{
  "data": {
    "tool": {
      "category": "travel",
      "endpoint": "https://vitna.costrinity.xyz/api/mcp",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/costrinity-vitna-compliance-preflight.json",
      "kind": "mcp",
      "listed": "indexed",
      "liveUrl": "https://www.anchorterminal.com/api/v1/live/costrinity-vitna-compliance-preflight.json",
      "markdownUrl": "https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight.md",
      "mcpTools": {
        "check": {
          "checker": "anchor-check/1.0",
          "totalTokens": 3293,
          "counts": {
            "error": 0,
            "note": 1,
            "warn": 39
          },
          "findings": [
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "aadhaar_mask",
              "message": "its one parameter, aadhaar, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "ai_act_classify",
              "message": "none of its 8 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "breach_classify",
              "message": "none of its 6 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "cpf_validate",
              "message": "its one parameter, cpf, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "dpia_threshold_check",
              "message": "none of its 8 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "gstin_validate",
              "message": "its one parameter, gstin, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "iban_validate",
              "message": "its one parameter, iban, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "india_regulators_directory",
              "message": "its one parameter, sector, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "india_sectoral_check",
              "message": "none of its 4 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "pan_classify",
              "message": "its one parameter, pan, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "pii_test",
              "message": "1 parameter without a description: jurisdiction",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "privacy_notice_get",
              "message": "its one parameter, format, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "sin_validate",
              "message": "its one parameter, sin, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "us_sectoral_check",
              "message": "none of its 5 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC13",
              "severity": "warn",
              "tool": "pii_test",
              "message": "sample_event (object with no properties)",
              "fix": "Declare the properties (or additionalProperties with a schema) and the array's items."
            },
            {
              "rule": "TC13",
              "severity": "warn",
              "tool": "vitna_preflight",
              "message": "payload (object with no properties)",
              "fix": "Declare the properties (or additionalProperties with a schema) and the array's items."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "aadhaar_mask",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "ai_act_classify",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "breach_classify",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "consent_check",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "cpf_validate",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"validate\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "dpia_threshold_check",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "global_compliance_map",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "gstin_validate",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"validate\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "iban_validate",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"validate\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "india_cross_border_status",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"status\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "india_regulators_directory",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "india_sectoral_check",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "japan_cross_border_status",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"status\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "pan_classify",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "pii_test",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "privacy_notice_get",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "sin_validate",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"validate\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "sub_processors_register",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "us_sectoral_check",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "us_state_breach_deadline",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "vitna_claim",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "vitna_help",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "vitna_preflight",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC24",
              "severity": "note",
              "message": "23 of 23 tools have no outputSchema",
              "fix": "Declare outputSchema for tools that return structured data, and return structuredContent that matches it."
            }
          ]
        },
        "checkedAt": "2026-10-04T22:26:09Z",
        "count": 23,
        "note": "answered without the initialize handshake",
        "schemaTokens": 3293,
        "status": "ok",
        "tools": [
          {
            "name": "vitna_help",
            "description": "What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check risky actions BEFORE running them, what a deny / hold decision means, trial vs claimed mode, and how the user can monitor and audit what you do. Runs entirely locally: no account, no API call, and no dashboard timeline trace.",
            "inputSchema": {
              "properties": {},
              "type": "object"
