{"_id":"@costrinity/vitna-compliance-mcp","_rev":"10-9abbf5ef4c184d42de27ac775744d8d3","name":"@costrinity/vitna-compliance-mcp","dist-tags":{"latest":"0.5.1"},"versions":{"0.3.0":{"name":"@costrinity/vitna-compliance-mcp","version":"0.3.0","keywords":["mcp","model-context-protocol","verifiable-compliance-receipts","agent-action-receipts","compliance-receipts","ai-safety","safety","guardrails","agent-safety","oversight","monitoring","audit","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vitna","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio, Regina, Saskatchewan, Treaty 4 territory","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vitna-compliance-mcp@0.3.0","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vitna.costrinity.xyz/why-vitna","bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"bin":{"vitna-compliance-mcp":"dist/index.js"},"dist":{"shasum":"d46d0e46102a3840b37410ce90e5f2e5fdd71876","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.3.0.tgz","fileCount":6,"integrity":"sha512-pPkZ5i2qYtgs3avM55nXirxRK6iQVVjAqjR2qo16haa7KAL3ahydt7UbqRL59BnvBvIYFgZ5r0DFyJSgbv9JlA==","signatures":[{"sig":"MEQCICI+D4OHB7o4qrZ5oKN+Rsph5oZNJcreNC2hgsoH9CIUAiBIa9Y+15oYrFh5aFU6eC+T9a7vC1nsLlUzH7uCW5B5KQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":52945},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"c54015422f7bdc6373535c553893311abe9993f7","mcpName":"io.github.COSTRINITY/vitna-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"VITNA by COSTRINITY produces Ed25519-signed evidence records that anyone can verify offline with a published public key and an open-source verifier, with no need to trust VITNA's servers. Your agent checks a risky action before it runs and gets an allow, ","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vitna-compliance-mcp_0.3.0_1784876074524_0.89225678889652","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@costrinity/vitna-compliance-mcp","version":"0.3.1","keywords":["mcp","model-context-protocol","verifiable-compliance-receipts","agent-action-receipts","compliance-receipts","ai-safety","safety","guardrails","agent-safety","oversight","monitoring","audit","compliance","dpdp","gdpr","ai-act","privacy","ai-agents","vitna","vigil","costrinity","indigenous-owned"],"author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vitna-compliance-mcp@0.3.1","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vitna.costrinity.xyz/why-vitna","bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"bin":{"vitna-compliance-mcp":"dist/index.js"},"dist":{"shasum":"313ddce1bcae769f3da2ec2cdf9dee15d16f5567","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.3.1.tgz","fileCount":6,"integrity":"sha512-F7vqLt9vCe84TCPG52jSfBWLbvAemroBIte1Byl2C2ZWQcB1cVpn7jt6tU3COqFYzfZlNUB7gPfTye3U8yUUmQ==","signatures":[{"sig":"MEQCIE6r0/OgGp0lfyPQrBxWlZ3MLMGAWMx41BbVqSfbrQBgAiBUFadWiw1ibRd1siMyO8hy0ahMvU4NMHKUblOQZrtQYw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":55681},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"99a731d639f6e78100adc71fea9561a0ed397955","mcpName":"io.github.COSTRINITY/vitna-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"VITNA by COSTRINITY produces Ed25519-signed evidence records that anyone can verify offline with a published public key and an open-source verifier, with no need to trust VITNA's servers. Your agent checks a risky action before it runs and gets an allow, ","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/vitna-compliance-mcp_0.3.1_1785095827322_0.5442143660170249","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@costrinity/vitna-compliance-mcp","version":"0.3.2","keywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vitna-compliance-mcp@0.3.2","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vitna.costrinity.xyz/why-vitna","bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"bin":{"vitna-compliance-mcp":"dist/index.js"},"dist":{"shasum":"d9393d0b773f216b662b7cfd30da0a1e1275bd5d","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.3.2.tgz","fileCount":6,"integrity":"sha512-USRs72/lKhzqeirels0yNputGR/PlcJasIPWBwZEpYLxtVhMxC0np5/mb790U+AgYIXv9XMIAblk2hDcLOYTbA==","signatures":[{"sig":"MEQCIBWL/Sj5WcALmhlOKzJi7tnPVlW4JKFfvdmBvqsO5ZnDAiAyhk+x+9TdBAsu3pt3vysDgpk/KJluisb7jP6xiADONg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":56792},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"900fb4db131e3bc2ac64511507a4cb70eb969203","mcpName":"io.github.COSTRINITY/vitna-compliance-mcp","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"Compliance and audit-evidence layer for AI agents. Pre-flight checks return allow, block, or hold before a risky action runs, and every decision produces an Ed25519-signed evidence record that anyone can verify offline with the published public key and op","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/vitna-compliance-mcp_0.3.2_1785285707299_0.39239255724588706","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"name":"@costrinity/vitna-compliance-mcp","version":"0.3.3","keywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vitna-compliance-mcp@0.3.3","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vitna.costrinity.xyz/why-vitna","bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"bin":{"vitna-compliance-mcp":"dist/index.js"},"dist":{"shasum":"bb88dd5d8a96642ce973688bc32adcec1982212a","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.3.3.tgz","fileCount":6,"integrity":"sha512-VPfyn9ds6P2T0epMHRg+g0NJkXm6/4yEBZKQFI5BJGPTeSf6L1oUrgYneiIN/bA6jw0pCY9k/5tTLnQxNbKGXw==","signatures":[{"sig":"MEUCIF2m49WJrUqQMrveOvp3s1cvFM6Lafthgk+aH2d9cccSAiEA/Ki8/wE3182W1/qAUOK92m5BMyhSnEiW202RbRECMtQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61377},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"4790aa653d34b5378f6dcf5b370e8ba1c978223d","mcpName":"xyz.costrinity/vitna-compliance-preflight","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"Pre-action