VITNA — Agent Compliance Preflight by costrinity.xyz

MCP server · Travel & booking · indexed, not reviewed

HostedLocalvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

Pre-action compliance for AI agents: allow, block or hold. 24 statutes, 13 jurisdictions.

What the official MCP registry says

Facts

MCP registry
xyz.costrinity/vitna-compliance-preflight · 0.5.0
Endpoint
https://vitna.costrinity.xyz/api/mcp
Packages
npm @costrinity/vitna-compliance-mcp stdio
npm / week
266
GitHub stars
0
Registry entry
updated 26 Sep 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under costrinity.xyz, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 23 · about 3,293 tokens of context · checked 26 minutes ago

ToolWhat it doesHint
vitna_helpWhat is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check risky actions BEFORE running them, what a deny / hold decision…
vitna_claimAsk whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account, when you are told evidence is not being kept, or any time…
consent_checkBefore you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and optional category); returns { allowed, reason,…
breach_classifyAfter a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories, sensitivity, recovery state) and VITNA returns reportability…
ai_act_classifyBefore you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric / remote-identification / automated-decision / social-scoring / GPAI flags)…
dpia_threshold_checkBefore you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data categories (and scale / systematic-monitoring / automated-decision…
us_sectoral_checkBefore you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given processing profile, so you can factor them in before you act.…
india_sectoral_checkBefore you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT / PFRDA) from its processing profile, so you know whose rules…
india_cross_border_statusBefore you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI / SEBI / IRDAI caveats. Pass the ISO-3166 alpha-2 country code…
japan_cross_border_statusBefore you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the ISO-3166 alpha-2 country code. Stateless lookup: records no…
us_state_breach_deadlineQuick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without unreasonable delay). This is a static table, not an incident…
aadhaar_maskMask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless validator: records no decision and leaves no dashboard timeline…
pan_classifyClassify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard timeline trace.
gstin_validateValidate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace.
cpf_validateValidate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace.
sin_validateValidate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace.
iban_validateValidate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace.
pii_testDry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether severity would escalate. Nothing is persisted and nothing is…
privacy_notice_getGenerate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard timeline trace.
sub_processors_registerReturn the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace.
global_compliance_mapMaster catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision and leaves no dashboard timeline trace.
india_regulators_directoryStatic reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup of who exists and what they cover. To instead work out which…
vitna_preflightSAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the action BEFORE you run it: it flags dangerous shell / SQL /…

What https://vitna.costrinity.xyz/api/mcp answered to tools/list, asked without credentials. answered without the initialize handshake. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 39 warnings · 1 note

  • warnTC11aadhaar_maskits one parameter, aadhaar, has no description
  • warnTC11ai_act_classifynone of its 8 parameters has a description
  • warnTC11breach_classifynone of its 6 parameters has a description
  • warnTC11cpf_validateits one parameter, cpf, has no description
  • warnTC11dpia_threshold_checknone of its 8 parameters has a description
  • warnTC11gstin_validateits one parameter, gstin, has no description
  • warnTC11iban_validateits one parameter, iban, has no description
  • warnTC11india_regulators_directoryits one parameter, sector, has no description
  • warnTC11india_sectoral_checknone of its 4 parameters has a description
  • warnTC11pan_classifyits one parameter, pan, has no description
  • warnTC11pii_test1 parameter without a description: jurisdiction
  • warnTC11privacy_notice_getits one parameter, format, has no description
  • warnTC11sin_validateits one parameter, sin, has no description
  • warnTC11us_sectoral_checknone of its 5 parameters has a description
  • warnTC13pii_testsample_event (object with no properties)
  • warnTC13vitna_preflightpayload (object with no properties)
  • warnTC16aadhaar_maskno readOnlyHint or destructiveHint
  • warnTC16ai_act_classifyno readOnlyHint or destructiveHint
  • warnTC16breach_classifyno readOnlyHint or destructiveHint
  • warnTC16consent_checkno readOnlyHint or destructiveHint
  • warnTC16cpf_validateno readOnlyHint or destructiveHint
  • warnTC16dpia_threshold_checkno readOnlyHint or destructiveHint
  • warnTC16global_compliance_mapno readOnlyHint or destructiveHint
  • warnTC16gstin_validateno readOnlyHint or destructiveHint

The first 24 of 40; every finding is in the listing's JSON under mcpTools.check.

The checks from /check and anchor check, run each day on the list above: about 3,293 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.