Headless compliance.
Run by your AI agent.
Strac Comply's MCP server. Connect Claude Code, Cursor, or any MCP-aware client — and let your AI agent build and maintain your SOC 2 binder. No dashboard required.
claude mcp add --transport http --scope user strac-comply \ https://mcp.comply.strac.io/mcpRun this before you launch Claude Code (MCP config loads at startup). Then, in a session, run /mcp → Authenticate once. --scope user keeps it available in every session, not just the current folder.
How it connects
Three steps from zero to your AI agent writing evidence into your binder.
- 01
Run the connect command
Pick your client tab above and paste the snippet into Claude Code, Claude Desktop, Cursor, or any MCP-aware client. The client opens your browser to
mcp.comply.strac.iofor consent. - 02
Sign in & pick scopes
Sign in with the same account you use for the web app. Choose which scopes the AI gets:
compliance:read,policies:write,documents:write, and more. Scopes are revocable from Settings. - 03
Your AI agent does the work
The agent reads your live compliance state — controls, policies, documents, test results, employees, audits — and writes evidence back to your binder. Every action lands in an append-only audit log with the AI's identity stamped on it.
What your AI agent can do
Every tool below is a real MCP method on mcp.comply.strac.io.
Answer compliance questions
tool“Where are we on SOC 2 CC6?” — your AI reads live controls, policies, and test evidence, then answers grounded in your real posture, not generic advice.
ask_compliance_question
Read your full compliance state
toolControls, policies, documents, audits, test results, employees — the AI can list and drill into every surface. Filtered by scope; partitioned by your tenant.
list_controls · list_policies · list_tests
Write policies and evidence
toolDraft policies, upload new versions, attach evidence to controls, mark controls Not Applicable with justifications. Every write emits an audit-log row attributing the change to the AI.
upload_policy · attach_evidence · mark_control_na
Connect your integrations
toolHand the AI a connect-button for Google Workspace, AWS, or Slack. The customer authorizes in the browser; the AI polls until the integration is live and starts pulling evidence.
connect_integration · get_connection_status
Migrate off your current GRC platform
toolExport from Vanta, Drata, or Secureframe, point your AI at the folder, and the installed
strac-importplaybook migrates policies, vendors, risks, evidence — even historic test runs — in one run. Idempotent and safe to re-run.import_vendors · import_risks · import_test_runs
Run and triage automated tests
toolRe-run a failing compliance test after a fix, watch the execution to completion, and propose accept-risk exceptions — the AI drafts the justification, a human approves it in the app.
rerun_test · get_test_execution · acknowledge_test
Manage vendor risk
toolRun the deterministic vendor risk assessment (one vendor or the whole list), record completed security reviews, and file a vendor's SOC 2 report or DPA into the binder — every action marked agent-recorded.
run_vendor_risk_assessments · record_vendor_security_review
Reply to your auditor
toolList open evidence requests, prepare a draft reply from binder evidence or a fresh upload, then submit — prepare and send are separate steps, so the auditor is never emailed by accident.
list_audit_requests · submit_audit_request_response
Works with your AI client
Standard MCP transport. Drop in your client's config and reload.
Ready to ship faster?
Built for SOC 2, ISO 27001, NIST CSF, GDPR, and HIPAA. Compliance that runs while you build.