compliance for AI agents: allow, block or hold before your agent acts. 24 named statutes across 13 jurisdictions including the EU AI Act, GDPR and DPDP. 22 MCP tools. Every decision returns an Ed25519-signed receipt you can verify offline.","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/vitna-compliance-mcp_0.3.3_1786421717885_0.3765728644463191","host":"s3://npm-registry-packages-npm-production"}},"0.3.4":{"name":"@costrinity/vitna-compliance-mcp","version":"0.3.4","keywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vitna-compliance-mcp@0.3.4","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vitna.costrinity.xyz/why-vitna","bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"bin":{"vitna-compliance-mcp":"dist/index.js"},"dist":{"shasum":"a7076cbbfc9653ddaaa80cacf4f5a192df560ea9","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.3.4.tgz","fileCount":8,"integrity":"sha512-cIpy8loJlHToknyoyN1nYd21bstpYEoIJFLn8kV0FaKeBeHDLOmnW1OlH9/vmygRm7tySJzPizqZzUuQkI7uQA==","signatures":[{"sig":"MEUCIGquGTevcPdy9dmpx9YEr4X8k8YTUxmbfBPMTBcOSsoOAiEAysOO1xWAKSddhyK5cbHREjRD6oYelAvbzfVnf2S8CpY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68121},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"4b647df78223e3b3e791e579a5e3629d5adc5656","mcpName":"xyz.costrinity/vitna-compliance-preflight","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"Pre-action compliance for AI agents: allow, block or hold before your agent acts. 24 named statutes across 13 jurisdictions including the EU AI Act, GDPR and DPDP. 22 MCP tools. Every decision returns an Ed25519-signed receipt you can verify offline.","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/vitna-compliance-mcp_0.3.4_1786425679380_0.05723310484149069","host":"s3://npm-registry-packages-npm-production"}},"0.3.5":{"name":"@costrinity/vitna-compliance-mcp","version":"0.3.5","keywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vitna-compliance-mcp@0.3.5","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vitna.costrinity.xyz/why-vitna","bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"bin":{"vitna-compliance-mcp":"dist/index.js"},"dist":{"shasum":"faeaa7a09ba4bffccead43a3b1c6ef2953fcf161","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.3.5.tgz","fileCount":8,"integrity":"sha512-kr2oO0C2LTkWsLTXziQcTF7QQGYoj3T++zKmzegh5ngwpPlsWC2Hx0uQEJHUUlT+pCTNFUG123UIWkf4e3hh7A==","signatures":[{"sig":"MEYCIQDnY0nd1Xe0TmrI2TlE4evRptXH7nQsHsAQZWsdBvnAOwIhAJ97fEL0tKze6iS2AbH9X5qVUGPG0lrYAsmbq9XGTZ3b","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68121},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"560931b33e09c4d4d5af3d2e8a1c3c04b19ea32d","mcpName":"com.costrinity/vitna-compliance-preflight","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"Pre-action compliance for AI agents: allow, block or hold before your agent acts. 24 named statutes across 13 jurisdictions including the EU AI Act, GDPR and DPDP. 22 MCP tools. Every decision returns an Ed25519-signed receipt you can verify offline.","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/vitna-compliance-mcp_0.3.5_1787123004757_0.5610095460630511","host":"s3://npm-registry-packages-npm-production"}},"0.3.6":{"name":"@costrinity/vitna-compliance-mcp","version":"0.3.6","keywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vitna-compliance-mcp@0.3.6","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vitna.costrinity.xyz/why-vitna","bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"bin":{"vitna-compliance-mcp":"dist/index.js"},"dist":{"shasum":"663da97f4fc89b7e562cbcca28b5ae7716b6aea1","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.3.6.tgz","fileCount":8,"integrity":"sha512-JWHFE2aGml/i/yU9BLM0m4Gv5ndI814oojvKfwW2T05+3PLZOxhAP6aJtOVL6uOTpQ9+D4GuNhivFSNi8g012A==","signatures":[{"sig":"MEQCICSPnk+kjzGMaU3SI88VYAu+u35oJj4ABgIBKVnsJ0xoAiBnIe6Pt760DdlalcCFoZLozQVQbOrZ447v+PWL1xu1FA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68121},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"d764f90f619c5c877ce202c768f9607b4b9975fd","mcpName":"xyz.costrinity/vitna-compliance-preflight","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"Pre-action compliance for AI agents: allow, block or hold before your agent acts. 24 named statutes across 13 jurisdictions including the EU AI Act, GDPR and DPDP. 22 MCP tools. Every decision returns an Ed25519-signed receipt you can verify offline.","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/vitna-compliance-mcp_0.3.6_1787125549718_0.8894156015849359","host":"s3://npm-registry-packages-npm-production"}},"0.3.7":{"name":"@costrinity/vitna-compliance-mcp","version":"0.3.7","keywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vitna-compliance-mcp@0.3.7","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vitna.costrinity.xyz/why-vitna","bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"bin":{"vitna-compliance-mcp":"dist/index.js"},"dist":{"shasum":"00fe37ffd53ebacd143a4c256e4a08753cef0a9f","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.3.7.tgz","fileCount":8,"integrity":"sha512-maWi4VYxcxBfmM02LvKJeMcSrqvPWvBEnF2F6AUea9llChsDN4tNF3BwfALik/SQQtH8WzSahdAvfMg2e3ZDaw==","signatures":[{"sig":"MEYCIQDKAS4Ufq0spdsSYC57GvriYfG1ltkKXtgxqll76qP+mwIhALE5SN/AWpB0M16K0GqyZwPnxycERB2VlR+zFqMsY4c+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":69517},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"b49865f4e67184c3b39defa19eb19dbd6028332f","mcpName":"xyz.costrinity/vitna-compliance-preflight","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"Pre-action