LaunchTrust

Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
83%
Naming quality
93%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~1,176Tokens (tool definitions)
~484 BTypical response size
Moderate attention impact (0.92% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "launchtrust": {
      "url": "https://mcp.launchtrust.co/mcp"
    }
  }
}

Remote endpoints

https://mcp.launchtrust.co/mcpstreamable-http

What it can do

Tool inventory

Tools (9)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢scan_url(url)

Run a FREE LaunchTrust compliance + security quick-scan on a public web URL. Returns a focused SUBSET of checks — leaked frontend secrets/API keys, exposed .env//.git, security headers, HTTPS/HSTS, missing privacy/terms pages, trackers/cookie banner, and AI-interaction disclosure. The result is unsigned and not stored. The full 27-detector signed, dated, continuously-monitored scan requires a LaunchTrust account. Compliance aid, not legal advice.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Public http(s) URL to scan, e.g. https://example.com"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
🟢list_jurisdictions

List the jurisdictions and categories LaunchTrust tracks (e.g. EU AI Act, GDPR, US state privacy laws, app-store policies). Public coverage registry. Compliance aid, not legal advice.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟢get_compliance_rules(jurisdiction)

Fetch LaunchTrust's sourced, founder-reviewed compliance rule snapshots, optionally filtered to one jurisdiction code (e.g. eu-ai-act-50, gdpr, ca-sb243). Compliance aid, not legal advice.

Input Schema

{
  "type": "object",
  "properties": {
    "jurisdiction": {
      "type": "string",
      "description": "Optional jurisdiction code to filter by, e.g. gdpr or eu-ai-act-50."
    }
  },
  "additionalProperties": false
}
🟢verify_record(record)

Independently verify the ECDSA (ES256) signature on a LaunchTrust signed scan/disclosure record against the published public key. Pass the record JSON (the downloaded record, or an object containing `canonical` and `signature`).

Input Schema

{
  "type": "object",
  "properties": {
    "record": {
      "type": "object",
      "description": "The LaunchTrust signed record JSON (or an object with `canonical` + `signature`).",
      "additionalProperties": true
    }
  },
  "required": [
    "record"
  ],
  "additionalProperties": false
}
🟢list_my_apps

List the apps registered in your LaunchTrust account, with each one's latest scan status. Requires a LaunchTrust token.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪register_app(url, name)

Register a web URL in your LaunchTrust account so it can be fully scanned and monitored. Idempotent — if the URL is already registered, returns the existing app. Requires a LaunchTrust token and an active subscription.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Public https URL of the app to register."
    },
    "name": {
      "type": "string",
      "description": "Optional label (defaults to the hostname)."
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
⚪scan_app(app_id)

Run the full LaunchTrust scan on one of your registered apps and store a signed, dated evidence record. Requires a LaunchTrust token and an active subscription. Limited to 5 scans per app per day.

Input Schema

{
  "type": "object",
  "properties": {
    "app_id": {
      "type": "string",
      "description": "The id of a registered app (see list_my_apps or register_app)."
    }
  },
  "required": [
    "app_id"
  ],
  "additionalProperties": false
}
🟢get_scan_history(app_id)

List recent scans (summary + findings) for one of your registered apps. Requires a LaunchTrust token.

Input Schema

{
  "type": "object",
  "properties": {
    "app_id": {
      "type": "string",
      "description": "The id of a registered app."
    }
  },
  "required": [
    "app_id"
  ],
  "additionalProperties": false
}
🟢get_market_report(app_id)

Get the latest scan for one of your registered apps, with each finding annotated by the jurisdictions and rules applicable to that app's target markets. Requires a LaunchTrust token.

Input Schema

{
  "type": "object",
  "properties": {
    "app_id": {
      "type": "string",
      "description": "The id of a registered app."
    }
  },
  "required": [
    "app_id"
  ],
  "additionalProperties": false
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded9 tools
verifiedversion not recorded9 tools