mcp server
LaunchTrust
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
Description as published by the maintainer. Source
- version 0.1.0
- archived
- security
archived — The linked repository returns 404. It was deleted, renamed or made private. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
9 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
get_compliance_rules(jurisdiction)- Fetch LaunchTrust's sourced, founder-reviewed compliance rule snapshots, optionally filtered to one jurisdiction code (e.g. eu-ai-act-50, gdpr, ca-sb243). Compliance aid, not legal advice.
get_market_report(app_id)- Get the latest scan for one of your registered apps, with each finding annotated by the jurisdictions and rules applicable to that app's target markets. Requires a LaunchTrust token. Required: app_id.
get_scan_history(app_id)- List recent scans (summary + findings) for one of your registered apps. Requires a LaunchTrust token. Required: app_id.
list_jurisdictions- List the jurisdictions and categories LaunchTrust tracks (e.g. EU AI Act, GDPR, US state privacy laws, app-store policies). Public coverage registry. Compliance aid, not legal advice.
list_my_apps- List the apps registered in your LaunchTrust account, with each one's latest scan status. Requires a LaunchTrust token.
register_app(url, name)- Register a web URL in your LaunchTrust account so it can be fully scanned and monitored. Idempotent — if the URL is already registered, returns the existing app. Requires a LaunchTrust token and an active subscription. Required: url.
scan_app(app_id)- Run the full LaunchTrust scan on one of your registered apps and store a signed, dated evidence record. Requires a LaunchTrust token and an active subscription. Limited to 5 scans per app per day. Required: app_id.
scan_url(url)- Run a FREE LaunchTrust compliance + security quick-scan on a public web URL. Returns a focused SUBSET of checks — leaked frontend secrets/API keys, exposed .env//.git, security headers, HTTPS/HSTS, missing privacy/terms pages, trackers/cookie banner, and AI-interaction disclosure. The result is unsigned and not stored. The full 27-detector signed, dated, continuously-monitored scan requires a LaunchTrust account. Compliance aid, not legal advice. Required: url.
verify_record(record)- Independently verify the ECDSA (ES256) signature on a LaunchTrust signed scan/disclosure record against the published public key. Pass the record JSON (the downloaded record, or an object containing `canonical` and `signature`). Required: record.
Last successful function declaration observed on . Source: https://mcp.launchtrust.co/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://mcp.launchtrust.co/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 0.1.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-06-26 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-06-26 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| repository status | not_found | GitHub returned 404 for the repository the maintainer listed. The project was deleted, renamed or made private, so the listing points at nothing. | as of fetch | GitHub | |
| mcp tools declared | 9 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | mcp.launchtrust.co | |
| mcp endpoint status | ok | The server listed 9 functions when asked. | as of probe | mcp.launchtrust.co |
Where to get it
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json