compliance for AI agents: allow, block or hold before your agent acts. 24 named statutes across 13 jurisdictions including the EU AI Act, GDPR and DPDP. 22 MCP tools. Every decision returns an Ed25519-signed receipt you can verify offline.","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/vitna-compliance-mcp_0.3.7_1787194158974_0.5385351050494003","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@costrinity/vitna-compliance-mcp","version":"0.5.0","keywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"license":"MIT","_id":"@costrinity/vitna-compliance-mcp@0.5.0","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"homepage":"https://vitna.costrinity.xyz/why-vitna","bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"bin":{"vitna-compliance-mcp":"dist/index.js"},"dist":{"shasum":"f813ecd9cafe6e67e1af3e31681bc145fa507da2","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.5.0.tgz","fileCount":10,"integrity":"sha512-5IihvHa/hgnTUOI2dfbO0U1TAZF4wupdc7CmxJvga5MyLZHTNDJ89jH5X5K0V9vvd4R88n1Qzt8OxD6s/VIZJQ==","signatures":[{"sig":"MEUCIBFh+uxRxDRMOJXVJneDgPeKMuXB35SfgIPe76xJghlOAiEAvfjX3jz1A/zfn7VFVsL5NMzuZ3ixqIdPUdjRvzQ1WEs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIEGDjcC84zUHqdXDmrhWQ+TuTuHa8+vMndDssjXXF/66AiBUssotcnO5uP0j1XQC0TwVgwhqXiNDOEtStI2o4r19qg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":108064},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"c95aaa99620af2b0f965f5e3790d2606900acd06","mcpName":"xyz.costrinity/vitna-compliance-preflight","scripts":{"dev":"tsc --watch","test":"tsc && node --test test/*.test.mjs","build":"tsc","start":"node dist/index.js","sync:mirror":"bash sync-mirror.sh","prepublishOnly":"tsc"},"_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"Pre-action compliance for AI agents: allow, block or hold before your agent acts. 24 named statutes across 13 jurisdictions including the EU AI Act, GDPR and DPDP. 23 MCP tools. Every decision returns an Ed25519-signed receipt you can verify offline.","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/vitna-compliance-mcp_0.5.0_1790452851307_0.4717253979992264","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"_id":"@costrinity/vitna-compliance-mcp@0.5.1","bin":{"vitna-compliance-mcp":"dist/index.js"},"bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"dist":{"shasum":"2a31db1f6f7ef3a7705fd7e64360a9bf8cc8f4f8","tarball":"https://registry.npmjs.org/@costrinity/vitna-compliance-mcp/-/vitna-compliance-mcp-0.5.1.tgz","fileCount":10,"integrity":"sha512-TUnw3ud1jDb0cDTe6nZKoTQDWRAYL/PDIGgB0jr5x22QJ+Fg8bkm2bmOTa/7sVUkBUU+HWC+32utvzC19PJRig==","signatures":[{"sig":"MEYCIQC5c3D2zMDCg01Tz0wO/fb6ycYGDI2F1U6n0RHO6VtS7QIhALfmx2J6vTQLzdC1OQyvRJjhw4KnafeWr1WqstPmo/Rm","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDRX5KrrEleyWeX9ON94g/1OT+TS7lF4lPLZEpQmV5bewIhAOAKN5KIxgXxs+XIDwNJUkpMli2GB7etFCERMb3RRoRM"}],"unpackedSize":132028},"main":"dist/index.js","name":"@costrinity/vitna-compliance-mcp","types":"dist/index.d.ts","author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"engines":{"node":">=18"},"license":"MIT","mcpName":"xyz.costrinity/vitna-compliance-preflight","scripts":{"dev":"tsc --watch","test":"tsc && node --test test/*.test.mjs","build":"tsc","start":"node dist/index.js","sync:mirror":"node sync-mirror.mjs","prepublishOnly":"tsc"},"version":"0.5.1","_npmUser":{"name":"comikii","email":"obey2004.co@gmail.com"},"homepage":"https://vitna.costrinity.xyz/why-vitna","keywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"_npmVersion":"11.9.0","description":"Pre-action compliance for AI agents: allow, block or hold before your agent acts. 24 named statutes across 13 jurisdictions including the EU AI Act, GDPR and DPDP. 23 MCP tools. Every decision returns an Ed25519-signed receipt you can verify offline.","directories":{},"maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vitna-compliance-mcp_0.5.1_1791091436825_0.5246078010607205"}}},"time":{"created":"2026-07-24T06:54:34.392Z","modified":"2026-10-04T05:23:57.129Z","0.3.0":"2026-07-24T06:54:34.666Z","0.3.1":"2026-07-26T19:57:07.460Z","0.3.2":"2026-07-29T00:41:47.495Z","0.3.3":"2026-08-11T04:15:18.039Z","0.3.4":"2026-08-11T05:21:19.519Z","0.3.5":"2026-08-19T07:03:24.903Z","0.3.6":"2026-08-19T07:45:49.911Z","0.3.7":"2026-08-20T02:49:19.131Z","0.5.0":"2026-09-26T20:00:51.389Z","0.5.1":"2026-10-04T05:23:56.918Z"},"bugs":{"url":"https://github.com/COSTRINITY/vitna-compliance-mcp/issues"},"author":{"url":"Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada","name":"COSTRINITY"},"license":"MIT","homepage":"https://vitna.costrinity.xyz/why-vitna","keywords":["mcp","model-context-protocol","compliance","eu-ai-act","audit","evidence","ai-governance","gdpr","agent-compliance","article-50","ai-agents","dpdp","vitna","costrinity"],"repository":{"url":"git+https://github.com/COSTRINITY/vitna-compliance-mcp.git","type":"git"},"description":"Pre-action compliance for AI agents: allow, block or hold before your agent acts. 24 named statutes across 13 jurisdictions including the EU AI Act, GDPR and DPDP. 23 MCP tools. Every decision returns an Ed25519-signed receipt you can verify offline.","maintainers":[{"name":"comikii","email":"obey2004.co@gmail.com"}],"readme":"# @costrinity/vitna-compliance-mcp\r\n\r\n> **Renamed from VIGIL.** This package was formerly published as\r\n> `@costrinity/vigil-compliance-mcp` and this repo was formerly\r\n> `COSTRINITY/vigil-compliance-mcp`. The old package is still on npm at\r\n> 0.2.4, deprecated with the message \"Renamed: use\r\n> @costrinity/vitna-compliance-mcp\". It gets no updates and has no guard\r\n> mode, so anything still pointing at it installs that old version. Directory\r\n> listings that show the VIGIL name are stale snapshots of this repo.