2026-10-07T04:43:14.476785Z","registryName":"xyz.costrinity/vitna-compliance-preflight"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","license":"npm","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"communication.notifications","name":"Notifications","confidence":0.583,"provenance":"derived"},{"slug":"dev.filesystem","name":"Filesystem","confidence":0.54,"provenance":"derived"},{"slug":"dev.docs-lookup","name":"Documentation Lookup","confidence":0.54,"provenance":"derived"},{"slug":"analytics.reporting","name":"Reporting & Dashboards","confidence":0.54,"provenance":"derived"},{"slug":"ai.agent-discovery","name":"Agent Discovery","confidence":0.54,"provenance":"derived"},{"slug":"data.database","name":"Databases","confidence":0.525,"provenance":"derived"}],"categories":["ai","analytics","communication","data","dev"],"language":"fr"},"observed":{"status":"unavailable","statusReason":"5 consecutive checks failed; last success 10d ago.","lastOkAt":"2026-09-30T15:27:13.375Z","lastProbedAt":"2026-10-08T23:22:05.436Z","statusComputedAt":"2026-10-08T23:24:03.922Z","reliability30d":{"probes":79,"successRate":0.9367,"p50Ms":328,"basis":"service","measures":{"availability":"availability","latency":"response time","tools":"tool surface observed","summary":"Checks reached the service itself."},"checks":{"total":77,"ok":72,"authBoundaryOk":0,"serviceOk":72,"note":"Counted from the observation rows for the window, checks of the server only (HTTP, A2A card, MCP initialize). ok = authBoundaryOk + serviceOk. `probes` is the sum of daily rollups and includes registry checks, so it can differ from `total`."}},"latestObservations":[{"at":"2026-10-08T23:22:05.436Z","kind":"http_head","ok":false,"httpStatus":null,"latencyMs":null,"error":"disallowed by robots.txt","detail":null},{"at":"2026-10-04T16:31:40.783Z","kind":"http_head","ok":false,"httpStatus":null,"latencyMs":null,"error":"disallowed by robots.txt","detail":null},{"at":"2026-10-02T12:29:10.457Z","kind":"http_head","ok":false,"httpStatus":null,"latencyMs":null,"error":"disallowed by robots.txt","detail":null},{"at":"2026-10-01T10:30:26.788Z","kind":"http_head","ok":false,"httpStatus":null,"latencyMs":null,"error":"disallowed by robots.txt","detail":null},{"at":"2026-09-30T21:27:18.728Z","kind":"http_head","ok":false,"httpStatus":null,"latencyMs":null,"error":"disallowed by robots.txt","detail":null},{"at":"2026-09-30T15:27:13.375Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":919,"error":null,"detail":{"tools":[{"name":"vitna_help","description":"What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check ris"},{"name":"vitna_claim","description":"Ask whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account, w"},{"name":"consent_check","description":"Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and opt"},{"name":"breach_classify","description":"After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories, se"},{"name":"ai_act_classify","description":"Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric / remote-identifi"},{"name":"dpia_threshold_check","description":"Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data categori"},{"name":"us_sectoral_check","description":"Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given processing"},{"name":"india_sectoral_check","description":"Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT / PF"},{"name":"india_cross_border_status","description":"Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI / SE"},{"name":"japan_cross_border_status","description":"Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the ISO-316"},{"name":"us_state_breach_deadline","description":"Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without unr"},{"name":"aadhaar_mask","description":"Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless valid"},{"name":"pan_classify","description":"Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard ti"},{"name":"gstin_validate","description":"Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"cpf_validate","description":"Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"sin_validate","description":"Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"iban_validate","description":"Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"pii_test","description":"Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether sever"},{"name":"privacy_notice_get","description":"Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard timeli"},{"name":"sub_processors_register","description":"Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace."},{"name":"global_compliance_map","description":"Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision a"},{"name":"india_regulators_directory","description":"Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup o"},{"name":"vitna_preflight","description":"SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the "}],"toolCount":23,"toolsHash":"bd483ba456975b8c811f38e90510e44ee856eff12caf62032d58db50298c86d6","serverName":"vitna-compliance","capabilities":["tools"],"serverVersion":"0.5.0","protocolVersion":"2025-03-26"}},{"at":"2026-09-30T09:25:05.325Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":176,"error":null,"detail":{"tools":[{"name":"vitna_help","description":"What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check ris"},{"name":"vitna_claim","description":"Ask whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account, w"},{"name":"consent_check","description":"Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and opt"},{"name":"breach_classify","description":"After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories, se"},{"name":"ai_act_classify","description":"Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric / remote-identifi"},{"name":"dpia_threshold_check","description":"Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data categori"},{"name":"us_sectoral_check","description":"Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given processing"},{"name":"india_sectoral_check","description":"Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT / PF"},{"name":"india_cross_border_status","description":"Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI / SE"},{"name":"japan_cross_border_status","description":"Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the ISO-316"},{"name":"us_state_breach_deadline","description":"Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without unr"},{"name":"aadhaar_mask","description":"Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless valid"},{"name":"pan_classify","description":"Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard ti"},{"name":"gstin_validate","description":"Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"cpf_validate","description":"Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"sin_validate","description":"Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"iban_validate","description":"Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"pii_test","description":"Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether sever"},{"name":"privacy_notice_get","description":"Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard timeli"},{"name":"sub_processors_register","description":"Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace."