JSPM

Found 99 results for soc2

@agenticmail/enterprise

AgenticMail Enterprise — cloud-hosted AI agent identity, email, auth & compliance for organizations

  • v0.5.559
  • 57.15
  • Published

@kylewadegrove/cutline-mcp-cli-staging

CLI and MCP servers for Cutline, including SlopBurn: a product quality engineering roguelike RPG for vibecoding workflows.

    • v0.23.1
    • 48.00
    • Published

    @vurb/testing

    In-memory MVA lifecycle emulator for Vurb. Runs the full pipeline (Zod Input → Middlewares → Handler → Egress Firewall) without network transport. Returns structured MvaTestResult objects — zero coupling to Jest/Vitest.

    • v3.15.2
    • 47.68
    • Published

    speclock

    Stop AI from breaking code you told it not to touch. Enforces .cursorrules, CLAUDE.md, and AGENTS.md — not just suggests. Zero-config: npx speclock protect reads your existing AI rule files, extracts constraints, installs pre-commit hooks, and makes your

    • v5.5.7
    • 47.32
    • Published

    @probo/n8n-nodes-probo

    n8n nodes for integrating with the Probo compliance platform API

    • v0.170.0
    • 47.04
    • Published

    @nodatachat/guard

    NoData Guard — continuous security scanner. Runs locally, reports only metadata. Your data never leaves your machine.

    • v4.2.2
    • 45.03
    • Published

    @vibekiln/cutline-mcp-cli

    CLI and MCP servers for Cutline — authenticate, then run constraint-aware MCP servers in Cursor or any MCP client.

      • v0.13.0
      • 43.52
      • Published

      @cveriskpilot/scan

      Compliance as a Service CLI — scan dependencies, secrets, and IaC, then auto-map every finding to NIST 800-53, SOC 2, CMMC, FedRAMP, ASVS, and SSDF controls

      • v0.1.17
      • 42.60
      • Published

      cia-compliance-manager

      React components, hooks, and services for CIA triad security assessment, compliance management, and risk analysis — supporting ISO 27001, NIST 800-53, SOC 2, GDPR, HIPAA, and EU CRA frameworks

      • v1.1.52
      • 42.12
      • Published

      @aegis-scan/scanners

      AEGIS scanner registry — 39 built-in regex/AST checkers + 1 AST cross-file taint analyzer + 16 external-tool wrappers (Semgrep, Gitleaks, Trivy, ZAP, …). Framework-specific security rules for Next.js + Supabase: multi-tenant isolation, RLS bypass, Zod enf

      • v0.10.0
      • 40.99
      • Published

      @custodia/cli

      Secure Code — scan, fix, and automate security for any codebase. SOC 2, NIST CSF, OWASP Top 10 & CWE.

        • v2.7.0
        • 40.19
        • Published

        dingdawg-compliance

        87/100 compliance score in 60 seconds. EU AI Act + Colorado AI Act — gets more accurate with every scan. Free local check included.

        • v2.0.5
        • 39.98
        • Published

        @pan-sec/notebooklm-mcp

        Security-hardened MCP server for NotebookLM API with compliance-ready architecture (GDPR, SOC2, CSSF controls implemented)

        • v2026.2.11
        • 39.94
        • Published

        tamper-evident-log

        Lightweight tamper-evident audit log with HMAC-SHA256 hash chain. Zero dependencies. Framework-agnostic.

        • v0.1.1
        • 38.87
        • Published

        @varcore/policy

        VAR-Core deterministic YAML policy engine with pre-built compliance control packs

        • v1.2.6
        • 38.76
        • Published

        sentrik

        Governance runtime for AI-generated code. Scan, gate, and trace compliance automatically.

        • v1.4.0
        • 38.11
        • Published

        legal-doc-analyzer

        Legal vertical MCP server for document analysis - contract summarization, risk assessment, version comparison, compliance checking, and plain-English summaries.

