{"_id":"@ansvar/us-law-mcp","_rev":"3-ae5402593f672bb07b830c81da7b70e7","name":"@ansvar/us-law-mcp","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@ansvar/us-law-mcp","version":"0.1.0","keywords":["mcp","model-context-protocol","ai","claude","us-law","united-states","legal","cybersecurity","privacy","breach-notification","compliance","federal","state-law","ansvar"],"author":{"name":"Ansvar Systems AB","email":"hello@ansvar.ai"},"license":"Apache-2.0","_id":"@ansvar/us-law-mcp@0.1.0","maintainers":[{"name":"ansvar","email":"jeffrey.von.rotz@ansvar.eu"}],"homepage":"https://github.com/Ansvar-Systems/US-law-mcp#readme","bugs":{"url":"https://github.com/Ansvar-Systems/US-law-mcp/issues"},"bin":{"us-law-mcp":"dist/index.js"},"dist":{"shasum":"59c63f73d31865e04c349161acd0c68f20dd1db6","tarball":"https://registry.npmjs.org/@ansvar/us-law-mcp/-/us-law-mcp-0.1.0.tgz","fileCount":46,"integrity":"sha512-tQ6soS7lzg/g0sLWru3wwo3jKSvWKQr8KRhvPELaCQI/QcGdz0uppIpggLiIfZGcPf0PL81mPYlWDd/ufWOQ9g==","signatures":[{"sig":"MEUCIBAPX/vaWLfXL85qGErjM6bQ+kxcZGcUAh2YYXwqecwdAiEA4UFBKXVpyHivtZRdv2FH6P+X5GrK9FcMsWwBT8c6WVw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3289580},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"gitHead":"1f518fc846fa7e4ababea9ba4ddae78f512ff465","mcpName":"eu.ansvar/us-law-mcp","scripts":{"dev":"tsx src/index.ts","lint":"eslint src/ __tests__/","test":"vitest run --exclude __tests__/contract/**","build":"tsc","start":"node dist/index.js","format":"prettier --write .","build:db":"tsx scripts/build-db.ts","lint:fix":"eslint --fix src/ __tests__/","validate":"npm run lint && npm test && npm run test:contract","fetch:all":"npm run fetch:federal && npm run fetch:states","ingest:all":"npm run ingest:federal && npm run ingest:states && npm run ingest:classify","test:watch":"vitest","fetch:states":"tsx scripts/fetch-states.ts","format:check":"prettier --check .","build:db:free":"tsx scripts/build-db-free.ts","check:updates":"tsx scripts/check-uscode-updates.ts","fetch:federal":"tsx scripts/fetch-uscode.ts","ingest:states":"tsx scripts/ingest/states.ts","test:contract":"vitest run __tests__/contract/","test:coverage":"vitest run --coverage","ingest:federal":"tsx scripts/ingest/federal.ts","prepublishOnly":"npm run build:db && npm run ingest:all && npm run build","ingest:classify":"tsx scripts/ingest/classify.ts","fetch:states:lawserver":"tsx scripts/fetch-states-lawserver.ts"},"_npmUser":{"name":"ansvar","email":"jeffrey.von.rotz@ansvar.eu"},"repository":{"url":"git+https://github.com/Ansvar-Systems/US-law-mcp.git","type":"git"},"_npmVersion":"11.6.2","description":"US federal and state cybersecurity/privacy law MCP server with cross-state comparison","directories":{},"_nodeVersion":"25.2.1","dependencies":{"@ansvar/mcp-sqlite":"^1.0.0","@modelcontextprotocol/sdk":"^1.25.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","eslint":"^9.27.0","vitest":"^4.0.18","cheerio":"^1.2.0","prettier":"^3.5.3","@eslint/js":"^9.27.0","typescript":"^5.9.3","@types/node":"^22.15.29","@vercel/node":"^5.6.3","@types/cheerio":"^0.22.35","fast-xml-parser":"^5.3.6","typescript-eslint":"^8.33.1","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/us-law-mcp_0.1.0_1771572465409_0.6114500592184018","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Ansvar MCP servers are now distributed as source from github.com/Ansvar-Systems/us-law-mcp under Apache 2.0. Self-hosting instructions: see the repo README. Hosted gateway: ansvar.eu"},"0.1.1":{"name":"@ansvar/us-law-mcp","version":"0.1.1","keywords":["mcp","model-context-protocol","ai","claude","us-law","united-states","legal","cybersecurity","privacy","breach-notification","compliance","federal","state-law","ansvar"],"author":{"name":"Ansvar Systems AB","email":"hello@ansvar.ai"},"license":"Apache-2.0","_id":"@ansvar/us-law-mcp@0.1.1","maintainers":[{"name":"ansvar","email":"jeffrey.von.rotz@ansvar.eu"}],"homepage":"https://github.com/Ansvar-Systems/US-law-mcp#readme","bugs":{"url":"https://github.com/Ansvar-Systems/US-law-mcp/issues"},"bin":{"us-law-mcp":"dist/index.js"},"dist":{"shasum":"c2c80c41386e2caa424a7e2e97cc3ad3c3161ef0","tarball":"https://registry.npmjs.org/@ansvar/us-law-mcp/-/us-law-mcp-0.1.1.tgz","fileCount":47,"integrity":"sha512-Mho5GCoH5bNsk5kqhDORcyRR6a5DjxnaVnaaID9tba8HXSkABoZi7qkCZoIChzn645Cx7vplpjjJQcla8DvzBw==","signatures":[{"sig":"MEUCIHo5WAzpVJeHDQC01JlUrSJ723Hf0DuFGUGjotmjDhGnAiEAmVLwVo33L0cRaLffKkAx4bdJKA0+L6DbIaz5mhzzNOY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ansvar%2fus-law-mcp@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3294717},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"gitHead":"02ab0b1c350b14b2690495d4ceea06019f36d1d9","mcpName":"eu.ansvar/us-law-mcp","scripts":{"dev":"tsx src/index.ts","lint":"eslint src/ __tests__/","test":"vitest run --exclude __tests__/contract/**","build":"tsc","start":"node dist/index.js","format":"prettier --write .","build:db":"tsx scripts/build-db.ts","lint:fix":"eslint --fix src/ __tests__/","validate":"npm run lint && npm test && npm run test:contract","fetch:all":"npm run fetch:federal && npm run fetch:states","ingest:all":"npm run ingest:federal && npm run ingest:states && npm run ingest:classify","test:watch":"vitest","fetch:states":"tsx scripts/fetch-states.ts","format:check":"prettier --check .","build:db:free":"tsx scripts/build-db-free.ts","check:updates":"tsx scripts/check-uscode-updates.ts","fetch:federal":"tsx scripts/fetch-uscode.ts","ingest:states":"tsx scripts/ingest/states.ts","test:contract":"vitest run __tests__/contract/","test:coverage":"vitest run --coverage","ingest:federal":"tsx scripts/ingest/federal.ts","prepublishOnly":"npm run build:db && npm run ingest:all && npm run build","ingest:classify":"tsx scripts/ingest/classify.ts","fetch:states:lawserver":"tsx scripts/fetch-states-lawserver.ts"},"_npmUser":{"name":"ansvar","email":"jeffrey.von.rotz@ansvar.eu"},"repository":{"url":"git+https://github.com/Ansvar-Systems/US-law-mcp.git","type":"git"},"_npmVersion":"10.8.2","description":"US federal and state cybersecurity/privacy law MCP server with cross-state comparison","directories":{},"_nodeVersion":"20.20.0","dependencies":{"@ansvar/mcp-sqlite":"^1.0.0","@modelcontextprotocol/sdk":"^1.25.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","eslint":"^9.27.0","vitest":"^4.0.18","cheerio":"^1.2.0","prettier":"^3.5.3","@eslint/js":"^9.27.0","typescript":"^5.9.3","@types/node":"^22.15.29","@vercel/node":"^5.6.3","@types/cheerio":"^0.22.35","fast-xml-parser":"^5.3.6","typescript-eslint":"^8.33.1","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/us-law-mcp_0.1.1_1771782125409_0.023726469963661012","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Ansvar MCP servers are now distributed as source from github.com/Ansvar-Systems/us-law-mcp under Apache 2.0. Self-hosting instructions: see the repo