},{"name":"global_compliance_map","description":"Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision a"},{"name":"india_regulators_directory","description":"Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup o"},{"name":"vitna_preflight","description":"SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the "}],"toolCount":23,"toolsHash":"bd483ba456975b8c811f38e90510e44ee856eff12caf62032d58db50298c86d6","serverName":"vitna-compliance","capabilities":["tools"],"serverVersion":"0.5.0","protocolVersion":"2025-03-26"}},{"at":"2026-09-30T02:24:15.014Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":151,"error":null,"detail":{"tools":[{"name":"vitna_help","description":"What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check ris"},{"name":"vitna_claim","description":"Ask whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account, w"},{"name":"consent_check","description":"Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and opt"},{"name":"breach_classify","description":"After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories, se"},{"name":"ai_act_classify","description":"Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric / remote-identifi"},{"name":"dpia_threshold_check","description":"Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data categori"},{"name":"us_sectoral_check","description":"Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given processing"},{"name":"india_sectoral_check","description":"Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT / PF"},{"name":"india_cross_border_status","description":"Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI / SE"},{"name":"japan_cross_border_status","description":"Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the ISO-316"},{"name":"us_state_breach_deadline","description":"Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without unr"},{"name":"aadhaar_mask","description":"Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless valid"},{"name":"pan_classify","description":"Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard ti"},{"name":"gstin_validate","description":"Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"cpf_validate","description":"Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"sin_validate","description":"Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"iban_validate","description":"Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"pii_test","description":"Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether sever"},{"name":"privacy_notice_get","description":"Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard timeli"},{"name":"sub_processors_register","description":"Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace."},{"name":"global_compliance_map","description":"Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision a"},{"name":"india_regulators_directory","description":"Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup o"},{"name":"vitna_preflight","description":"SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the "}],"toolCount":23,"toolsHash":"bd483ba456975b8c811f38e90510e44ee856eff12caf62032d58db50298c86d6","serverName":"vitna-compliance","capabilities":["tools"],"serverVersion":"0.5.0","protocolVersion":"2025-03-26"}},{"at":"2026-09-29T20:25:21.491Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":199,"error":null,"detail":{"tools":[{"name":"vitna_help","description":"What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check ris"},{"name":"vitna_claim","description":"Ask whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account, w"},{"name":"consent_check","description":"Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and opt"},{"name":"breach_classify","description":"After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories, se"},{"name":"ai_act_classify","description":"Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric / remote-identifi"},{"name":"dpia_threshold_check","description":"Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data categori"},{"name":"us_sectoral_check","description":"Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given processing"},{"name":"india_sectoral_check","description":"Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT / PF"},{"name":"india_cross_border_status","description":"Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI / SE"},{"name":"japan_cross_border_status","description":"Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the ISO-316"},{"name":"us_state_breach_deadline","description":"Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without unr"},{"name":"aadhaar_mask","description":"Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless valid"},{"name":"pan_classify","description":"Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard ti"},{"name":"gstin_validate","description":"Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"cpf_validate","description":"Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"sin_validate","description":"Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"iban_validate","description":"Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"pii_test","description":"Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether sever"},{"name":"privacy_notice_get","description":"Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard timeli"},{"name":"sub_processors_register","description":"Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace."},{"name":"global_compliance_map","description":"Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision a"},{"name":"india_regulators_directory","description":"Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup o"},{"name":"vitna_preflight","description":"SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the "}],"toolCount":23,"toolsHash":"bd483ba456975b8c811f38e90510e44ee856eff12caf62032d58db50298c86d6","serverName":"vitna-compliance","capabilities":["tools"],"serverVersion":"0.5.0","protocolVersion":"2025-03-26"}},{"at":"2026-09-29T13:25:24.955Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":163,"error":null,"detail":{"tools":[{"name":"vitna_help","description":"What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check ris"},{"name":"vitna_claim","description":"Ask whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account, w"},{"name":"consent_check","description":"Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and opt"},{"name":"breach_classify","description":"After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories, se"},{"name":"ai_act_classify","description":"Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric / remote-identifi"},{"name":"dpia_threshold_check","description":"Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data