          • v1.1.3
          • 37.70
          • Published

          @aegis-scan/cli

          AEGIS CLI — paranoid stack-specific security scanner for Next.js + Supabase. 0-1000 score, 40 built-in checkers (+16 external-tool wrappers), AST-based cross-file taint analysis, 4 compliance frameworks (GDPR / SOC 2 / ISO 27001 / PCI-DSS), inline + confi

          • v0.10.0
          • 37.39
          • Published

          vcs-access-review

          Generate auditor-ready access review reports from GitHub orgs. SOC2 CC6.3 quarterly access reviews made easy.

          • v0.2.3
          • 37.36
          • Published

          security-mcp

          AI security MCP server and enforcement gate for Claude Code, Cursor, GitHub Copilot, Codex, Replit, and any MCP-compatible editor. Applies OWASP, MITRE ATT&CK, NIST, Zero Trust, PCI DSS, SOC 2, and ISO 27001.

          • v1.1.3
          • 37.11
          • Published

          @nodatachat/capsule

          Always-on security agent — file watcher, git hooks, scheduled scans, notifications. Zero data access.

          • v1.3.0
          • 36.49
          • Published

          @bulwark-ai/gateway

          Enterprise AI governance gateway — PII detection, prompt injection guard, budget control, audit logging, RAG, multi-tenant. Drop into any Node.js app.

          • v0.2.0
          • 36.47
          • Published

          @qnsp/audit-sdk

          TypeScript SDK client for the QNSP audit-service API. Provides audit log querying and compliance reporting.

          • v0.3.4
          • 35.26
          • Published

          prprompts-flutter-generator

          AI-powered Flutter development with full automation + official extension support - Generate 32 security-audited guides & auto-implement in 2-3 hours. NEW v5.1: Official Claude Code plugin with hooks, Gemini TOML commands, Qwen MCP settings. Features: Comp

          • v5.1.3
          • 35.06
          • Published

          tethora-sdk

          Official SDK for Tethora - AI agent governance and compliance platform. Log every agent action, enforce policies, and generate compliance reports.

          • v1.1.0
          • 35.02
          • Published

          @zi2/relay-sdk

          Enterprise SMS relay SDK with E2E encryption, provider fallback, and PCI DSS v4 compliance

          • v2.0.0
          • 34.04
          • Published

          mergewhy

          MergeWhy CLI — record change evidence, attestations, and compliance data from any CI/CD pipeline

          • v1.2.0
          • 33.47
          • Published

          @bene-npm/shield-ui

          Security-themed React component library for dashboards, scanners, and threat visualization

          • v2.0.3
          • 33.34
          • Published

          @donotdev/security

          SOC2-grade security controls for DoNotDev — audit logging, rate limiting, PII encryption, auth hardening, anomaly detection, privacy management

          • v0.1.1
          • 32.33
          • Published

          @vinkius-core/mcp-fusion-testing

          In-memory MVA lifecycle emulator for MCP Fusion. Runs the full pipeline (Zod Input → Middlewares → Handler → Egress Firewall) without network transport. Returns structured MvaTestResult objects — zero coupling to Jest/Vitest.

          • v3.1.31
          • 32.19
          • Published

          recoder-security

          Enterprise-grade security and compliance layer for CodeCraft CLI

          • v1.0.0
          • 31.99
          • Published

          codepliant

          Scan your codebase, generate compliance documents. Privacy Policy, Terms of Service, AI Disclosure, Cookie Policy, DPA — all from your actual code.

          • v1.1.1
          • 31.09
          • Published

          mergewhy-collector

          MergeWhy Collector — Change evidence collection for CI pipelines and regulated environments. Score PRs, detect compliance gaps, and push signed attestations.

          • v1.1.0
          • 30.00
          • Published

          mcp-perforce-server

          Enterprise-grade MCP (Model Context Protocol) server for Perforce P4 integration with AI assistants. Includes 59 MCP tools, native-style batch and flag support, rich review/search workflow helpers, and comprehensive security controls such as audit logging

          • v3.2.0
          • 29.84
          • Published

          @prodcycle/prodcycle

          Multi-framework policy-as-code compliance scanner for infrastructure and application code.