README. Hosted gateway: ansvar.eu"}},"time":{"created":"2026-02-20T07:27:45.353Z","modified":"2026-05-02T05:50:00.012Z","0.1.0":"2026-02-20T07:27:45.676Z","0.1.1":"2026-02-22T17:42:05.611Z"},"bugs":{"url":"https://github.com/Ansvar-Systems/US-law-mcp/issues"},"author":{"name":"Ansvar Systems AB","email":"hello@ansvar.ai"},"license":"Apache-2.0","homepage":"https://github.com/Ansvar-Systems/US-law-mcp#readme","keywords":["mcp","model-context-protocol","ai","claude","us-law","united-states","legal","cybersecurity","privacy","breach-notification","compliance","federal","state-law","ansvar"],"repository":{"url":"git+https://github.com/Ansvar-Systems/US-law-mcp.git","type":"git"},"description":"US federal and state cybersecurity/privacy law MCP server with cross-state comparison","maintainers":[{"name":"ansvar","email":"jeffrey.von.rotz@ansvar.eu"}],"readme":"# US Law MCP Server\n\n**The US Code alternative for the AI age.**\n\n[![CI](https://github.com/Ansvar-Systems/US-law-mcp/actions/workflows/ci.yml/badge.svg)](https://github.com/Ansvar-Systems/US-law-mcp/actions/workflows/ci.yml)\n[![Daily Data Check](https://github.com/Ansvar-Systems/US-law-mcp/actions/workflows/check-updates.yml/badge.svg)](https://github.com/Ansvar-Systems/US-law-mcp/actions/workflows/check-updates.yml)\n[![npm version](https://badge.fury.io/js/@ansvar%2Fus-law-mcp.svg)](https://www.npmjs.com/package/@ansvar/us-law-mcp)\n[![MCP Registry](https://img.shields.io/badge/MCP-Registry-blue)](https://registry.modelcontextprotocol.io)\n[![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n[![GitHub stars](https://img.shields.io/github/stars/Ansvar-Systems/US-law-mcp?style=social)](https://github.com/Ansvar-Systems/US-law-mcp)\n[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/Ansvar-Systems/US-law-mcp/badge)](https://scorecard.dev/viewer/?uri=github.com/Ansvar-Systems/US-law-mcp)\n[![Provisions](https://img.shields.io/badge/provisions-484-blue)](#whats-included)\n\nQuery **93 US federal and state statutes** across **all 50 states + DC + key US territories** -- from CFAA and HIPAA to California's CCPA/CPRA, New York's SHIELD Act, and Texas TDPSA -- directly from Claude, Cursor, or any MCP-compatible client.\n\nIf you're building legal tech, compliance tools, or doing US cybersecurity/privacy research, this is your verified reference database.\n\nBuilt by [Ansvar Systems](https://ansvar.eu) -- Stockholm, Sweden\n\n---\n\n## Why This Exists\n\nUS cybersecurity and privacy law is fragmented across 50+ jurisdictions. Whether you're:\n- A **compliance officer** comparing breach notification timelines across states\n- A **privacy engineer** checking which states require encryption of personal data\n- A **legal tech developer** building multi-state compliance tools\n- A **CISO** mapping state requirements to your incident response plan\n\n...you shouldn't need to navigate dozens of state legislature websites and manually cross-reference PDFs. Ask Claude. Get the exact provision. Compare across states.\n\nThis MCP server makes US cybersecurity, privacy, and breach notification law **searchable, comparable, and AI-readable**.\n\n---\n\n## Quick Start\n\n### Use Remotely (No Install Needed)\n\n> Connect directly to the hosted version -- zero dependencies, nothing to install.