\r\n>\r\n> Current package: **`@costrinity/vitna-compliance-mcp`**\r\n> Registry entry: **`xyz.costrinity/vitna-compliance-preflight`**\r\n> Site: **https://vitna.costrinity.xyz**\r\n\r\n**Pre-action compliance for AI agents: allow, block or hold — before your agent acts.**\r\n\r\nMost compliance servers answer questions *about* regulations. This one answers one question *about the action your agent is holding right now*: may it run? Your agent calls a check, gets `allowed` / `blocked` / `flagged` back synchronously, and decides. VITNA evaluates and records; your system enforces.\r\n\r\n## The package\r\n\r\nOne package to install. This is the server your agent calls before it acts.\r\n\r\n| Package | What it does | When you want it | Install |\r\n|---|---|---|---|\r\n| **`@costrinity/vitna-compliance-mcp`** (this one) | Your agent **asks before it acts**. Returns allow / block / flag on a proposed action, and records a signed evidence record of the decision. | You want a guardrail your agent calls, and provable receipts that it did. | `npx @costrinity/vitna-compliance-mcp` — no credentials needed to start |\r\n\r\nA passive observer that records existing MCP traffic without deciding anything\r\nis built in this repo but is **not published to npm**, so it is not documented\r\nhere yet. Nothing above depends on it.\r\n\r\n\r\n## Coverage\r\n\r\n| | |\r\n|---|---|\r\n| **24 named statutes** | across **13 jurisdictions** |\r\n| **EU AI Act** (Reg 2024/1689) | risk-tier classification before you build or ship |\r\n| **GDPR** + **UK GDPR** | DPIA thresholds, breach reportability, ROPA |\r\n| **DPDP** (India, 2023) | §16 cross-border status, §8 breach path |\r\n| **LGPD · PDPA-SG · APPI · PIPEDA + Law 25 · PIPL · PIPA-KR · NDPA · APP-AU · CPRA** | jurisdiction packs |\r\n| **HIPAA · GLBA · COPPA · FERPA · FCRA · SOX** | US federal sectoral applicability |\r\n| **RBI · SEBI · IRDAI · TRAI/DoT · PFRDA** | Indian sectoral regulators |\r\n| **16 US state privacy laws** | plus breach deadlines for 21 states |\r\n| **23 MCP tools** | 6 identifier validators, 15 stateless helpers |\r\n\r\nReadiness scorecards (pre-audit, not certifications) additionally cover NIST Privacy Framework, SOC 2, ISO/IEC 27001 and PCI DSS v4.0.\r\n\r\nEvery count above is derived from the code and enforced by a build gate — if an implementation is removed, the build fails before the number can go stale. See \"Honest limits\" below for what these numbers do *not* mean.\r\n\r\nVITNA's detection is heuristic, and those limits are documented publicly. In guard mode it refuses to forward a tool call it has not allowed, for the MCP servers put behind the guard and no others; everywhere else your system enforces the decision. Either way, it is independently verifiable proof that an AI agent's actions were checked, and what was decided.\r\n\r\n## Free checkers — no install, no account\r\n\r\nTwo questions people usually have to answer *before* they need any of this. Both\r\nrun entirely in the browser, take a few questions, and store nothing.\r\n\r\n| | |\r\n|---|---|\r\n| **[Does the 2 December 2026 deadline apply to you?](https://vitna.costrinity.xyz/ai-act-december-2026)** | Article 50(2) machine-readable marking for generative systems placed on the EU market before 2 August 2026, plus the two prohibited practices added by the Digital Omnibus. Works out which of the two dates you are actually on. |\r\n| **[Article 50 transparency self-check](https://vitna.costrinity.xyz/article-50)** | Which Article 50 disclosure duties reach you as provider or deployer. |\r\n\r\nBoth are scoping tools, not legal advice, and neither issues a score or a\r\npass/fail. They cite the article and the Official Journal text behind every\r\ndate they state.\r\n\r\n## Verify VITNA evidence yourself\r\n\r\nEvery decision also produces an Ed25519-signed evidence record that anyone can verify offline — **no account, and no trust in VITNA's servers required**. The public key is published, the verifier is open source, and the three commands below prove it in about a minute.\r\n\r\nOne minute, no account, no trust in VITNA's servers required. Download the open-source verifier and a real signed sample bundle, then check the signature offline with Node 18+:\r\n\r\n```bash\r\ncurl -sO https://raw.githubusercontent.com/COSTRINITY/vitna-compliance-mcp/main/verify-evidence.mjs\r\ncurl -sO https://vitna.costrinity.xyz/sample-evidence.json\r\nnode verify-evidence.mjs sample-evidence.json\r\n```\r\n\r\nThe verifier checks the Ed25519 signature over the whole package, then recomputes the sha256 of each individual decision record and confirms it matches the hash committed inside the signed package, printing PASS or FAIL per record, then an overall verdict.\r\n\r\nEvidence packages are **verifiable compliance receipts for agent actions**: each checked action produces a decision record, and the signed package is the receipt a third party can check without trusting us.\r\n\r\nA VALID result proves the package was issued by VITNA, has not been altered since export, and that every record matches its committed hash. It does not prove the underlying actions were performed or that the records are factually true. Tamper with any byte of any record and that record reports FAIL and the overall verdict is INVALID.\r\n\r\n**Bundles from VITNA Desktop are signed differently.