          • v0.2.1
          • 29.15
          • Published

          @deja-dev/dsr-verify

          Verification library for DSR/1.0 production incident receipts

          • v1.0.2
          • 28.30
          • Published

          trailkit

          Lightweight, zero-infrastructure audit logging for Node.js and TypeScript

          • v0.1.0
          • 28.24
          • Published

          @recalled/sdk

          Official TypeScript SDK for Recalled — audit logs as a service for your product.

          • v0.2.0
          • 28.09
          • Published

          @custodia/mcp

          MCP server for Custodia — scan GitHub repos for security vulnerabilities from Claude Desktop, Cursor, and Claude.ai.

            • v1.2.0
            • 27.43
            • Published

            @theartofservice/compliance-mcp

            MCP server for compliance intelligence — 692 frameworks, 13,700+ controls, 819K+ cross-framework mappings. Works with Claude Desktop, Cursor, and any MCP client.

            • v0.1.1
            • 27.35
            • Published

            @vasoyaprince14/sql-analyzer

            🚀 Enterprise SQL database analyzer with AI insights, security auditing, performance optimization, real-time monitoring, and beautiful reports

            • v1.5.3
            • 27.12
            • Published

            nodata-soc-scan

            SOC 1 & SOC 2 exposure scanner — deep analysis, runs locally, never uploads code

            • v1.0.0
            • 26.78
            • Published

            vigil-scan

            Compliance static analysis tool for Java and JS/TS projects

            • v1.0.1
            • 26.67
            • Published

            @ascend-ai/sdk

            ASCEND SDK - Enterprise AI Governance with fail mode, circuit breaker, and MCP integration

            • v2.1.1
            • 26.40
            • Published

            @kylewadegrove/cutline-mcp-cli

            CLI and MCP servers for Cutline — authenticate, then run constraint-aware MCP servers in Cursor or any MCP client.

              • v0.7.4
              • 25.75
              • Published

              @ascend-ai/mcp-server

              ASCEND governance integration for MCP (Model Context Protocol) servers - Enterprise-grade AI agent security

              • v1.1.0
              • 25.63
              • Published

              px-pack

              Portable release pack — bundle binaries, SBOMs and provenance into one offline-verifiable package

                • v0.1.0
                • 25.50
                • Published

                claw-grc-mcp-server

                Official MCP (Model Context Protocol) server for Claw GRC — the AI-native GRC platform. Connect any MCP-compatible AI assistant to your compliance data.

                • v1.0.0
                • 25.07
                • Published

                container-image-scanner

                🚨 EMERGENCY Bitnami Migration Scanner - Critical Timeline Aug 28/Sep 29, 2025. Enterprise scanner for 280+ Bitnami images, 118+ Helm charts with emergency migration automation to AWS alternatives.

                • v2.6.0
                • 24.37
                • Published

                @ugend/mcp-compliance

                MCP audit trail and compliance middleware — logs every tool call for FCA, GDPR, SOC2, and ISO 27001 compliance

                  • v1.0.0
                  • 22.14
                  • Published

                  sentinel-protocol

                  The Reference Architecture for Local AI Governance & Firewalling. Secure, deterministic protection for Agents, MCP, and LLMs.

                  • v1.2.7
                  • 21.86
                  • Published

                  @evidence-oss/sdk

                  Evidence SDK - SOC 2 compliance evidence collector library

                  • v0.1.1
                  • 21.48
                  • Published

                  @holoscript/export-api

                  REST API for HoloScript compilation and export with SOC 2 compliance foundations - async job processing, RBAC, audit logging, rate limiting

                  • v1.0.0
                  • 20.42
                  • Published

                  optimisely-cloud-sdk

                  Optimisely Cloud SDK - Extract, analyze, and generate Terraform Infrastructure as Code from cloud resources across AWS, Azure, and GCP

                  • v1.2.6
                  • 20.36
                  • Published

                  @kitiumai/auth

                  Enterprise-grade authentication solution with OAuth2, API keys, email verification, SAML2, SSO, WebAuthn, 2FA, RBAC, and subscription management