\n\n**Endpoint:** `https://us-law-mcp.vercel.app/mcp`\n\n| Client | How to Connect |\n|--------|---------------|\n| **Claude.ai** | Settings > Connectors > Add Integration > paste URL |\n| **Claude Code** | `claude mcp add us-law --transport http https://us-law-mcp.vercel.app/mcp` |\n| **Claude Desktop** | Add to config (see below) |\n| **GitHub Copilot** | Add to VS Code settings (see below) |\n\n**Claude Desktop** -- add to `claude_desktop_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"us-law\": {\n      \"type\": \"url\",\n      \"url\": \"https://us-law-mcp.vercel.app/mcp\"\n    }\n  }\n}\n```\n\n**GitHub Copilot** -- add to VS Code `settings.json`:\n\n```json\n{\n  \"github.copilot.chat.mcp.servers\": {\n    \"us-law\": {\n      \"type\": \"http\",\n      \"url\": \"https://us-law-mcp.vercel.app/mcp\"\n    }\n  }\n}\n```\n\n### Use Locally (npm)\n\n```bash\nnpx @ansvar/us-law-mcp\n```\n\n**Claude Desktop** -- add to `claude_desktop_config.json`:\n\n**macOS:** `~/Library/Application Support/Claude/claude_desktop_config.json`\n**Windows:** `%APPDATA%\\Claude\\claude_desktop_config.json`\n\n```json\n{\n  \"mcpServers\": {\n    \"us-law\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@ansvar/us-law-mcp\"]\n    }\n  }\n}\n```\n\n**Cursor / VS Code:**\n\n```json\n{\n  \"mcp.servers\": {\n    \"us-law\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@ansvar/us-law-mcp\"]\n    }\n  }\n}\n```\n\n---\n\n## Example Queries\n\nOnce connected, just ask naturally:\n\n- *\"What does 18 U.S.C. § 1030 say about protected computers?\"*\n- *\"Compare breach notification timelines across California, New York, and Texas\"*\n- *\"What are Florida's breach notification requirements?\"*\n- *\"Is HIPAA currently in force?\"*\n- *\"Find provisions about encryption of personal information\"*\n- *\"What privacy rights does California's CCPA/CPRA grant?\"*\n- *\"Validate the citation CFAA\"*\n- *\"Which states require notification within 30 days of a breach?\"*\n\n---\n\n## What's Included\n\n| Category | Count | Details |\n|----------|-------|---------|\n| **Federal Statutes** | 15 laws | CFAA, HIPAA, ECPA, GLBA, COPPA, FISMA, CISA, FTC Act, and more |\n| **State Statutes** | 78 laws | All 50 states + DC + Guam/Puerto Rico/US Virgin Islands: breach notification, privacy, cybersecurity |\n| **Provisions** | 484 sections | Full-text searchable with FTS5 |\n| **State Requirements** | 145 classified | Breach notification, privacy rights, cybersecurity obligations |\n| **Requirement Categories** | 20 types | Timeline, scope, penalties, rights, obligations |\n| **Jurisdictions** | 55 | Federal + 50 states + DC + Guam/Puerto Rico/US Virgin Islands |\n| **Database Size** | ~3 MB | Optimized SQLite, portable |\n| **Weekly Updates** | Automated | Freshness checks against uscode.house.gov |\n\n**No LLM-generated statute text** -- provisions are fetched from published legal sources and stored verbatim for retrieval/search.\n\n---\n\n## Available Tools (8)\n\n| Tool | Description |\n|------|-------------|\n| `search_legislation` | FTS5 search across all federal and state provisions with BM25 ranking |\n| `get_provision` | Retrieve specific provision by jurisdiction, law identifier, or section number |\n| `list_sources` | List all available jurisdictions with document and provision counts |\n| `compare_requirements` | Compare requirements across states by category and subcategory |\n| `get_state_requirements` | Get classified requirements for a specific state (breach notification, privacy rights, etc.) |\n| `validate_citation` | Validate a legal citation