NORMA MCP Server

NORMA MCP Server

Free hosted MCP server for EU compliance, enabling search across 8 frameworks, cross-framework mapping, policy generation, and gap assessment via natural language.

Category
访问服务器

README

NORMA MCP Server

Il corpus di compliance EU di Kynosure, esposto come server MCP gratuito. EU compliance corpus across 8 frameworks (NIS2, DORA, ISO 27001, ISO 42001, EU AI Act, ISO 22301, ISO 27701, CRA), exposed as a free hosted Model Context Protocol server by Kynosure.


Disclaimer. Questo software produce bozze di policy + analisi di gap a partire da fonti regolatorie pubbliche e dalla ricerca metodologica Kynosure. Non costituisce consulenza legale. Ogni output va revisionato da un professionista legale/compliance qualificato prima di adozione in produzione.

Disclaimer. This software drafts policies and gap analyses from public regulatory sources and Kynosure methodology research. It is not legal advice and not a substitute for qualified counsel. Review every output with a qualified legal/compliance professional before adoption in production.


Install

The fastest path is the Claude Code one-liner. From any terminal:

claude mcp add --transport http norma https://norma-mcp.kynosure.ai/mcp

That's it. Open a Claude Code session in any working directory, run /mcp, and you should see four tools: search_controls, map_controls, generate_policy, assess_gap.

Anonymous tier is 10 calls/hour per IP — no signup, no API key, no env vars.

Cursor

Add to your project's .cursor/mcp.json:

{
  "mcpServers": {
    "norma": {
      "url": "https://norma-mcp.kynosure.ai/mcp"
    }
  }
}

Claude Desktop (stdio bridge fallback)

Claude Desktop's claude_desktop_config.json does not yet officially accept a top-level url field. Two paths:

  1. Settings -> Connectors -> Add custom server (the UI path) and paste https://norma-mcp.kynosure.ai/mcp.
  2. stdio bridge fallback via mcp-remote:
{
  "mcpServers": {
    "norma": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://norma-mcp.kynosure.ai/mcp"]
    }
  }
}

What's inside

Four tools, each with Zod-validated inputs and a not-legal-advice disclaimer on the response:

  • search_controls — Full-text search across the NORMA corpus, filtered by framework + keyword.
  • map_controls — Cross-framework crosswalk (e.g. "map ISO 27001 to NIS2") via curated cross_references adjacency.
  • generate_policy — Parametrized policy draft from a curated template (substitutes {{COMPANY_NAME}}, {{SECTOR}}, {{SIZE}}, {{JURISDICTION}} and prepends a not-legal-advice header).
  • assess_gap — Indicative covered/partial/gap register for a target framework, driven by your existing certifications + sector profile. Pointer to Pyxis for full FCI/WMI/ECI scoring.

Example prompts

These trigger the tools automatically from a Claude Code session with NORMA installed:

  1. Search

    "Using NORMA, what controls does NIS2 require for access management?"

    Invokes search_controls with framework: 'nis2' + keyword: 'access'. Returns control slugs, titles, source-refs, excerpts around the match.

  2. Gap assessment

    "Using NORMA, I'm ISO 27001 certified and operate in a critical sector (energy, medium-sized). What are my NIS2 gaps?"

    Invokes assess_gap with the company profile booleans. Returns counts of covered/partial/gap controls + a pointer to Pyxis for severity-ranked scoring.

  3. Policy generation

    "Using NORMA, generate an information security policy for Acme SRL, a small Italian SaaS company."

    Invokes generate_policy with the relevant template slug + your company context. Returns a parametrized markdown draft with a prominent disclaimer header and footer.

Two doors, same house

NORMA reaches you through two equally first-class distribution surfaces. Pick the door that matches your platform and trust posture:

MCP Server (this repo) Claude Skill
Delivery Live HTTPS service Bundled local plugin
Corpus freshness Always-fresh (server reads at runtime) Pinned at install time
Network required Yes No (offline after install)
Client compatibility Any MCP client (Claude Code, Cursor, Claude Desktop, custom) Claude Code only
Observable usage Yes (counters at /about) No
Privacy posture Server-side counters only, source-auditable Fully local

Neither is hierarchical. Same corpus, different delivery shape. The Skill is the right choice when you want a snapshot you control offline; the MCP Server is the right choice when you want the freshest corpus and observability.

Privacy

This server logs counters only — never inputs, never request bodies, never IPs beyond the rate-limit bucket. The privacy posture is verifiable in source, not just claimed:

  • Privacy policy: https://kynosure.ai/en/norma/mcp-privacy
  • Source-level proof: see src/log.ts for the actual logger — that's the audit trail. The function whitelists scalar fields and physically drops Error objects, request bodies, and IPs before they reach stdout. Anyone can git clone and verify the privacy promise for themselves.
  • Architecture: "open code, private data" — corpus is read at runtime from a private Cloud Storage bucket in the kynosure-ai GCP project via a runtime service account with bucket-scoped read-only IAM. The service code is fully public; the corpus stays in a private bucket.

FAQ

What are the rate limits? Anonymous tier: 10 calls/hour per IP, enforced at the Cloudflare edge + a defense-in-depth in-app limiter. When you hit the limit, the 429 response points at the signup flow.

Do I need an API key? Not for v1.0.0 — the anonymous tier is the front door. An API-key tier (100 calls/hour, email-captured signup) is planned for v1.1 once we see anonymous-tier traction.

Which corpus version does this serve? The immutable norma-corpus-v1.0.0 tag from the upstream Kynosure repository. See PROVENANCE.md for the byte-identical mirror manifest (sha256 verified).

Which frameworks are covered? Eight: NIS2, DORA, ISO 27001, ISO 42001, EU AI Act, ISO 22301, ISO 27701, CRA. The strategic subset distributed publicly is 32 templates focused on the EU AI Act + ISO 42001 wedge — see PUBLIC-SUBSET.md in the upstream Kynosure repo for the full inventory.

Can I use this offline? This MCP server is hosted, so no — use the NORMA Claude Skill for an offline bundled experience.

Is this a replacement for Pyxis? No. NORMA distributes; Pyxis assesses. This MCP server returns indicative search results and gap counts; the full severity-ranked cross-framework gap register with FCI/WMI/ECI scoring + sector-profiled controls + methodology-backed PDF lives at https://kynosure.ai/en/pyxis.

License

MIT, with a not-legal-advice clause appended. See LICENSE for the full text.

Provenance

The NORMA corpus origin, license posture, and editorial provenance are attested in PROVENANCE.md, mirrored byte-identically from the norma-corpus-v1.0.0 tag in the upstream Kynosure repository. The byte-identical invariant is the audit trail.

About Kynosure

This MCP server is built and maintained by Kynosure, a European compliance platform. The server exposes 4 tools — search_controls, map_controls, generate_policy, assess_gap — that route compliance questions through a curated subset of the Kynosure corpus covering NIS2, DORA, ISO 27001, ISO 22301, ISO 42001, ISO 27701, CRA, and the EU AI Act. The corpus itself is served at runtime from a private Cloud Storage bucket ("open code, private data" pattern) so the strategic-subset boundary stays enforced at the data layer, not just the code layer.

For the full multi-framework assessment, sector-profiled scoring, and methodology-backed PDF reports, see kynosure.ai.


Catalogue + side-by-side decision matrix:

Kynosure

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选