# LaunchTrust MCP server

Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.

## Links
- Registry page: https://www.getdrio.com/mcp/co-launchtrust-launchtrust
- Repository: https://github.com/mustafasalimerek-bit/launchtrust-mcp

## Install
- Endpoint: https://mcp.launchtrust.co/mcp
- Auth: Not captured

## Setup notes
- Remote endpoint: https://mcp.launchtrust.co/mcp

## Tools
- scan_url (Free compliance + security quick-scan) - Run a FREE LaunchTrust compliance + security quick-scan on a public web URL. Returns a focused SUBSET of checks — leaked frontend secrets/API keys, exposed .env//.git, security headers, HTTPS/HSTS, missing privacy/terms pages, trackers/cookie banner, and AI-interaction disclosure. The result is unsigned and not stored. The full 27-detector signed, dated, continuously-monitored scan requires a LaunchTrust account. Compliance aid, not legal advice. Endpoint: https://mcp.launchtrust.co/mcp
- list_jurisdictions (List compliance jurisdictions covered) - List the jurisdictions and categories LaunchTrust tracks (e.g. EU AI Act, GDPR, US state privacy laws, app-store policies). Public coverage registry. Compliance aid, not legal advice. Endpoint: https://mcp.launchtrust.co/mcp
- get_compliance_rules (Get sourced compliance rule snapshots) - Fetch LaunchTrust's sourced, founder-reviewed compliance rule snapshots, optionally filtered to one jurisdiction code (e.g. eu-ai-act-50, gdpr, ca-sb243). Compliance aid, not legal advice. Endpoint: https://mcp.launchtrust.co/mcp
- verify_record (Verify a LaunchTrust signed record) - Independently verify the ECDSA (ES256) signature on a LaunchTrust signed scan/disclosure record against the published public key. Pass the record JSON (the downloaded record, or an object containing `canonical` and `signature`). Endpoint: https://mcp.launchtrust.co/mcp
- list_my_apps (List your registered apps) - List the apps registered in your LaunchTrust account, with each one's latest scan status. Requires a LaunchTrust token. Endpoint: https://mcp.launchtrust.co/mcp
- register_app (Register an app to monitor) - Register a web URL in your LaunchTrust account so it can be fully scanned and monitored. Idempotent — if the URL is already registered, returns the existing app. Requires a LaunchTrust token and an active subscription. Endpoint: https://mcp.launchtrust.co/mcp
- scan_app (Run a full signed scan on a registered app) - Run the full LaunchTrust scan on one of your registered apps and store a signed, dated evidence record. Requires a LaunchTrust token and an active subscription. Limited to 5 scans per app per day. Endpoint: https://mcp.launchtrust.co/mcp
- get_scan_history (Get scan history for an app) - List recent scans (summary + findings) for one of your registered apps. Requires a LaunchTrust token. Endpoint: https://mcp.launchtrust.co/mcp
- get_market_report (Get a market-annotated compliance report) - Get the latest scan for one of your registered apps, with each finding annotated by the jurisdictions and rules applicable to that app's target markets. Requires a LaunchTrust token. Endpoint: https://mcp.launchtrust.co/mcp

## Resources
Not captured

## Prompts
Not captured

## Metadata
- Owner: co.launchtrust
- Version: 0.1.0
- Runtime: Streamable Http
- Transports: HTTP
- License: Not captured
- Language: Not captured
- Stars: Not captured
- Updated: Jun 26, 2026
- Source: https://registry.modelcontextprotocol.io
