Mmcp.market

Sovereignty Scan MCP server

online · 100% uptime
by kajaril·io.github.kajaril/sovereignty-scan-mcp·v0.1.2·1 stars

EU AI Act sovereignty scanning. Provider residency, registration status, audit trail support.

B83/100grade B
What users say
No reviews yet
Be the first
Safety scan
B83/100

full report

Adoption
Growing

1 stars

Reviews

Write one

Nobody has reviewed Sovereignty Scan yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Sovereignty Scan tools

Tool list not cached yet. `describe` through the gateway fetches it live.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • –Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 115ms (auth required)20/20
  • –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
  • Auth qualityauth enforced (unknown)9/15
  • Maintenancelast push 18 days ago15/15
  • Maintainer identityregistry namespace matches repository owner6/10
Overall 83/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Sovereignty Scan in Claude Code, Cursor or VS Code

claude mcp add --transport http sovereignty-scan-mcp https://sovereignty-scan.kajaril.com/mcp
Add to Cursor

What the publisher says

From the Sovereignty Scan repository's README, as published. We do not edit it. Read it on GitHub

@kajaril/sovereignty-scan-mcp

MCP server for EU AI Act vendor sovereignty scanning. MIT-licensed free tier.

Know where your stack processes data before the enforcer does. Covers 55 providers across 12 categories.

Install

1. Get a free API key

curl -s -X POST https://sovereignty-scan.kajaril.com/register \
  -H "Content-Type: application/json" \
  -d '{"email":"you@example.com"}' | jq .api_key

Save the returned key — it cannot be recovered.

2. Add to claudedesktopconfig.json

{
  "mcpServers": {
    "sovereignty-scan": {
      "type": "http",
      "url": "https://sovereignty-scan.kajaril.com/mcp",
      "headers": {
        "Authorization": "Bearer ks_free_YOUR_KEY"
      }
    }
  }
}

Restart Claude Desktop.

Client compatibility

Quick test

Verify the endpoint is live:

curl -s https://sovereignty-scan.kajaril.com/health | jq .

Call a tool with your key:

curl -s -X POST https://sovereignty-scan.kajaril.com/mcp \
  -H "Authorization: Bearer ks_free_YOUR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"scan_provider","arguments":{"name":"cloudflare"}}}' \
  | jq .

Tools

scanprovider** — Full jurisdictional profile for a single vendor: headquarters country, data residency regions, EU residency option, US CLOUD Act exposure, GDPR DPA availability, and legal framework.

  • name — string, case-insensitive

Example response:

{
  "name": "Cloudflare",
  "hq_country": "US",
  "data_residency_regions": ["US", "EU", "APAC"],
  "eu_residency_option": true,
  "us_cloud_act_subject": true,
  "gdpr_dpa_available": true,
  "legal_framework": "GDPR+SCC"
}

scanstack** — Aggregate jurisdictional summary for a list of vendors: CLOUD Act exposure count, EU residency coverage, missing DPAs. Maximum 50 providers per call.

  • providers — string[], max 50

listproviders** — List all tracked providers. Optional category filter.

  • category? — AI · Hosting · Database · Auth · Analytics · Observability · CI/CD · Communications · Payments · Search · Sandbox · Cache

getuscloudactproviders — All providers subject to US CLOUD Act compelled disclosure (18 U.S.C. § 2713). No parameters.

suggesteualternatives — EU/EEA/UK/CH-based alternatives in the same category as a given provider. Deterministic ordering: EU/EEA first, then UK/CH. Capped at 10.

  • provider_name — string, case-insensitive

Pricing

Paid tier notifications: studio@kajaril.com

Self-hosting

Requires a Cloudflare account (Workers + D1 + KV).

1. Clone and install

git clone https://github.com/mightbesaad/sovereignty-scan-mcp
cd sovereignty-scan-mcp
npm install

2. Create infrastructure

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Sovereignty Scan: common questions

Is Sovereignty Scan MCP server safe?
Mostly: it is graded B (83/100). Read the Sovereignty Scan safety report
How do I install Sovereignty Scan?
It runs remotely at sovereignty-scan.kajaril.com. Add it to Claude Code, Cursor, VS Code or Claude Desktop with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Sovereignty Scan need an API key?
Yes. The endpoint refuses requests without credentials; the publisher's docs say how to get them.
Is Sovereignty Scan maintained?
The last commit was 18 days ago (2026-09-10). The latest release is v0.1.2.
Is Sovereignty Scan up?
100% of our last 28 checks got an answer. We check remote servers about four times a day.
What can I use instead of Sovereignty Scan?
Servers from other publishers that do the same job: Healthclaw Guardrails MCP server, Kastell MCP server and Bastion MCP server. Compare all Sovereignty Scan alternatives.

Alternatives to Sovereignty Scan

Same job from other publishers: the closest match first, then the best rated.

All Sovereignty Scan alternatives →
  • Healthclaw Guardrails
    Guardrailed FHIR access for AI agents: PHI redaction, audit trail, step-up auth, tenant isolation
    A
  • Kastell
    Server security audit (413 checks), hardening, and fleet management across 4 cloud providers.
    B
  • Bastion
    Reliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.
    A
  • mcp-audit
    Scan, enumerate, and risk-score every MCP server configured on your machine.
    A
  • Wireshark
    Professional network analysis with tshark. Security audits, deep-dives, and threat detection.
    A

More from kajaril →