Skip to content
MCP server

LaunchTrust

By launchtrustAll Launchtrust servers

Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.

Listed on

First seen 2 Oct 2026. One server, whatever directories list it: each directory listing keeps its own page and history.

3
Directories
2 via MCP Toplist
9
Tools
From an anonymous probe
-
ToolBench grade
Not graded by Arcade
0
GitHub stars
From MCP Toplist

Tools

ToolDescriptionBehaviour
get_compliance_rulesFetch LaunchTrust's sourced, founder-reviewed compliance rule snapshots, optionally filtered to one jurisdiction code (e.g. eu-ai-act-50, gdpr, ca-sb243). Compliance aid, not legal advice.Read-only
get_market_reportGet the latest scan for one of your registered apps, with each finding annotated by the jurisdictions and rules applicable to that app's target markets. Requires a LaunchTrust token.Read-only
get_scan_historyList recent scans (summary + findings) for one of your registered apps. Requires a LaunchTrust token.Read-only
list_jurisdictionsList the jurisdictions and categories LaunchTrust tracks (e.g. EU AI Act, GDPR, US state privacy laws, app-store policies). Public coverage registry. Compliance aid, not legal advice.Read-only
list_my_appsList the apps registered in your LaunchTrust account, with each one's latest scan status. Requires a LaunchTrust token.Read-only
register_appRegister a web URL in your LaunchTrust account so it can be fully scanned and monitored. Idempotent — if the URL is already registered, returns the existing app. Requires a LaunchTrust token and an active subscription.Changes data
scan_appRun the full LaunchTrust scan on one of your registered apps and store a signed, dated evidence record. Requires a LaunchTrust token and an active subscription. Limited to 5 scans per app per day.Changes data
scan_urlRun a FREE LaunchTrust compliance + security quick-scan on a public web URL. Returns a focused SUBSET of checks — leaked frontend secrets/API keys, exposed .env//.git, security headers, HTTPS/HSTS, missing privacy/terms pages, trackers/cookie banner, and AI-interaction disclosure. The result is unsigned and not stored. The full 27-detector signed, dated, continuously-monitored scan requires a LaunchTrust account. Compliance aid, not legal advice.Read-only
verify_recordIndependently verify the ECDSA (ES256) signature on a LaunchTrust signed scan/disclosure record against the published public key. Pass the record JSON (the downloaded record, or an object containing `canonical` and `signature`).Read-only

Directory listings

DirectoryListingTierFirst seen
Official MCP RegistryLaunchTrust-2 Oct 2026
GlamaListed there according to MCP Toplist’s dataset; not collected by InvokeRank.
PulseMCPListed there according to MCP Toplist’s dataset; not collected by InvokeRank.