            }
          },
          {
            "name": "vitna_claim",
            "description": "Ask whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account, when you are told evidence is not being kept, or any time you want to hand the user something actionable. Returns { claimed, claim_url, what_claiming_gets_you }. IMPORTANT: if claimed is false, show the user the claim_url verbatim -- it is a one-time link that only they can act on, the account's evidence is NOT being durably recorded until they do, and they cannot find this link anywhere else. Do not paraphrase the URL and do not withhold it.",
            "inputSchema": {
              "properties": {},
              "type": "object"
            }
          },
          {
            "name": "consent_check",
            "description": "Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and optional category); returns { allowed, reason, matching_consent_id, principal_id }, a determination you must honour yourself since VITNA evaluates and records but does not enforce. Use this for personal-data processing legality; for a dangerous technical action (shell / file / DB / network) use vitna_preflight instead.",
            "inputSchema": {
              "properties": {
                "category": {
                  "description": "Optional permitted-category check.",
                  "type": "string"
                },
                "principal_id": {
                  "description": "UUID of the data principal (if known).",
                  "type": "string"
                },
                "principal_ref": {
                  "description": "Operator-side identifier; will be SHA-256-hashed.",
                  "type": "string"
                },
                "purpose": {
                  "description": "Purpose code (e.g. 'operational_observability').",
                  "type": "string"
                }
              },
              "required": [
                "purpose"
              ],
              "type": "object"
            }
          },
          {
            "name": "breach_classify",
            "description": "After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories, sensitivity, recovery state) and VITNA returns reportability + reasoning + the notification deadline + who to notify, across DPDP §8, GDPR Art 33, CPRA §1798.82, LGPD Art 48, PDPA §26B, and US-FED sectoral. This makes the full incident decision from the facts; for a quick per-US-state deadline/recipient/threshold table without incident facts, use us_state_breach_deadline. VITNA evaluates and records; acting on the result is up to you.",
            "inputSchema": {
              "properties": {
                "affected_count": {
                  "type": "integer"
                },
                "data_categories": {
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "jurisdiction": {
                  "type": "string"
                },
                "processing_purpose": {
                  "type": "string"
                },
                "recovery_state": {
                  "enum": [
                    "lost",
                    "exposed",
                    "altered",
                    "destroyed",
                    "contained"
                  ],
                  "type": "string"
                },
                "sensitivity": {
                  "enum": [
                    "low",
                    "medium",
                    "high",
                    "special"
                  ],
                  "type": "string"
                }
              },
              "required": [
                "affected_count",
                "data_categories",
                "sensitivity",
                "recovery_state"
              ],
              "type": "object"
            }
          },
          {
            "name": "ai_act_classify",
            "description": "Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric / remote-identification / automated-decision / social-scoring / GPAI flags) and VITNA returns the risk tier (prohibited / high-risk / limited-risk / minimal-risk), GPAI obligations, and the per-tier obligations you would have to meet. A classification for you to act on: VITNA evaluates and records, it does not gate the build.",
            "inputSchema": {
              "properties": {
                "automated_decisions": {
                  "type": "boolean"
                },
                "biometric": {
                  "type": "boolean"
                },
                "data_categories": {
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "general_purpose_ai": {
                  "type": "boolean"
                },
                "remote_identification": {
                  "type": "boolean"
                },
                "sectors": {
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "social_scoring": {
                  "type": "boolean"
                },
                "use_case": {
                  "type": "string"
                }
              },
              "required": [
                "use_case"
              ],
              "type": "object"
            }
          },
          {
            "name": "dpia_threshold_check",
            "description": "Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data categories (and scale / systematic-monitoring / automated-decision / cross-border / vulnerable-subjects flags); returns dpia_required + the 9-criterion WP29 analysis + jurisdiction guidance, so you know whether to pause and assess before proceeding.",
            "inputSchema": {
              "properties": {
                "automated_decision": {
                  "type": "boolean"
                },
                "cross_border": {
                  "type": "boolean"
                },
                "data_categories": {
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "jurisdiction": {
                  "type": "string"
                },
