# VITNA — Agent Compliance Preflight (slim) > VITNA — Agent Compliance Preflight, an MCP server by costrinity.xyz, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Pre-action compliance for AI agents: allow, block or hold. 24 statutes, 13 jurisdictions. - Full: https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight.md (~2,050 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight.json · canonical https://www.anchorterminal.com/tools/costrinity-vitna-compliance-preflight - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 # VITNA — Agent Compliance Preflight > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by costrinity.xyz (https://vitna.costrinity.xyz) - Category: Travel & booking (https://www.anchorterminal.com/categories/travel.md) - Listed because: It's published in the registry under costrinity.xyz, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: Pre-action compliance for AI agents: allow, block or hold. 24 statutes, 13 jurisdictions. ## Facts - MCP registry: `xyz.costrinity/vitna-compliance-preflight` 0.5.1 - Endpoint: https://vitna.costrinity.xyz/api/mcp (streamable HTTP) - Package: npm `@costrinity/vitna-compliance-mcp` (stdio) - Source: https://github.com/COSTRINITY/vitna-compliance-mcp - Website: https://vitna.costrinity.xyz - npm downloads a week: 266 - GitHub stars: 0 - Registry entry updated: 2026-10-04 ## Tools - Tools it lists (23, about 3,293 tokens of context, `tools/list` without credentials, checked 2026-10-04 22:26 UTC): - `vitna_help`: What is VITNA and how do I use it to keep myself in check? Call this FIRST after connecting to learn the safety and oversight checks available: how to check… - `vitna_claim`: Ask whether this VITNA account has been claimed by a real person yet, and get the link that claims it. Call this when the user asks about their VITNA account,… - `consent_check`: Before you process someone's personal data, ask VITNA whether an active consent actually permits it for this purpose. Give the data principal + purpose (and… - `breach_classify`: After a security incident, check whether it is legally reportable before you decide how to respond. Give the incident facts (affected count, data categories,… - `ai_act_classify`: Before you build or ship an AI feature, check where it lands under the EU AI Act (Regulation 2024/1689). Describe the use case (with biometric /… - `dpia_threshold_check`: Before you start a new processing activity, check whether the law requires a DPIA first (GDPR Art 35 / DPDP §10 / LGPD Art 38). Give the purpose + data… - `us_sectoral_check`: Before you process personal data under US law, find out which US federal sectoral regimes bind you (HIPAA, GLBA, COPPA, FERPA, FCRA, SOX) for a given… - `india_sectoral_check`: Before you process personal data under Indian law, find out which sectoral regulators actually bind your specific activity (RBI / SEBI / IRDAI / TRAI / DoT /… - `india_cross_border_status`: Before you transfer personal data out of India, check the destination country's DPDP §16 status (permitted / restricted / sectoral_restricted) plus any RBI /… - `japan_cross_border_status`: Before you transfer personal data out of Japan, check the destination country's APPI Art 28 status (adequacy / standard basis / high scrutiny). Pass the… - `us_state_breach_deadline`: Quick reference lookup of a single US state's breach-notification window, AG recipient and resident threshold (e.g. 'CA' gives 500 residents, CA AG, without… - `aadhaar_mask`: Mask + Verhoeff-validate an Aadhaar number. Returns masked form, validity, and an owner-scoped reference token. No persistence of the raw value. Stateless… - `pan_classify`: Classify a PAN entity type from the 4th character (P=Person, C=Company, H=HUF, F=Firm, ...). Stateless validator: records no decision and leaves no dashboard… - `gstin_validate`: Validate a GSTIN format + mod-36 check digit; returns state code lookup. Stateless validator: records no decision and leaves no dashboard timeline trace. - `cpf_validate`: Validate a Brazilian CPF (mod-11 check digits, rejects all-same). Stateless validator: records no decision and leaves no dashboard timeline trace. - `sin_validate`: Validate a Canadian SIN (Luhn checksum); returns series region + masked form. Stateless validator: records no decision and leaves no dashboard timeline trace. - `iban_validate`: Validate an IBAN format + ISO 7064 mod-97 check digit; supports 71 countries. Stateless validator: records no decision and leaves no dashboard timeline trace. - `pii_test`: Dry-run VITNA's PII / threat detection on a sample event before you send real data, to preview what would be tagged, how it would be redacted, and whether… - `privacy_notice_get`: Generate the operator's jurisdiction-templated privacy notice. Returns markdown or JSON. Stateless generator: records no decision and leaves no dashboard… - `sub_processors_register`: Return the public sub-processor register (Supabase, Vercel, Resend, etc.). Stateless lookup: records no decision and leaves no dashboard timeline trace. - `global_compliance_map`: Master catalogue of every privacy/security/sectoral regime VITNA has fabric for (28 entries covering 24 named statutes). Stateless lookup: records no decision… - `india_regulators_directory`: Static reference directory of Indian data and sector regulators (DPB, RBI, SEBI, IRDAI, TRAI, DoT, PFRDA, MeitY, MCA), optionally filtered by sector: a lookup… - `vitna_preflight`: SAFETY / OVERSIGHT CHECK before a dangerous or destructive action (shell command, file deletion, DB statement, network call). Call this to have VITNA check the… - How its tools read to an agent (0 errors, 39 warnings, 1 note, about 3,293 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - warn TC11 aadhaar_mask: its one parameter, aadhaar, has no description - warn TC11 ai_act_classify: none of its 8 parameters has a description - warn TC11 breach_classify: none of its 6 parameters has a description - warn TC11 cpf_validate: its one parameter, cpf, has no description - warn TC11 dpia_threshold_check: none of its 8 parameters has a description - warn TC11 gstin_validate: its one parameter, gstin, has no description - warn TC11 iban_validate: its one parameter, iban, has no description - warn TC11 india_regulators_directory: its one parameter, sector, has no description - warn TC11 india_sectoral_check: none of its 4 parameters has a description - warn TC11 pan_classify: its one parameter, pan, has no description - warn TC11 pii_test: 1 parameter without a description: jurisdiction - warn TC11 privacy_notice_get: its one parameter, format, has no description - warn TC11 sin_validate: its one parameter, sin, has no description - warn TC11 us_sectoral_check: none of its 5 parameters has a description - warn TC13 pii_test: sample_event (object with no properties) - warn TC13 vitna_preflight: payload (object with no properties) - warn TC16 aadhaar_mask: no readOnlyHint or destructiveHint - warn TC16 ai_act_classify: no readOnlyHint or destructiveHint - warn TC16 breach_classify: no readOnlyHint or destructiveHint - warn TC16 consent_check: no readOnlyHint or destructiveHint - warn TC16 cpf_validate: no readOnlyHint or destructiveHint - warn TC16 dpia_threshold_check: no readOnlyHint or destructiveHint - warn TC16 global_compliance_map: no readOnlyHint or destructiveHint - warn TC16 gstin_validate: no readOnlyHint or destructiveHint - JSON: https://www.anchorterminal.com/api/v1/tools/costrinity-vitna-compliance-preflight.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming