LaunchTrust MCP server
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
Little public usage data yet
Reviews
Write oneNobody has reviewed LaunchTrust yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
LaunchTrust tools (9, 2 write)
write = sends, deletes, buys or postsget_compliance_rulesFreeFetch LaunchTrust's sourced, founder-reviewed compliance rule snapshots, optionally filtered to one jurisdiction code (e.g. eu-ai-act-50, gdpr, ca-sb243). Compliance aid, not legal advice.
get_market_reportFreeGet the latest scan for one of your registered apps, with each finding annotated by the jurisdictions and rules applicable to that app's target markets. Requires a LaunchTrust token.
get_scan_historyFreeList recent scans (summary + findings) for one of your registered apps. Requires a LaunchTrust token.
list_jurisdictionsFreeList the jurisdictions and categories LaunchTrust tracks (e.g. EU AI Act, GDPR, US state privacy laws, app-store policies). Public coverage registry. Compliance aid, not legal advice.
list_my_appsFreeList the apps registered in your LaunchTrust account, with each one's latest scan status. Requires a LaunchTrust token.
register_appFreeRegister a web URL in your LaunchTrust account so it can be fully scanned and monitored. Idempotent — if the URL is already registered, returns the existing app. Requires a LaunchTrust token and an active subscription.
scan_appwrite actionFreeRun the full LaunchTrust scan on one of your registered apps and store a signed, dated evidence record. Requires a LaunchTrust token and an active subscription. Limited to 5 scans per app per day.
scan_urlwrite actionFreeRun a FREE LaunchTrust compliance + security quick-scan on a public web URL. Returns a focused SUBSET of checks — leaked frontend secrets/API keys, exposed .env//.git, security headers, HTTPS/HSTS, missing privacy/terms pages, trackers/cookie banner, and AI-interaction disclosure. The result is unsigned and not stored. The full 27-detector signed, dated, continuously-monitored scan requires a LaunchTrust account. Compliance aid, not legal advice.
verify_recordFreeIndependently verify the ECDSA (ES256) signature on a LaunchTrust signed scan/disclosure record against the published public key. Pass the record JSON (the downloaded record, or an object containing `canonical` and `signature`).
Public scan report
scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 153ms20/20
- Tool poisoning9 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 2 write-action tools with no auth3/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Findings (1)
- highWrite-action tools reachable without authentication
auth.open-write
Install directly
claude mcp add --transport http launchtrust https://mcp.launchtrust.co/mcp
LaunchTrust: common questions
- Is LaunchTrust MCP server safe?
- With care: it is graded C, so read the findings first (57/100). Read the LaunchTrust safety report
- How do I install LaunchTrust?
- It runs remotely at mcp.launchtrust.co. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does LaunchTrust need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is LaunchTrust maintained?
- The latest release is v0.1.0.
- Is LaunchTrust up?
- 100% of our last 28 checks got an answer. We check remote servers about four times a day.
- What can I use instead of LaunchTrust?
- Servers from other publishers that do the same job: MCP server, Security Headers Csp Lint MCP server and Solana Security Standard MCP server. Compare all LaunchTrust alternatives.
Alternatives to LaunchTrust
Same job from other publishers: the closest match first, then the best rated.
- MCPSecurity tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.not reviewedGrowingA
- Security Headers Csp LintReads security headers and CSP line by line in your config file and names the lines that silently donot reviewedGrowingA
- Solana Security StandardScan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.not reviewedGrowingA
- pkgxrayPre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.not reviewedGrowingB
MCP ZAP ServerSafe, self-hosted OWASP ZAP operator for guided AI security scans and reports.not reviewedGrowingB