Four MCP servers (Rules, Insights, Workflow, Assistant) that let AI agents create and execute compliance rules, query evidence and compliance posture, and build compliance workflows against the ComplianceCow platform.
Agent directory
58 live agents. Sorted by recency, then name. No paid boost.
Enterprise MCP server from Comply that connects the ComplyAI financial-services compliance platform to AI tools, so authorized teams can build agentic workflows such as trade pre-clearances, policy guidance, and annual reviews.
Open-source MCP server from IBM that lets AI agents query and update IBM OpenPages GRC objects such as issues and controls over HTTP or stdio.
Hosted MCP server that exposes Secureframe compliance data as tools for AI assistants: controls, tests, vendors, frameworks, risks, and more.
Configurable GRC AI agents that review evidence, draft policies, score vendor risk, and fill trust questionnaires inside the Complyance platform.
Agentic compliance graph that maps requirements, collects evidence, fills questionnaires, and watches regulatory change.
Startup SOC 2 and ISO platform with AI GRC agents for policy onboarding, control mapping, and questionnaires.
Ask-your-GRC-data copilot and questionnaire assist on the Compyl platform. Does not list the not-yet-GA Agent Library.
KAIA is Kertos's AI guide that automates European privacy and information-security compliance workflows.
Regulatory AI agents that encode law and run compliance analyses, including a Microsoft 365 Copilot compliance agent.
Open-source compliance platform agent that handles requirements, docs, risks, controls, and evidence for SOC 2, GDPR, HIPAA, and ISO.
Named agent that logs into SaaS apps, reads contracts and privacy settings, and checks them against the company's AI policy.
Named regulatory compliance agent that maps obligations and monitors regulatory change.
Purpose-built security questionnaire automation for SaaS teams that need to answer CAIQ-style reviews without a dedicated GRC hire.
Named AI GRC agent fleet for governance, risk, and compliance workflows.
AI GRC teammates inside Scrut that evaluate evidence, fill questionnaires, score vendors, and open remediation tickets.
Scytale's named GRC AI agent for evidence review, gap scanning, policy work, and security questionnaires.
AI-drafted security questionnaire and trust-center workflows with certified analysts reviewing answers before send.
Named GRC agent that fills security questionnaires and portal reviews from a sourced knowledge base, with a complimentary trust center.
YC-backed AI agent for security, privacy, DDQ, and ESG questionnaire automation across portals and files.
AI-native compliance management platform with agentic workflows for audits, evidence, and trust.
Agentic third-party cyber assessment surface on TrustCloud that scores vendors from outside-in and inside-out signals.
Multi-agent GRC system with specialized control, evidence, policy, and risk agents that work on top of an existing GRC program.
Named GRC agent inside Vanta that drafts policies, checks evidence, answers questionnaires, and flags vendor risk.
Enterprise agentic GRC platform with broad integrations and pre-mapped frameworks.
OpenAI ChatGPT/Custom GPTs used as workflow agents for policy drafting and compliance research.
General-purpose Anthropic Claude used via Skills/MCP for custom GRC workflows in enterprise teams.
AI-assisted security questionnaire automation and trust center for B2B vendors.
AI governance platform for policy, risk, and regulatory alignment across AI systems.
Cursor's automated PR review agent for bugs and regressions; usage-metered agent runs on pull requests.
Automated evidence collection and continuous control monitoring for security and privacy frameworks.
Dependency and reachability analysis to prioritize open-source risk for security programs.
GitHub-hosted agent that can implement tasks and open pull requests in your repositories.
Domain-specific legal AI used by firms and in-house teams for research and drafting.
heyGRC
Listed by Better ISMS (same rules as everyone)
GitHub App that reviews every pull request for compliance impact: flags changes that put controls, evidence, or framework posture at risk.
AI risk management and governance tooling for enterprise AI portfolios.
GRC platform with AI-assisted workflows for controls, audits, and risk programs.
ISMS Copilot
Listed by Better ISMS (same rules as everyone)
Compliance AI engine for 75+ frameworks. Chat, tasks, and account MCP so agents and practitioners run GRC work with an auditable trail.
ISMS Copilot for Agents
Listed by Better ISMS (same rules as everyone)
Account MCP + PAT so Claude Code, Cursor, and other agents use your ISMS Copilot workspace tools directly.
ISMS Directory MCP
Listed by Better ISMS (same rules as everyone)
MCP server that lets agents search a curated directory of human GRC services and submit listings.
AI legal workspace used by legal teams for document-heavy compliance and contract workflows.
AI operations agents for incident response workflows with audit-friendly operational trails.
Trust center and security review automation for vendor questionnaires.
Continuous compliance automation platform for cloud-native companies across security and privacy frameworks.
AI-powered compliance automation with expert-backed workflows for cloud-native companies.
AI-driven compliance audit solution that collects evidence artifacts from IT systems.
AI-assisted compliance automation for evidence, questionnaires, and multi-framework programs.
AI-assisted static analysis triage and fix guidance for security findings in code.
Security-focused code analysis and AI fix suggestions integrated into developer workflows.
Supply-chain security agent that monitors dependencies for malware and risk signals.
AI-powered SOC 2 and EU AI Act compliance with continuous evidence collection.
Compliance automation with continuous monitoring for SOC 2, ISO 27001, GDPR, and more.
End-to-end compliance platform combining AI automation with in-house audit services.
AI governance software helping organizations comply with the EU AI Act and manage AI-specific risk.
Continuous control monitoring and evidence collection automation for SOC 2, ISO 27001, and related frameworks.
AI-assisted trust and questionnaire workflows adjacent to Vanta's compliance automation suite.
Vendor risk automation with AI-assisted questionnaire and trust center workflows.
AI-driven automation to accelerate ISO 27001 and SOC 2 for SaaS companies.