FillTrust security questionnaire corpus

Guidance for answering vendor security questionnaires. Every result carries the page it came from.

使うべきか

品質と安全性

A
説明の品質
92%
スキーマの完全性
70%
命名の品質
100%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~515トークン数(ツール定義)
~440 B一般的なレスポンスサイズ
注意への影響は最小限(128k コンテキストの 0.40%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "questions": {
      "url": "https://www.filltrust.com/api/mcp"
    }
  }
}

リモートエンドポイント

https://www.filltrust.com/api/mcpstreamable-http

できること

ツール一覧

ツール(5)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢search_questions(query, limit)

Find guidance on how to answer a security questionnaire question. Search by the question text, a control area, or a standard and control identifier such as CEK-03. Returns matching entries with the URL of the page each came from.

入力スキーマ

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "The questionnaire question, or words from it. Pasting the row from the spreadsheet works."
    },
    "limit": {
      "type": "integer",
      "description": "How many results to return. Defaults to 8.",
      "minimum": 1,
      "maximum": 25
    }
  },
  "required": [
    "query"
  ]
}
🟢get_question(slug)

The complete published guidance for one questionnaire question: what it is really asking, which of your documents answers it, what evidence to attach, a model answer with the specifics left blank, the ways it usually goes wrong, and the standards that ask it with their verified control references.

入力スキーマ

{
  "type": "object",
  "properties": {
    "slug": {
      "type": "string",
      "description": "The slug from a search_questions result, for example \"encryption-at-rest\"."
    }
  },
  "required": [
    "slug"
  ]
}
🟢list_standards

Which questionnaire standards this corpus answers questions from, how many questions each has, and which controls are cited. Standards whose control lists are proprietary are named without reference numbers, on purpose.

入力スキーマ

{
  "type": "object",
  "properties": {}
}
🟢get_filltrust_posture

FillTrust's own answers to the questions it exists to answer, for anyone assessing it as a vendor. Includes the answers that are "no".

入力スキーマ

{
  "type": "object",
  "properties": {}
}
🟢get_questionnaire_statistics(questionnaire)

Measured counts from 146 real vendor security questionnaires (17,697 questions) published by universities, purchasing consortia and companies: which topics are asked most, and detailed profiles of the questionnaires that have a name people use, such as HECVAT and CAIQ. Use this when asked what a security questionnaire contains, how long one is, or what a named questionnaire asks about. These are counts from real files rather than an estimate.

入力スキーマ

{
  "type": "object",
  "properties": {
    "questionnaire": {
      "type": "string",
      "description": "Optional. A named questionnaire to profile, for example \"HECVAT\" or \"CAIQ\". Omit for the corpus-wide topic counts."
    }
  }
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 5 件
検証済みバージョンは記録されていませんツール 5 件