                  • v4.0.1
                  • 20.05
                  • Published

                  @logseal/node

                  Official Node.js SDK for LogSeal - Audit logging for B2B SaaS

                  • v0.0.2
                  • 19.76
                  • Published

                  openclaw-global-compliance

                  AI-powered global compliance checker, document generator, and risk assessor for GDPR, CCPA, SOC2, ISO27001, and more

                  • v1.0.1
                  • 19.26
                  • Published

                  @evidence-oss/cli

                  Evidence CLI - Command-line interface for evidence collection

                  • v0.1.1
                  • 18.96
                  • Published

                  @officialdeadman/mcp-auditor

                  The Omniscient Auditor - Forensic-grade security, compliance, and code auditing for Claude via MCP. 35 professional tools across 8 audit domains.

                  • v1.1.1
                  • 17.85
                  • Published

                  ascend-mcp-server

                  ASCEND governance integration for MCP (Model Context Protocol) servers - Enterprise-grade AI agent security

                  • v1.0.0
                  • 17.66
                  • Published

                  @imexs/audit-trail

                  Enterprise-grade Audit Trail Plugin for Node.js with TypeScript - Performance Monitoring, System Integration Audit, Data Accountability & User Activity Tracking with Advanced Security Features

                  • v1.0.3
                  • 17.57
                  • Published

                  astra-os

                  AstraOS — The most complete AI agent operating system. Multi-LLM, MCP, A2A, GraphRAG, Computer Use, RBAC, Multi-Tenancy, Marketplace (55+ skills), Admin Dashboard, Workflow Builder, SSO (SAML+OIDC), Audit Log, Data Residency, Billing (Stripe), Edge Runtim

                  • v4.0.0
                  • 17.13
                  • Published

                  @iflow-mcp/sgroy10-speclock

                  AI Constraint Engine by Sandeep Roy — AI Patch Firewall. Diff-native review (interface breaks, protected symbols, dependency drift, schema changes, API impact), Patch Gateway (ALLOW/WARN/BLOCK verdicts), Spec Compiler (NL→constraints), Code Graph (blast r

                  • v5.2.6
                  • 16.91
                  • Published

                  aws-container-image-scanner

                  AWS Container Image Scanner - Enterprise tool for scanning EKS clusters, analyzing Bitnami container dependencies, and generating migration guidance for AWS ECR alternatives with security best practices.

                  • v2.5.2
                  • 16.54
                  • Published

                  @logvault/cli

                  LogVault CLI - Audit logging setup in 2 minutes

                  • v0.2.3
                  • 16.36
                  • Published

                  sm-todos

                  ## Project setup ``` npm install ```

                    • v0.3.2
                    • 16.25
                    • Published

                    cursor-rules-awesome

                    World-class comprehensive coding standards for Cursor AI. 4,800+ lines covering 72 topics: OWASP Top 10, SRE practices, 15+ languages, 9 compliance frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR). Perfect 10/10 rating.

                    • v1.0.1
                    • 16.06
                    • Published

                    @logvault/schemas

                    Type-safe Zod schemas for LogVault audit events

                    • v0.2.3
                    • 15.83
                    • Published

                    @nihal1983/cli

                    Review Policy CLI - AI-powered code review with policy-as-code

                    • v0.2.3
                    • 15.79
                    • Published

                    @forge-framework/cli

                    AI Software Bill of Materials (AI-SBOM) CLI - Generate, verify, and audit cryptographically-signed records for AI-generated code

                    • v1.2.0
                    • 15.57
                    • Published

                    @frozotrailbase/sdk

                    Official TypeScript SDK for Trailbase — audit logs, RBAC, and compliance for B2B SaaS

                    • v0.1.1
                    • 15.57
                    • Published

                    @grcorsair/cli

                    CORSAIR - CPOE ingestion and trust exchange platform

                    • v1.1.7
                    • 15.03
                    • Published

                    @kitiumai/auth-postgres

                    Enterprise-grade PostgreSQL storage adapter for @kitiumai/auth with full support for users, sessions, OAuth links, API keys, 2FA, RBAC, and SSO

                    • v3.1.1
                    • 14.86
                    • Published

                    sealvera

                    AI compliance infrastructure — tamper-evident audit trail for AI agents in regulated industries