                "processing_purpose": {
                  "type": "string"
                },
                "scale": {
                  "enum": [
                    "small",
                    "medium",
                    "large",
                    "mass"
                  ],
                  "type": "string"
                },
                "systematic_monitoring": {
                  "type": "boolean"
                },
                "vulnerable_subjects": {
                  "type": "boolean"
                }
              },
              "required": [
                "processing_purpose",
                "data_categories"
              ],
              "type": "object"
            }
          },
          {
            "name": "us_sectoral_check",
            "description": "Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given processing profile, so you can factor them in before you act. US-scoped; for Indian sectoral regulators use india_sectoral_check.",
            "inputSchema": {
              "properties": {
                "ai_decisions": {
                  "type": "boolean"
                },
                "counterparty_types": {
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "data_categories": {
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "has_revenue_threshold": {
                  "type": "boolean"
                },
                "processing_purpose": {
                  "type": "string"
                }
              },
              "required": [
                "processing_purpose",
                "data_categories"
              ],
              "type": "object"
            }
          },
          {
            "name": "india_sectoral_check",
            "description": "Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT / PFRDA) from its processing profile, so you know whose rules apply before you act. This analyses your processing to say what applies; for a plain directory of every Indian regulator regardless of your activity, use india_regulators_directory.",
            "inputSchema": {
              "properties": {
                "counterparty_types": {
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "data_categories": {
                  "items": {
                    "type": "string"
                  },
                  "type": "array"
                },
                "processing_purpose": {
                  "type": "string"
                },
                "sector_hint": {
                  "type": "string"
                }
              },
              "required": [
                "processing_purpose",
                "data_categories"
              ],
              "type": "object"
            }
          },
          {
            "name": "india_cross_border_status",
            "description": "Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI / SEBI / IRDAI caveats. Pass the ISO-3166 alpha-2 country code (e.g. US). Stateless lookup: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "country": {
                  "description": "ISO-3166 alpha-2 (e.g. US).",
                  "type": "string"
                }
              },
              "required": [
                "country"
              ],
              "type": "object"
            }
          },
          {
            "name": "japan_cross_border_status",
            "description": "Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the ISO-3166 alpha-2 country code. Stateless lookup: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "country": {
                  "description": "ISO-3166 alpha-2.",
                  "type": "string"
                }
              },
              "required": [
                "country"
              ],
              "type": "object"
            }
          },
          {
            "name": "us_state_breach_deadline",
            "description": "Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without unreasonable delay). This is a static table, not an incident ruling. When you have the actual incident facts and need a reportable / not-reportable decision with reasoning, use breach_classify instead. Stateless lookup: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "state": {
                  "description": "US 2-letter state code (CA, NY, TX, ...).",
                  "type": "string"
                }
              },
              "required": [
                "state"
              ],
              "type": "object"
            }
          },
          {
            "name": "aadhaar_mask",
            "description": "Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless validator: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "aadhaar": {
                  "type": "string"
                }
              },
              "required": [
                "aadhaar"
              ],
              "type": "object"
            }
          },
          {
            "name": "pan_classify",
            "description": "Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "pan": {
                  "type": "string"
                }
              },
              "required": [
                "pan"
              ],
              "type": "object"
            }
          },
          {
            "name": "gstin_validate",
            "description": "Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "gstin": {
                  "type": "string"
                }
              },
              "required": [
                "gstin"
              ],
              "type": "object"
            }
          },
          {
            "name": "cpf_validate",
            "description": "Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "cpf": {
                  "type": "string"
                }
              },
              "required": [
                "cpf"
              ],
              "type": "object"
            }
          },
          {
            "name": "sin_validate",