against the database (zero-hallucination check) |\n| `check_currency` | Check if a statute is currently in force, amended, repealed, or superseded |\n| `build_legal_stance` | Aggregate statute search + state requirements for comprehensive legal research |\n\n### Cross-State Comparison\n\nThe killer feature. `compare_requirements` lets you instantly compare how different states handle the same legal requirement:\n\n```\ncompare_requirements(category: \"breach_notification\", subcategory: \"timeline\", jurisdictions: [\"US-CA\", \"US-NY\", \"US-TX\"])\n```\n\nReturns structured data with notification deadlines, scope, and penalties for each state -- the kind of research that normally takes hours of manual cross-referencing.\n\n---\n\n## Jurisdictions\n\n**55 jurisdictions**: US Federal + all 50 states + DC + Guam/Puerto Rico/US Virgin Islands\n\n`US-FED` `US-AL` `US-AK` `US-AZ` `US-AR` `US-CA` `US-CO` `US-CT` `US-DE` `US-DC` `US-FL` `US-GA` `US-GU` `US-HI` `US-ID` `US-IL` `US-IN` `US-IA` `US-KS` `US-KY` `US-LA` `US-ME` `US-MD` `US-MA` `US-MI` `US-MN` `US-MS` `US-MO` `US-MT` `US-NE` `US-NV` `US-NH` `US-NJ` `US-NM` `US-NY` `US-NC` `US-ND` `US-OH` `US-OK` `US-OR` `US-PA` `US-PR` `US-RI` `US-SC` `US-SD` `US-TN` `US-TX` `US-UT` `US-VT` `US-VA` `US-VI` `US-WA` `US-WV` `US-WI` `US-WY`\n\n---\n\n## Data Sources & Freshness\n\nAll content is sourced from authoritative legal publications:\n\n- **[US Code (USLM)](https://uscode.house.gov/)** -- Office of the Law Revision Counsel, official XML\n- **[State Legislative Portals](https://www.congress.gov/state-legislature-websites)** -- individual state legislature publications and state-source captures\n\n### Automated Freshness Checks (Weekly)\n\nA [weekly GitHub Actions workflow](.github/workflows/check-updates.yml) monitors US Code release points, refreshes federal data, rebuilds the database, runs tests, and opens a PR when changes are detected.\n\n| Source | Check | Method |\n|--------|-------|--------|\n| **US Code releases** | uscode.house.gov release points | Release-link digest change detection |\n| **Public laws** | congress.gov/public-laws | Manual review triggered |\n| **State amendments** | State legislature portals | Periodic manual review |\n\n---\n\n## Security\n\nThis project uses multiple layers of automated security scanning:\n\n| Scanner | What It Does | Schedule |\n|---------|-------------|----------|\n| **CodeQL** | Static analysis for security vulnerabilities | Weekly + PRs |\n| **Semgrep** | SAST scanning (OWASP top 10, secrets, TypeScript) | Every push |\n| **Gitleaks** | Secret detection across git history | Every push |\n| **Trivy** | CVE scanning on filesystem and npm dependencies | Weekly |\n| **OSSF Scorecard** | OpenSSF best practices scoring | Weekly |\n\nSee [SECURITY.md](SECURITY.md) for the full policy and vulnerability reporting.\n\n---\n\n## Important Disclaimers\n\n### Legal Advice\n\n> **THIS TOOL IS NOT LEGAL ADVICE**\n>\n> Statute text is sourced from official/legal publications. However:\n> - This is a **research tool**, not a substitute for professional legal counsel\n> - **State law coverage focuses on cybersecurity, privacy, and breach notification** -- it does not cover all areas of law\n> - **Verify critical citations** against primary sources for court filings\n> - **State laws change frequently** -- always confirm currency against official state sources\n\n---\n\n## Development\n\n### Setup\n\n```bash\ngit