categori"},{"name":"us_sectoral_check","description":"Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given processing"},{"name":"india_sectoral_check","description":"Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT / PF"},{"name":"india_cross_border_status","description":"Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI / SE"},{"name":"japan_cross_border_status","description":"Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the ISO-316"},{"name":"us_state_breach_deadline","description":"Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without unr"},{"name":"aadhaar_mask","description":"Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless valid"},{"name":"pan_classify","description":"Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard ti"},{"name":"gstin_validate","description":"Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"cpf_validate","description":"Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"sin_validate","description":"Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"iban_validate","description":"Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"pii_test","description":"Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether sever"},{"name":"privacy_notice_get","description":"Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard timeli"},{"name":"sub_processors_register","description":"Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace."},{"name":"global_compliance_map","description":"Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision a"},{"name":"india_regulators_directory","description":"Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup o"},{"name":"vitna_preflight","description":"SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the "}],"toolCount":23,"toolsHash":"bd483ba456975b8c811f38e90510e44ee856eff12caf62032d58db50298c86d6","serverName":"vitna-compliance","capabilities":["tools"],"serverVersion":"0.5.0","protocolVersion":"2025-03-26"}}],"tools":[{"name":"vitna_help","description":"What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check ris"},{"name":"vitna_claim","description":"Ask whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account, w"},{"name":"consent_check","description":"Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and opt"},{"name":"breach_classify","description":"After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories, se"},{"name":"ai_act_classify","description":"Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric / remote-identifi"},{"name":"dpia_threshold_check","description":"Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data categori"},{"name":"us_sectoral_check","description":"Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given processing"},{"name":"india_sectoral_check","description":"Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT / PF"},{"name":"india_cross_border_status","description":"Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI / SE"},{"name":"japan_cross_border_status","description":"Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the ISO-316"},{"name":"us_state_breach_deadline","description":"Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without unr"},{"name":"aadhaar_mask","description":"Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless valid"},{"name":"pan_classify","description":"Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard ti"},{"name":"gstin_validate","description":"Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"cpf_validate","description":"Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"sin_validate","description":"Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"iban_validate","description":"Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace."},{"name":"pii_test","description":"Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether sever"},{"name":"privacy_notice_get","description":"Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard timeli"},{"name":"sub_processors_register","description":"Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace."},{"name":"global_compliance_map","description":"Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision a"},{"name":"india_regulators_directory","description":"Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup o"},{"name":"vitna_preflight","description":"SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the "}],"package":{"name":"@costrinity/vitna-compliance-mcp","registry":"npm","observedAt":"2026-10-10T08:19:03.780Z","publishedAt":"2026-10-07T04:33:03.376Z","latestVersion":"0.5.4","weeklyDownloads":268},"toolSurface":{"id":"ts_x2bgufwunfmu","endpointId":"ep_4g9xcxf4sw37","hash":"bd483ba456975b8c811f38e90510e44ee856eff12caf62032d58db50298c86d6","toolCount":23,"serverName":"vitna-compliance","serverVersion":"0.3.7","protocolVersion":"2025-03-26","firstSeenAt":"2026-09-12T13:26:57.467Z","lastSeenAt":"2026-09-30T15:27:13.390Z","observations":66,"toolNames":["vitna_help","vitna_claim","consent_check","breach_classify","ai_act_classify","dpia_threshold_check","us_sectoral_check","india_sectoral_check","india_cross_border_status","japan_cross_border_status","us_state_breach_deadline","aadhaar_mask","pan_classify","gstin_validate","cpf_validate","sin_validate","iban_validate","pii_test","privacy_notice_get","sub_processors_register","global_compliance_map","india_regulators_directory","vitna_preflight"],"distinctSurfaces":1},"endpointFacts":[{"id":"ep_4g9xcxf4sw37","url":"https://vitna.costrinity.xyz/api/mcp","type":"mcp_streamable_http","factsCheckedAt":"2026-10-08T23:22:05.440Z","auth":{"observedAt":"2026-09-29T20:25:21.518Z","authRequired":false,"scheme":null,"resourceMetadata":null,"authorizationServer":null,"conformance":{"dpop":false,"rfc8414":false,"rfc9728":false,"pkceS256":false,"clientIdMetadataDocument":false,"dynamicClientRegistration":false}},"tls":{"observedAt":"2026-10-08T23:22:05.466Z","protocol":"TLSv1.3","chainValid":true,"chainError":null,"hostMatches":true,"subject":"vitna.costrinity.xyz","issuer":{"commonName":"YR1","organization":"Let's Encrypt"},"validFrom":"2026-09-24T11:27:23.000Z","validTo":"2026-12-23T11:27:22.000Z","daysToExpiry":73,"sanCount":1,"fingerprint256":"36:B3:2D:BE:CD:71:27:39:2F:AD:CC:16:16:CF:06:7F:D9:46:1D:A1:BC:89:1E:CC:C7:F0:8A:96:E9:F1:8D:49"}}]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"npm","key":"@costrinity/vitna-compliance-mcp","url":"https://www.npmjs.com/package/@costrinity/vitna-compliance-mcp","firstSeenAt":"2026-09-05T23:20:19.052Z","fetchedAt":"2026-10-10T08:18:58.155Z","normalizedAt":"2026-10-10T08:18:58.155Z"},{"source":"mcp_registry","key":"xyz.costrinity/vitna-compliance-preflight","url":"https://registry.modelcontextprotocol.io/v0/servers/xyz.costrinity%2Fvitna-compliance-preflight","firstSeenAt":"2026-09-07T09:23:20.650Z","fetchedAt":"2026-10-08T21:19:54.336Z","normalizedAt":"2026-10-08T21:19:54.336Z"}]},"firstSeenAt":"2026-09-05T23:20:19.052Z","updatedAt":"2026-10-10T08:19:03.780Z"}