            "description": "Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "sin": {
                  "type": "string"
                }
              },
              "required": [
                "sin"
              ],
              "type": "object"
            }
          },
          {
            "name": "iban_validate",
            "description": "Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "iban": {
                  "type": "string"
                }
              },
              "required": [
                "iban"
              ],
              "type": "object"
            }
          },
          {
            "name": "pii_test",
            "description": "Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether severity would escalate. Nothing is persisted and nothing is filtered: a safe rehearsal you act on, not an enforced gate — it records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "jurisdiction": {
                  "type": "string"
                },
                "sample_event": {
                  "description": "event_type / message / payload fields.",
                  "type": "object"
                }
              },
              "required": [
                "sample_event"
              ],
              "type": "object"
            }
          },
          {
            "name": "privacy_notice_get",
            "description": "Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "format": {
                  "enum": [
                    "md",
                    "json"
                  ],
                  "type": "string"
                }
              },
              "type": "object"
            }
          },
          {
            "name": "sub_processors_register",
            "description": "Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {},
              "type": "object"
            }
          },
          {
            "name": "global_compliance_map",
            "description": "Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {},
              "type": "object"
            }
          },
          {
            "name": "india_regulators_directory",
            "description": "Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup of who exists and what they cover. To instead work out which of them apply to a specific processing activity, use india_sectoral_check. Stateless lookup: records no decision and leaves no dashboard timeline trace.",
            "inputSchema": {
              "properties": {
                "sector": {
                  "type": "string"
                }
              },
              "type": "object"
            }
          },
          {
            "name": "vitna_preflight",
            "description": "SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the action BEFORE you run it: it flags dangerous shell / SQL / secret-exfil / prompt-injection / suspicious-network patterns and returns { decision: allowed|blocked|flagged }. RESPONSE SHAPE DEPENDS ON THE KEY: an unclaimed trial key gets the decision label only, because the pattern detail is what makes the classifier worth stealing. A claimed key additionally gets threat_category, severity, reason (the rule names that matched, never the matched text), a threats[] array and a redacted echo of what was scanned, plus a signed audit record the user can review. VITNA evaluates and records; it does NOT enforce, so treat blocked / flagged as a stop and get human approval. This is how a user keeps you in check. Heuristic pattern match, not a sandbox: novel or obfuscated payloads can pass.",
            "inputSchema": {
              "properties": {
                "action": {
                  "description": "The proposed action / command text, e.g. \"rm -rf /\" or \"DROP TABLE users\".",
                  "type": "string"
                },
                "action_type": {
                  "description": "Optional short label for the action kind (shell, file_delete, db_query, network).",
                  "type": "string"
                },
                "payload": {
                  "description": "Optional structured payload to scan alongside the action text.",
                  "type": "object"
                }
              },
              "type": "object"
            }
          }
        ]
      },
      "name": "VITNA — Agent Compliance Preflight",
      "note": "Indexed from the official MCP registry: facts and our own checks, not reviewed, so no score, grade or rank.",
      "packages": [
        {
          "registryType": "npm",
          "identifier": "@costrinity/vitna-compliance-mcp",
          "version": "0.5.1",
          "transport": "stdio"
        }
      ],
      "pageJsonUrl": "https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight.json",
      "popularity": {
        "githubStars": 0,
        "npmWeekly": 266
      },
      "registryName": "xyz.costrinity/vitna-compliance-preflight",
      "remotes": [
        {
          "type": "streamable-http",
          "url": "https://vitna.costrinity.xyz/api/mcp"
        }
      ],
      "repository": "https://github.com/COSTRINITY/vitna-compliance-mcp",
      "reviewed": false,
      "slug": "costrinity-vitna-compliance-preflight",
      "source": "the official MCP registry",
      "sourceUrl": "https://registry.modelcontextprotocol.io/v0.1/servers?search=xyz.costrinity/vitna-compliance-preflight",
      "summary": "Pre-action compliance for AI agents: allow, block or hold. 24 statutes, 13 jurisdictions.",
      "updatedAt": "2026-10-04T22:34:25Z",
      "url": "https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight",
      "vendor": "costrinity.xyz",
      "vendorUrl": "https://vitna.costrinity.xyz",
      "version": "0.5.1",
      "websiteUrl": "https://vitna.costrinity.xyz",
      "where": "both",
      "why": [
        "vendor"
      ]
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight",
    "json": "https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight.md",