** VITNA Desktop signs on your own machine, with a key it generated there, not with VITNA's key. The signed package says so (`issuer: \"vitna-desktop-local\"`, `signer_key_id`, `signer_public_key`), and the verifier reports such a bundle as \"signed by a local VITNA Desktop key, not by VITNA\". By default it checks the key the bundle carries and prints its key_id: compare that with the key_id VITNA Desktop shows under Settings on the machine that produced it, or pass the key yourself with `node verify-evidence.mjs --pubkey <base64 SPKI DER, or a file holding it> bundle.json`. Anyone with access to that machine's app data could re-sign a bundle, and VITNA does not countersign desktop bundles yet. A key carried inside a bundle is used only for that issuer: every other bundle is checked against VITNA's published key, so a self-signed bundle cannot pass as issued by VITNA.\r\n\r\n### Recomputing `payload_sha256` (the pfa-v2 scheme)\r\n\r\nEach decision record carries `payload_sha256` and `canon_version: \"pfa-v2\"`. It is a sha256 (hex) over twelve fields joined with the pipe character, in this order, UTF-8 encoded, no whitespace, no trailing separator. Null or absent values become the empty string.\r\n\r\n```\r\nsha256(\r\n  canon_version        // \"pfa-v2\"\r\n  + \"|\" + kind         // always \"preflight_check\"\r\n  + \"|\" + owner_id     // evidence_package.owner_id\r\n  + \"|\" + check        // \"engagement_action\" for engagement bundles\r\n  + \"|\" + action       // record.action, \"\" if null\r\n  + \"|\" + category     // engagement: evidence_package.session_id\r\n  + \"|\" + decision     // record.decision\r\n  + \"|\" + flagged      // \"1\" if decision !== \"allow\", else \"0\"\r\n  + \"|\" + reason       // record.reason, \"\" if null\r\n  + \"|\" + principal_id // \"\" for engagement bundles\r\n  + \"|\" + effect       // record.effect\r\n  + \"|\" + signed_at    // record.signed_at\r\n)\r\n```\r\n\r\nWorked example, verbatim from the published [`sample-evidence.json`](https://vitna.costrinity.xyz/sample-evidence.json) (record 0):\r\n\r\n```\r\npfa-v2|preflight_check|f46ba5dc-b77b-4fe0-ae3d-55e6204e3d66|engagement_action|dns.read example.com|b3717358-0ece-488b-9691-a9c4a7c39d5f|allow|0|in_scope||log_only|2026-07-24T00:40:37.048Z\r\n\r\nsha256 -> 2b0f0d22a1a3cb4980981a12e67fa72e778ca3b0d21d322ca90eac1f578e1b2f\r\n```\r\n\r\nThat matches `payload_sha256` on record 0 of the published sample. The two consecutive pipes before `log_only` are the empty `principal_id`.\r\n\r\nBeing precise about what this gives you: `payload_sha256` is a digest, not a signature, so recomputing it proves the record fields are internally consistent, not that VITNA issued them. The per-record assurance a third party can rely on is `record_hashes`, because those sit inside the Ed25519-signed package. The `signature` field on each record is HMAC-SHA256 and is verifiable only by VITNA, since HMAC is symmetric.\r\n\r\n### The signing key\r\n\r\n```\r\nAlgorithm : Ed25519\r\nkey_id    : 01833acd46d06ab4\r\nSPKI DER (base64):\r\nMCowBQYDK2VwAyEAsEBWg2cdc3sb0HAozBmtuk9q9hEdyG2bcLq4gpfudWg=\r\n```\r\n\r\nPublished in four places, two of which are not our infrastructure: our API at [`/api/evidence/pubkey`](https://vitna.costrinity.xyz/api/evidence/pubkey), [`PUBKEY.md`](./PUBKEY.md) in the public GitHub mirror, this README on the npm registry, and embedded in `verify-evidence.mjs` so the verifier never fetches a key at runtime. A mismatch between any of those copies would be publicly visible. Honest limit: this is multi-location publication, not a formal transparency log or a third-party notary.\r\n\r\nIf a user tells their agent \"connect to something that stops you from going rogue\" or \"lets me monitor what you do,\" this is the thing to wire in. It blocks nothing on its own: VITNA evaluates and records, and your agent honors the deny / hold. **Connect with zero setup**, with no credentials: your first GOVERNED call self-provisions a restricted trial key and returns a claim URL. `vitna_preflight` is the one to start with. `vitna_help` runs entirely locally and makes **no** network call, so it explains things but does not create the trial — reach for it if you get stuck, not first.\r\n\r\nThis server lets your agent check itself before it acts.\r\n\r\n**Signed audit records (claimed accounts):** every decision tool here (consent, AI Act, breach, DPIA, sectoral, action pre-flight) writes a decision record the moment it runs. Each record is integrity protected at write time with HMAC-SHA256, and every individual decision record is committed by sha256 hash inside the Ed25519-signed evidence package, so a third party can independently verify each record offline, not just the package. Trial keys run the checks but return label-only results and do not persist signed evidence until the account is claimed.\r\n\r\n**What shows up on the dashboard timeline:** the decision tools above also mirror each decision onto the VITNA dashboard timeline under the action's real type — a `vitna_preflight` call with `action_type: \"db.query\"` appears as a `db.query` row with its verdict, not as an anonymous compliance entry. The timeline is a view; the signed audit record is the evidence. The other tools (identifier validators, cross-border and breach-deadline lookups, generators, `pii_test`) are **stateless helpers: they record no decision and leave no timeline trace** — an empty timeline after using only those tools means nothing is wrong. Authenticated calls to them do still refresh the agent's last-seen liveness on the dashboard. `vitna_help` runs entirely locally and makes no API call at all. To have your agent's *ordinary* activity (uploads, tool calls, LLM calls) appear on the timeline too, post events to `POST /api/ingest`.