trustlists Plugin

MCP serverDev tools

Lets your agent find vendor trust centers, review SOC 2 reports, and request access to them.

Unavailable. This server has no hosted endpoint yet, so Ahel can't serve it.

Add to setup to save this item as a reference. Ahel cannot run it, and signing in will not install it.

About this server

Find public vendor trust centers, analyze SOC 2 reports, and request trust-center access.

Getting started

  1. Save this item in Your setup as a reference.
  2. Read the source or reference documentation for its setup requirements. Saving it here does not connect it to your AI.
  3. Check this page for availability before trying to install it through Ahel.

From the project's README

As published by trustlists/trustlists-plugin in README.md.

What it does

The trustlists_ plugin gives your AI assistant access to thousands of public company trust center records, local SOC 2 analysis, and SafeBase/Vanta access requests.

Tools

ToolWhat it doesCost
trustlists_searchSearch thousands of trust centers by name or domainFree
trustlists_lookupLook up a single vendor by exact domainFree
trustlists_browseFilter by platform, listed framework, or CSA STAR levelFree
trustlists_audit_dependenciesAudit package.json, requirements.txt, go.mod, etc.Free
trustlists_login / whoami / logoutDevice-code sign-in (~/.trustlists/auth.json)Free
trustlists_soc2_analyze / status / reportAnalyze local SOC 2 PDFs after a credit previewCredits
trustlists_requester_profileIdentity used on vendor access formsFree
trustlists_access_request / status / continue / request_batchRequest SafeBase or Vanta access (max 5 per batch)Free (beta)

Hosted endpoint (ChatGPT and other remote clients)

https://mcp.trustlists.org/mcp serves the same tools over Streamable HTTP after an OAuth sign-in with a trustlists account (Google or Microsoft). Connecting the app replaces trustlists_login and trustlists_logout. Because a hosted server cannot read your disk, the dependency audit takes pasted manifest text, and SOC 2 PDFs are uploaded in the trustlists app via trustlists_soc2_upload.

Skills

The plugin ships with skills your AI assistant uses automatically:

  • lookup-vendor - Find a vendor's trust center and listed frameworks
  • audit-dependencies - Map project dependencies to public trust center records
  • compliance-quick-check - Check whether a directory record lists a requested framework
  • sign-in - Connect a trustlists account with a device code
  • analyze-soc2 - Preview credits, then analyze a local SOC 2 PDF
  • request-trust-center-access - Complete the requester profile and request access

Example usage

In Cursor or Claude Code, just ask:

"Look up Stripe's trust center"

"Audit my package.json for vendor security"

"Does Datadog's trust center list HIPAA information?"

The AI uses the plugin's tools to answer with current public trustlists data. A directory record is a discovery aid, not an audit, certification, endorsement, or security rating.

Quick Install (Cursor, Claude Desktop, Claude Code)

Add this to your MCP config and restart:

{
  "mcpServers": {
    "trustlists": {
      "command": "npx",
      "args": ["-y", "@trustlists/mcp"]
    }
  }
}
AppConfig location
CursorSettings → MCP → Edit config (or ~/.cursor/mcp.json)
Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.json
Claude Code~/.claude/settings.json or .claude/settings.json in your project

Full installation guide → (includes troubleshooting)

Pricing

The directory and audit tools are free and require no trustlists account. SOC 2 analysis and access requests use a device-code login on the local MCP.

  • Free MCP tools - Search, lookup, browse, and dependency mapping
  • Signed-in MCP tools - SOC 2 analysis (credits) and trust-center access requests
  • Companion - The same account workflows in the browser at app.trustlists.org

Visit the MCP overview for setup and tool details, or trustlists.org for the full directory and Companion subscriptions.

Development

# Install dependencies
npm install

# Build the MCP server
npm run build

# Test locally
npm run test:local

See docs/development.md for the full development guide.

License

Apache 2.0. See LICENSE and NOTICE.

Links

Signals

Last commit
Oct 2026
Weekly_downloads
33 weekly_downloads
Advanced
Delivery
trustlists MCP server → your Ahel connector (mcp.ahel.ai) → your AI.
Item type
mcp-server
Key
io-github-trustlists-mcp
Source
github.com/trustlists/trustlists-plugin