    "slim": "https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight.min.md"
  },
  "markdown": "# VITNA — Agent Compliance Preflight\n\n\u003e Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/\n\n- Kind: MCP server, by costrinity.xyz (https://vitna.costrinity.xyz)\n- Category: Travel \u0026 booking (https://www.anchorterminal.com/categories/travel.md)\n- Listed because: It's published in the registry under costrinity.xyz, a namespace the registry only gives to whoever proves they control that domain.\n- What the official MCP registry says: Pre-action compliance for AI agents: allow, block or hold. 24 statutes, 13 jurisdictions.\n\n## Facts\n\n- MCP registry: `xyz.costrinity/vitna-compliance-preflight` 0.5.1\n- Endpoint: https://vitna.costrinity.xyz/api/mcp (streamable HTTP)\n- Package: npm `@costrinity/vitna-compliance-mcp` (stdio)\n- Source: https://github.com/COSTRINITY/vitna-compliance-mcp\n- Website: https://vitna.costrinity.xyz\n- npm downloads a week: 266\n- GitHub stars: 0\n- Registry entry updated: 2026-10-04\n\n## Tools\n\n- Tools it lists (23, about 3,293 tokens of context, `tools/list` without credentials, checked 2026-10-04 22:26 UTC):\n  - `vitna_help`: What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check…\n  - `vitna_claim`: Ask whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account,…\n  - `consent_check`: Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and…\n  - `breach_classify`: After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories,…\n  - `ai_act_classify`: Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric /…\n  - `dpia_threshold_check`: Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data…\n  - `us_sectoral_check`: Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given…\n  - `india_sectoral_check`: Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT /…\n  - `india_cross_border_status`: Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI /…\n  - `japan_cross_border_status`: Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the…\n  - `us_state_breach_deadline`: Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without…\n  - `aadhaar_mask`: Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless…\n  - `pan_classify`: Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard…\n  - `gstin_validate`: Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace.\n  - `cpf_validate`: Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace.\n  - `sin_validate`: Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace.\n  - `iban_validate`: Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace.\n  - `pii_test`: Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether…\n  - `privacy_notice_get`: Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard…\n  - `sub_processors_register`: Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace.\n  - `global_compliance_map`: Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision…\n  - `india_regulators_directory`: Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup…\n  - `vitna_preflight`: SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the…\n- How its tools read to an agent (0 errors, 39 warnings, 1 note, about 3,293 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score):\n  - warn TC11 aadhaar_mask: its one parameter, aadhaar, has no description\n  - warn TC11 ai_act_classify: none of its 8 parameters has a description\n  - warn TC11 breach_classify: none of its 6 parameters has a description\n  - warn TC11 cpf_validate: its one parameter, cpf, has no description\n  - warn TC11 dpia_threshold_check: none of its 8 parameters has a description\n  - warn TC11 gstin_validate: its one parameter, gstin, has no description\n  - warn TC11 iban_validate: its one parameter, iban, has no description\n  - warn TC11 india_regulators_directory: its one parameter, sector, has no description\n  - warn TC11 india_sectoral_check: none of its 4 parameters has a description\n  - warn TC11 pan_classify: its one parameter, pan, has no description\n  - warn TC11 pii_test: 1 parameter without a description: jurisdiction\n  - warn TC11 privacy_notice_get: its one parameter, format, has no description\n  - warn TC11 sin_validate: its one parameter, sin, has no description\n  - warn TC11 us_sectoral_check: none of its 5 parameters has a description\n  - warn TC13 pii_test: sample_event (object with no properties)\n  - warn TC13 vitna_preflight: payload (object with no properties)\n  - warn TC16 aadhaar_mask: no readOnlyHint or destructiveHint\n  - warn TC16 ai_act_classify: no readOnlyHint or destructiveHint\n  - warn TC16 breach_classify: no readOnlyHint or destructiveHint\n  - warn TC16 consent_check: no readOnlyHint or destructiveHint\n  - warn TC16 cpf_validate: no readOnlyHint or destructiveHint\n  - warn TC16 dpia_threshold_check: no readOnlyHint or destructiveHint\n  - warn TC16 global_compliance_map: no readOnlyHint or destructiveHint\n  - warn TC16 gstin_validate: no readOnlyHint or destructiveHint\n\n- JSON: https://www.anchorterminal.com/api/v1/tools/costrinity-vitna-compliance-preflight.json\n- Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Indexed",
        "url": "https://www.anchorterminal.com/indexed/"
      },
      {
        "name": "VITNA — Agent Compliance Preflight",
        "url": ""
      }
    ],
    "description": "VITNA — Agent Compliance Preflight, an MCP server by costrinity.xyz, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Pre-action compliance for AI agents: allow, block or hold. 24 statutes, 13 jurisdictions.",
    "facts": [
      "not reviewed",
      "not ranked",
      "facts only"
    ],
    "h1": "VITNA — Agent Compliance Preflight",
    "image": "https://www.anchorterminal.com/assets/og/indexed.png",
    "path": "/tools/costrinity-vitna-compliance-preflight",
    "published": "",
    "section": "indexed",
    "title": "VITNA — Agent Compliance Preflight | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight"
  },
  "tokens": {
    "markdown": 2050,
    "slim": 1980
  },
  "version": 1
}