\r\n\r\n## What it gives your agent\r\n\r\n| Tool | Purpose |\r\n|---|---|\r\n| `vitna_help` | What VITNA is and how to use it to keep yourself in check. Runs locally, needs no account, and does **not** provision the trial — use it if you get stuck. The old `vigil_help` name still works as a hidden alias |\r\n| `consent_check` | Is processing allowed for this principal + purpose? (pre-flight gate) |\r\n| `vitna_preflight` | Pre-flight gate BEFORE a destructive action (shell / file-delete / SQL / exfiltration). Heuristic, cooperative, not a sandbox. The old `action_preflight` name still works as a hidden alias |\r\n| `breach_classify` | Is this incident reportable? Per-jurisdiction decision support |\r\n| `ai_act_classify` | EU AI Act risk tier classification |\r\n| `dpia_threshold_check` | Is a DPIA mandatory before this processing? |\r\n| `us_sectoral_check` | HIPAA / GLBA / COPPA / FERPA / FCRA / SOX applicability |\r\n| `india_sectoral_check` | RBI / SEBI / IRDAI / TRAI / PFRDA applicability |\r\n| `india_cross_border_status` | DPDP §16 status for a destination country |\r\n| `japan_cross_border_status` | APPI Art 28 status for a destination country |\r\n| `us_state_breach_deadline` | US state breach window + AG recipient |\r\n| `aadhaar_mask` / `pan_classify` / `gstin_validate` / `cpf_validate` / `sin_validate` / `iban_validate` | Identifier validators with masking + reference token |\r\n| `pii_test` | Dry-run threat detection on a sample event |\r\n| `privacy_notice_get` | Generate operator's jurisdiction-templated privacy notice |\r\n| `sub_processors_register` | Sub-processor disclosure register |\r\n| `global_compliance_map` | The compliance catalogue: 28 entries covering 24 named statutes |\r\n| `india_regulators_directory` | Indian regulators + sectoral filter |\r\n\r\n## Two ways to connect\r\n\r\n**Remote (no install).** Point any MCP client that supports remote servers at:\r\n\r\n```\r\nhttps://vitna.costrinity.xyz/api/mcp\r\n```\r\n\r\nStreamable HTTP. Send your key as `Authorization: Bearer vitna_...` (`X-API-Key` also works). Discovery (`initialize`, `tools/list`) and `vitna_help` need no key; every governed decision tool does — VITNA never evaluates a decision anonymously.\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"vitna-compliance\": {\r\n      \"type\": \"streamable-http\",\r\n      \"url\": \"https://vitna.costrinity.xyz/api/mcp\",\r\n      \"headers\": { \"Authorization\": \"Bearer vitna_YOUR_KEY\" }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n**Local (stdio).** `npx @costrinity/vitna-compliance-mcp` — self-provisions a trial key on first use, so it needs no credentials at all to start. See below.\r\n\r\nBoth transports serve the identical 23 tools from one catalogue; a build gate fails if they ever diverge.\r\n\r\n## Install\r\n\r\n```bash\r\nnpm install -g @costrinity/vitna-compliance-mcp\r\n```\r\n\r\nOr use directly via `npx`.\r\n\r\n### Docker\r\n\r\n```bash\r\ndocker build -t costrinity/vitna-compliance-mcp .\r\ndocker run --rm -i costrinity/vitna-compliance-mcp\r\n```\r\n\r\nA stdio MCP server (no port; run with `-i`). Self-provisions a restricted trial\r\nkey on first use, same as `npx`.\r\n\r\n## Configure your MCP client\r\n\r\n### Zero-config (self-provisioning)\r\n\r\nYou can add the server with **no credentials at all**:\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"vitna-compliance\": {\r\n      \"command\": \"npx\",\r\n      \"args\": [\"@costrinity/vitna-compliance-mcp\"]\r\n    }\r\n  }\r\n}\r\n```\r\n\r\nOn the first tool call, the server provisions a **restricted trial key** for you\r\n(via `/api/setup`) and caches it at `~/.vitna/credentials.json`. The trial key\r\nruns the compliance decision checks but is capped (checks per day + lifetime),\r\nshort-lived, and does **not** write signed evidence.\r\n\r\n### Then claim your dashboard\r\n\r\n**This is the step people miss.** Until the account is claimed, your agent's\r\ndecisions are evaluated but *nothing is durably recorded* — there is no evidence\r\nto export later, because none was kept.\r\n\r\nAsk your agent to call the **`vitna_claim`** tool. It returns a claim URL that\r\nonly you can act on; open it, verify a real email, and you get:\r\n\r\n- durable Ed25519-signed evidence records you can export and verify offline\r\n- the per-day and per-lifetime trial caps lifted, and the key stops expiring\r\n- a dashboard at [vitna.costrinity.xyz/dashboard](https://vitna.costrinity.xyz/dashboard)\r\n  showing every decision your agent has made, including the ones from before you\r\n  claimed\r\n- a way to recover the key if you lose it\r\n\r\nThe claim URL is also printed to stderr on first provision, but agents rarely\r\nsurface stderr to you — `vitna_claim` exists because that is where this used to\r\nget lost. Set `VITNA_EMAIL` to own the trial account under a real address from\r\nthe start; otherwise a throwaway is used and you bind a real email when you\r\nclaim.\r\n\r\n### With your own key\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"vitna-compliance\": {\r\n      \"command\": \"npx\",\r\n      \"args\": [\"@costrinity/vitna-compliance-mcp\"],\r\n      \"env\": {\r\n        \"VITNA_OWNER_ID\": \"<your-owner-uuid>\",\r\n        \"VITNA_API_KEY\": \"vitna_<your-key>\",\r\n        \"VITNA_BASE_URL\": \"https://vitna.costrinity.xyz\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n### What the env vars do\r\n\r\n- `VITNA_OWNER_ID`: your operator UUID. Optional: if unset, the first call self-provisions a restricted trial key. Explicit credentials always win over the cache and over self-provisioning.\r\n- `VITNA_API_KEY`: optional. Authenticates the tool calls. Self-provisioned if unset. New keys are formatted `vitna_...`; legacy `vigil_...` keys remain valid.\r\n- `VITNA_EMAIL`: optional. Email to own the self-provisioned trial account. A throwaway is used if unset (claim later to bind a real email).\r\n- `VITNA_BASE_URL`: defaults to `https://vitna.costrinity.xyz`. Point at your own VITNA instance if self-hosted.