Headless Compliance · MCP

Headless compliance.
Run by your AI agent.

Strac Comply's MCP server. Connect Claude Code, Cursor, or any MCP-aware client — and let your AI agent build and maintain your SOC 2 binder. No dashboard required.

bashrun before starting Claude Code
claude mcp add --transport http --scope user strac-comply \  https://mcp.comply.strac.io/mcp

Run this before you launch Claude Code (MCP config loads at startup). Then, in a session, run /mcpAuthenticate once. --scope user keeps it available in every session, not just the current folder.

How it connects

Three steps from zero to your AI agent writing evidence into your binder.

  1. 01

    Run the connect command

    Pick your client tab above and paste the snippet into Claude Code, Claude Desktop, Cursor, or any MCP-aware client. The client opens your browser to mcp.comply.strac.io for consent.

  2. 02

    Sign in & pick scopes

    Sign in with the same account you use for the web app. Choose which scopes the AI gets: compliance:read, policies:write, documents:write, and more. Scopes are revocable from Settings.

  3. 03

    Your AI agent does the work

    The agent reads your live compliance state — controls, policies, documents, test results, employees, audits — and writes evidence back to your binder. Every action lands in an append-only audit log with the AI's identity stamped on it.

What your AI agent can do

Every tool below is a real MCP method on mcp.comply.strac.io.

  • Answer compliance questions

    tool

    “Where are we on SOC 2 CC6?” — your AI reads live controls, policies, and test evidence, then answers grounded in your real posture, not generic advice.

    ask_compliance_question

  • Read your full compliance state

    tool

    Controls, policies, documents, audits, test results, employees — the AI can list and drill into every surface. Filtered by scope; partitioned by your tenant.

    list_controls · list_policies · list_tests

  • Write policies and evidence

    tool

    Draft policies, upload new versions, attach evidence to controls, mark controls Not Applicable with justifications. Every write emits an audit-log row attributing the change to the AI.

    upload_policy · attach_evidence · mark_control_na

  • Connect your integrations

    tool

    Hand the AI a connect-button for Google Workspace, AWS, or Slack. The customer authorizes in the browser; the AI polls until the integration is live and starts pulling evidence.

    connect_integration · get_connection_status

  • Migrate off your current GRC platform

    tool

    Export from Vanta, Drata, or Secureframe, point your AI at the folder, and the installed strac-import playbook migrates policies, vendors, risks, evidence — even historic test runs — in one run. Idempotent and safe to re-run.

    import_vendors · import_risks · import_test_runs

  • Run and triage automated tests

    tool

    Re-run a failing compliance test after a fix, watch the execution to completion, and propose accept-risk exceptions — the AI drafts the justification, a human approves it in the app.

    rerun_test · get_test_execution · acknowledge_test

  • Manage vendor risk

    tool

    Run the deterministic vendor risk assessment (one vendor or the whole list), record completed security reviews, and file a vendor's SOC 2 report or DPA into the binder — every action marked agent-recorded.

    run_vendor_risk_assessments · record_vendor_security_review

  • Reply to your auditor

    tool

    List open evidence requests, prepare a draft reply from binder evidence or a fresh upload, then submit — prepare and send are separate steps, so the auditor is never emailed by accident.

    list_audit_requests · submit_audit_request_response

Works with your AI client

Standard MCP transport. Drop in your client's config and reload.

Claude CodeClaude DesktopCursorContinueClineWindsurf

Ready to ship faster?

Built for SOC 2, ISO 27001, NIST CSF, GDPR, and HIPAA. Compliance that runs while you build.

Not ready for a call?

Get pricing and a free readiness assessment

Tell us where to send it. We’ll show you what Strac Comply costs and where your gaps are — no call required.

No spam. Your data is protected by our own DLP. Unsubscribe anytime.