                    • v0.1.0
                    • 14.31
                    • Published

                    @safekeylab/mcp-enterprise

                    SafeKeyLab Enterprise MCP Server - Agent Security, RAG Protection, and Compliance

                    • v1.0.1
                    • 14.20
                    • Published

                    noopkg

                    CLI installer for noopkg - Claude Code skills and agents for IT professionals

                    • v1.0.0
                    • 14.20
                    • Published

                    @astracipher/compliance-core

                    Compliance engine for AstraCipher — pluggable framework for regulatory compliance modules (DPDP, EU AI Act, SEBI CSCRF, SOC 2, HIPAA)

                    • v0.1.0
                    • 13.78
                    • Published

                    @fail-kit/core

                    F.A.I.L. Kit Core - Receipt generation, validation, and utilities for AI agent audit trails

                    • v2.0.0
                    • 13.47
                    • Published

                    @dreamfactory/create

                    Zero-friction DreamFactory setup: Governed database APIs for AI agents in minutes. The only self-hosted MCP server with field-level RBAC across 25+ databases (PostgreSQL, MySQL, Oracle, SQL Server, Snowflake). Blocks AI agents from accessing PII, prevents

                    • v0.1.0
                    • 12.73
                    • Published

                    @connector_oss/connector

                    Tamper-proof memory, chain-of-custody, and OS-grade runtime for AI agents — native Rust bindings via NAPI-RS with HTTP fallback

                    • v0.2.0
                    • 12.53
                    • Published

                    better-auth-audit-log

                    Comprehensive audit logging plugin for Better Auth - Track all authentication events for compliance and security

                    • v0.0.1
                    • 12.09
                    • Published

                    @logvault/client

                    Audit-Log-as-a-Service client library with type-safe logging

                    • v1.0.0
                    • 11.64
                    • Published

                    @principal-ai/vanta-sdk

                    SDK for interacting with Vanta API for compliance and security monitoring, with GitHub coverage calculator integration

                    • v0.1.2
                    • 11.20
                    • Published

                    @kitiumai/auth-mongo

                    Enterprise-grade MongoDB storage adapter for @kitiumai/auth with full support for users, sessions, OAuth links, API keys, 2FA, RBAC, and SSO

                    • v1.0.0
                    • 11.14
                    • Published

                    connector_oss

                    Tamper-proof memory and chain-of-custody for AI agents

                    • v0.1.0
                    • 10.20
                    • Published

                    openshart

                    Enterprise-grade encrypted agent memory. If it leaks, you're going to OpenShart yourself.

                    • v0.1.0
                    • 10.00
                    • Published

                    juro-mcp-server

                    Juro - providing compliance as a service: Enterprise-grade MCP server for automated compliance scanning with AI-powered analysis

                    • v2.0.0
                    • 9.42
                    • Published

                    @vinkius-core/testing

                    In-memory MVA lifecycle emulator for MCP Fusion. Runs the full pipeline (Zod Input → Middlewares → Handler → Egress Firewall) without network transport. Returns structured MvaTestResult objects — zero coupling to Jest/Vitest.

                    • v1.0.0
                    • 9.32
                    • Published

                    @widiramadhan/audit-trail

                    Enterprise-grade Audit Trail Plugin for Node.js with TypeScript - Performance Monitoring, System Integration Audit, Data Accountability & User Activity Tracking with Advanced Security Features

                    • v1.0.0
                    • 9.00
                    • Published

                    compai-mcp

                    MCP server for the Comp AI compliance platform API

                    • v1.0.0
                    • 0.00
                    • Published

                    complianceiq-policy-mcp

                    MCP server for compliance policy document generation — create security policies, SOPs, incident response plans, risk assessment templates, and training outlines aligned to regulatory frameworks

                    • v0.1.0
                    • 0.00
                    • Published

                    complianceiq-audit-mcp

                    MCP server for compliance auditing — run audits against SOC2, ISO 27001, HIPAA, GDPR, PCI-DSS frameworks, identify gaps, and generate remediation plans

                    • v0.1.0
                    • 0.00
                    • Published