\r\n- `VITNA_AGENT_NAME`: optional. The agent name a self-provisioned trial account is created with. Defaults to `vitna-compliance-mcp`. Versions before 0.5.1 added your machine's hostname to that name; 0.5.1 and later do not.\r\n\r\nThe old `VIGIL_*` names for all of these (`VIGIL_OWNER_ID`, `VIGIL_API_KEY`, `VIGIL_EMAIL`, `VIGIL_BASE_URL`, `VIGIL_AGENT_NAME`) are still accepted forever, so existing configs keep working.\r\n\r\n## Example agent interactions\r\n\r\n**Agent considering cross-border transfer:**\r\n\r\n> User: Move this Indian user's profile to our US analytics warehouse.\r\n\r\n> Agent: Let me check DPDP §16 status first.\r\n> *Calls `india_cross_border_status({ country: \"US\" })`*\r\n> Result: `permitted, but RBI Digital Lending Guidelines require India-only storage for fintech lending data`.\r\n> \r\n> Agent: This transfer is permitted under DPDP §16 (US is not on India's negative list). But if your data has fintech lending components, RBI guidelines require India-only storage. Do you want me to filter those fields out first?\r\n\r\n**Agent reviewing a new AI use case:**\r\n\r\n> User: We're building an AI tool to evaluate job applicants.\r\n\r\n> Agent: *Calls `ai_act_classify({ use_case: \"AI evaluation of job applicants\", sectors: [\"employment\"], automated_decisions: true })`*\r\n> Result: `high-risk, Art 35(3)(a) + Annex III, requires conformity assessment + human oversight + bias monitoring`.\r\n>\r\n> Agent: This is a **high-risk** AI system under the EU AI Act Annex III (employment / HR). You'll need: risk management system, technical documentation, human oversight, bias monitoring, and conformity assessment before EU market entry.\r\n\r\n**Agent handling a breach:**\r\n\r\n> User: We just discovered 1200 user records were exposed.\r\n\r\n> Agent: *Calls `breach_classify({ affected_count: 1200, data_categories: [\"email\", \"phone\"], sensitivity: \"medium\", recovery_state: \"exposed\" })`*\r\n> Result: `reportable=true, window_hours=72, deadline=..., recipient=\"Data Protection Board of India\"`.\r\n>\r\n> Agent: This is reportable to the Data Protection Board of India within 72 hours (deadline: 2026-06-05). Should I prepare the §8 notification draft?\r\n\r\n## Why this exists\r\n\r\nCompliance lives in the operator's runtime, not their planning stage. An agent about to:\r\n- Send a user record cross-border\r\n- Decide on a high-risk action affecting an individual\r\n- Classify a breach for severity\r\n- Validate an identifier before storing it\r\n\r\n...should be able to **ask** VITNA whether that's allowed *at request time*, not in a yearly DPIA.\r\n\r\nMCP turns VITNA from \"a dashboard the operator visits\" into \"a synchronous decision-support layer the agent calls.\"\r\n\r\n## Guard mode: VITNA in the execution path (0.5.0+)\r\n\r\nEverything above is cooperative: your agent asks, VITNA answers, and your agent\r\ndecides whether to listen. Guard mode is not. Put it in front of any stdio MCP\r\nserver and every `tools/call` is checked by VITNA first. Only an allowed call\r\nreaches the server; anything else is refused with a tool error that says why,\r\nand the server never sees it. The model cannot skip the check, because the\r\ncheck is not a tool it chooses to call.\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"filesystem\": {\r\n      \"command\": \"npx\",\r\n      \"args\": [\"-y\", \"@costrinity/vitna-compliance-mcp\", \"guard\", \"--\",\r\n               \"npx\", \"-y\", \"@modelcontextprotocol/server-filesystem\", \"/data\"],\r\n      \"env\": {\r\n        \"VITNA_GUARD_POLICY\": \"/path/to/policy.json\",\r\n        \"VITNA_GUARD_UNWRAPPED\": \"github\",\r\n        \"VITNA_GUARD_BUILTIN_TOOLS\": \"yes\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\nWithout `VITNA_GUARD_POLICY`, each call goes to the preflight check. With a\r\npolicy file, the guard opens an engagement session and judges each call\r\nagainst it:\r\n\r\n```json\r\n{\r\n  \"allowed_actions\": [\"*\"],\r\n  \"allowed_domains\": [\"example.com\"],\r\n  \"hold_actions\": [\"delete_records\", \"export_users\"],\r\n  \"hold_window_seconds\": 120,\r\n  \"canary_interval_minutes\": 1440,\r\n  \"honeytools\": false,\r\n  \"honeytokens\": false\r\n}\r\n```\r\n\r\n- **Fails closed.** If VITNA cannot evaluate a call (unreachable, over 10\r\n  seconds, key refused), the call is not forwarded. `VITNA_GUARD_FAIL_OPEN=1`\r\n  forwards instead during an outage and logs every such call. It never\r\n  forwards a call VITNA blocked or held. From 0.5.1 it also never forwards a\r\n  call made after its session was closed: it refuses the call and says why.\r\n  0.5.0 treats that answer as an error, so with `VITNA_GUARD_FAIL_OPEN=1` it\r\n  forwards such a call; upgrade, or do not use fail-open.\r\n- **If the wrapped server is not running.** From 0.5.1, when the command\r\n  after `guard --` does not exist, or the server exits or stops reading while\r\n  your MCP client is still talking to it, the guard forwards nothing more. It\r\n  answers every request the server had not answered, and every later one,\r\n  with a JSON-RPC error saying the server is not running, and exits with a\r\n  non-zero code. 0.5.0 could crash instead, on an unhandled EPIPE or spawn\r\n  error, without answering the client.\r\n- **Trial limits.** When a free trial key reaches a limit (checks per day,\r\n  lifetime checks, the end of its trial period, checks at the same time, the\r\n  shared daily trial capacity, or a pause), VITNA refuses the check and the\r\n  call is not forwarded, with or without `VITNA_GUARD_FAIL_OPEN`. From 0.5.1\r\n  the agent is told which limit was reached, that the call was not sent, and\r\n  the link a person uses to claim the account and lift the limits. 