clone https://github.com/Ansvar-Systems/US-law-mcp\ncd US-law-mcp\nnpm install\nnpm run build:db && npm run ingest:all\nnpm run build\nnpm test\n```\n\n### Running Locally\n\n```bash\nnpm run dev                                       # Start MCP server (stdio)\nnpx @anthropic/mcp-inspector node dist/index.js   # Test with MCP Inspector\n```\n\n### Environment Variables\n\n| Variable | Default | Description |\n|----------|---------|-------------|\n| `US_LAW_DB_PATH` | `data/database.db` (relative to dist) | Custom path to the SQLite database file |\n\n### Data Management\n\n```bash\nnpm run fetch:federal          # Fetch federal statutes from uscode.house.gov\nnpm run fetch:states           # Fetch state statutes\nnpm run build:db               # Rebuild SQLite database\nnpm run ingest:all             # Ingest all seed data (federal + states + classify)\nnpm run build:db:free          # Build free-tier database (no case law/regulatory guidance)\nnpm test                       # Run unit tests\nnpm run test:contract          # Run golden contract tests\nnpm run validate               # Lint + test + contract tests\n```\n\n---\n\n## Related Projects: Complete Compliance Suite\n\nThis server is part of **Ansvar's Compliance Suite** -- MCP servers that work together for end-to-end compliance coverage:\n\n### [@ansvar/eu-regulations-mcp](https://github.com/Ansvar-Systems/EU_compliance_MCP)\n**Query 49 EU regulations directly from Claude** -- GDPR, AI Act, DORA, NIS2, MiFID II, eIDAS, and more. Full regulatory text with article-level search. `npx @ansvar/eu-regulations-mcp`\n\n### [@ansvar/us-regulations-mcp](https://github.com/Ansvar-Systems/US_Compliance_MCP)\n**Query US federal compliance frameworks** -- HIPAA, SOX, GLBA, FERPA, and more. `npx @ansvar/us-regulations-mcp`\n\n### [@ansvar/swedish-law-mcp](https://github.com/Ansvar-Systems/swedish-law-mcp)\n**Query 717 Swedish statutes directly from Claude** -- DSL, BrB, ABL, MB, and more. Full provision text with EU cross-references. `npx @ansvar/swedish-law-mcp`\n\n### [@ansvar/automotive-cybersecurity-mcp](https://github.com/Ansvar-Systems/Automotive-MCP)\n**Query UNECE R155/R156 and ISO 21434** -- Automotive cybersecurity compliance. `npx @ansvar/automotive-cybersecurity-mcp`\n\n### [@ansvar/sanctions-mcp](https://github.com/Ansvar-Systems/Sanctions-MCP)\n**Offline-capable sanctions screening** -- OFAC, EU, UN sanctions lists. `pip install ansvar-sanctions-mcp`\n\n---\n\n## Contributing\n\nContributions welcome! Priority areas:\n- Expanding state law coverage beyond cybersecurity/privacy\n- Adding case law references\n- Historical statute versions and amendment tracking\n- Regulatory guidance cross-references\n\n---\n\n## License\n\nApache License 2.0. See [LICENSE](./LICENSE) for details.\n\n### Data Licenses\n\n- **US Code:** Public domain (Office of the Law Revision Counsel)\n- **State Statutes:** Public domain (individual state legislatures)\n\n---\n\n## About Ansvar Systems\n\nWe build AI-accelerated compliance and legal research tools. This MCP server started because comparing breach notification requirements across 50 states shouldn't require a week of manual research.\n\nSo we're open-sourcing it. Multi-state compliance shouldn't be this hard.\n\n**[ansvar.eu](https://ansvar.eu)** -- Stockholm, Sweden\n\n---\n\n<p align=\"center\">\n  <sub>Built with care in Stockholm, Sweden</sub>\n</p>\n","readmeFilename":"README.md"}