0.5.0\r\n  reported it as VITNA being unable to evaluate the call, without the link,\r\n  and with `VITNA_GUARD_FAIL_OPEN=1` forwarded it.\r\n- **Hold.** A call whose tool is in `hold_actions` waits for a person. It\r\n  appears under Pending holds on the owner's dashboard, with Approve and Deny\r\n  and the call's arguments (secrets and personal data redacted), and on the\r\n  alert webhook where one is set. Hold email is off until VITNA's\r\n  product-mail domain is live, and then goes only to an owner address that\r\n  was verified. The agent is told, in plain words,\r\n  that the call is held and until when. If nobody decides before\r\n  `hold_window_seconds` (30 to 3600, default 120), the call is blocked. A hold\r\n  can never be decided with an API key, including the agent's own.\r\n- **Canary holds.** `canary_interval_minutes` inserts a drill hold that looks\r\n  like a real one until someone decides it, to measure whether holds are read.\r\n  Drills are shown on the dashboard and never emailed.\r\n- **Rate signal.** Holds plus blocks in a session reaching\r\n  `rate_alert_threshold` within `rate_alert_window_seconds` (default 5 in 300\r\n  seconds) is reported in the decision response as `rate_alert`, once per\r\n  window. Emailing it to the owner waits for VITNA's product-mail domain.\r\n- **Bait, off by default.** `honeytools: true` adds tools no legitimate task\r\n  would call (`export_all_user_data`, `exfiltrate_data_to_attacker_server`,\r\n  `system_admin_console`, or your own `honeytool_names`) to the list the agent\r\n  sees. `honeytokens: true` plants fake credentials in tool output that already\r\n  looks like configuration (a `KEY=value` line). A call to a honeytool, or a\r\n  honeytoken coming back in a later call, is blocked, recorded and sent to the\r\n  alert webhook where one is set; emailing it waits for VITNA's product-mail\r\n  domain. The agent gets the same plain refusal as any other block. The design follows\r\n  AgentShield (Rassul and Rashid, 2026); in our own test run, five benign calls\r\n  across every tool of a test server produced no bait fires, which is a small\r\n  sample and not a measured rate. Bait does not catch an agent that stays\r\n  inside the policy with plausible arguments.\r\n- **Coverage.** Declare what the guard does not see with\r\n  `VITNA_GUARD_UNWRAPPED` (comma-separated) and `VITNA_GUARD_BUILTIN_TOOLS`\r\n  (`yes`/`no`). The session record and the evidence bundle state how many\r\n  declared surfaces were wrapped and name the rest. That statement is the\r\n  operator's declaration; VITNA cannot see an unwrapped server and does not\r\n  verify it. The wrapped server is named by `VITNA_GUARD_NAME` if you set it\r\n  (for example `filesystem`), otherwise by the file name of its command (for\r\n  example `npx` or `node`). From 0.5.1 that name is never a folder path or\r\n  one of the server's arguments; 0.5.0 sent the server's npm package, or its\r\n  full command, which could be a path on your machine.\r\n- **Activation note (0.5.1+).** When guard mode first contacts VITNA, it\r\n  says that guard mode is in use: default mode adds\r\n  `\"guard\": { \"activation\": true, \"mode\": \"default\" }` to its first checked\r\n  call, and policy mode marks the session it opens as opened by the guard.\r\n  From October 17, 2026, VITNA notes on your account, once, that guard mode\r\n  is in use, which mode, and the client version. The note has no tool name, arguments, IP address\r\n  or hostname. Set `VITNA_GUARD_NO_ACTIVATION=1` to stop this; checks still\r\n  work the same.\r\n- **Correlation.** A tool call's `_meta.traceparent` is carried into the\r\n  record, so VITNA's evidence joins your own traces.\r\n- **Evidence.** When the wrapped server exits, the session closes and its\r\n  Ed25519-signed bundle is saved to `~/.vitna/bundles/`. Each hold is one\r\n  `hold-v1` lifecycle record (proposed, held, routed, decided, outcome) inside\r\n  it, verifiable offline with `scripts/verify-evidence.mjs`.\r\n- **Only as wide as what you wrap.** A tool the agent reaches another way (a\r\n  built-in shell, an unwrapped server) is outside the guard, and a blocked or\r\n  held agent may try something else. Wrap every server that can act.\r\n\r\n## Honest limits\r\n\r\nWhat the numbers above do **not** mean:\r\n\r\n- **Readiness ≠ certified.** SOC 2, ISO/IEC 27001, HIPAA and PCI DSS are pre-audit *readiness scorecards*. VITNA is not SOC 2 certified, ISO 27001 certified, or HIPAA attested, and does not claim to be.\r\n- **Breach classification covers 6 jurisdictions**, not all 13 (DPDP-IN, GDPR-EU, CPRA-CA, LGPD-BR, PDPA-SG, US-FED). The other jurisdiction packs cover other checks.\r\n- **US state breach deadlines cover 21 states** plus a generic fallback — not all 50 states, DC and PR.\r\n- **\"24 named statutes\" and \"28 catalogue entries\" are two different countings.** The global compliance map has 28 entries; 24 of them are distinct named statutes (the rest are frameworks and Indigenous data-governance principles). Prose here uses 24.\r\n- **Three counts that are easy to confuse:** 23 MCP tools, 22 identifier-validator API routes (only 6 of which are exposed as MCP tools here), and 11 PII detectors. They are unrelated sets.\r\n- **Detection is heuristic** regex/signature matching — not a sandbox, not a semantic analyzer. Novel or obfuscated payloads can pass. Use it as one layer, not the only one.\r\n- **VITNA does not enforce, except in guard mode.** The tools return a decision and honoring it is your system's job. Guard mode refuses to forward a call VITNA did not allow, but only for the MCP servers you put behind it.\r\n\r\n## License\r\n\r\nMIT © COSTRINITY (Indigenous-owned software studio in Regina, Saskatchewan, Treaty 4 territory, Canada)\r\n","readmeFilename":"README.md"}