{"_id":"@csgaglobal/casa-certification","name":"@csgaglobal/casa-certification","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@csgaglobal/casa-certification","version":"1.0.0","description":"CASA Certification - CSOAI-Authorised Safety Assessment MCP Server","type":"module","main":"dist/index.js","bin":{"casa-certification-mcp":"dist/index.js"},"scripts":{"watch":"tsc --watch","start":"node dist/index.js","dev":"tsc && node dist/index.js","build":"tsc"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.1","zod":"^3.22.4"},"devDependencies":{"@types/node":"^20.10.6","typescript":"^5.3.3"},"author":{"name":"CSGA Global — Cyber Security Global Alliance"},"license":"CC0-1.0","repository":{"type":"git","url":"git+https://github.com/csga-global/mcp-servers.git","directory":"packages/casa-certification"},"homepage":"https://csga-global.org/casa","keywords":["mcp","casa","certification","ai-safety","assessment","compliance","audit"],"_id":"@csgaglobal/casa-certification@1.0.0","gitHead":"c7c0f8605f06b783f4bac5b541f4732ebce8b560","types":"./dist/index.d.ts","bugs":{"url":"https://github.com/csga-global/mcp-servers/issues"},"_nodeVersion":"22.16.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-hmwmyTrxrfVkE5h344LICtCZKYHl8rHDbx+8y5XrhRayRvAaplspdHNpw5g8KwxFoHW4ls4fF/+2dKvXEDD4Gw==","shasum":"13c598eb9186738f2402a3811c4cd147456b5c88","tarball":"https://registry.npmjs.org/@csgaglobal/casa-certification/-/casa-certification-1.0.0.tgz","fileCount":31,"unpackedSize":162051,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDGkUxQWkvWS2d1h1VgPYDMdV4spkqa26C+SwKmfV2waAIhALZ+MRx9JOf+KzwQfu9R5BxmOgsRqvVwldPrfoBlJHdY"}]},"_npmUser":{"name":"csga_global","email":"Nicholastempleman@gmail.com"},"directories":{},"maintainers":[{"name":"csga_global","email":"Nicholastempleman@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/casa-certification_1.0.0_1772122505984_0.09740782548691107"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-26T16:15:05.855Z","1.0.0":"2026-02-26T16:15:06.131Z","modified":"2026-02-26T16:15:06.397Z"},"maintainers":[{"name":"csga_global","email":"Nicholastempleman@gmail.com"}],"description":"CASA Certification - CSOAI-Authorised Safety Assessment MCP Server","homepage":"https://csga-global.org/casa","keywords":["mcp","casa","certification","ai-safety","assessment","compliance","audit"],"repository":{"type":"git","url":"git+https://github.com/csga-global/mcp-servers.git","directory":"packages/casa-certification"},"author":{"name":"CSGA Global — Cyber Security Global Alliance"},"bugs":{"url":"https://github.com/csga-global/mcp-servers/issues"},"license":"CC0-1.0","readme":"# CASA Certification MCP Server\n\nA standalone Model Context Protocol (MCP) server for CASA Certification — CSOAI-Authorised Safety Assessment. This server provides comprehensive AI system certification tools with a 4-tier framework, Byzantine Council consensus mechanisms, and detailed compliance assessment.\n\n## Overview\n\nCASA (CSOAI-Authorised Safety Assessment) is a rigorous framework for certifying AI systems with respect to safety, alignment, and responsible deployment. This MCP server operationalizes the CASA methodology by providing tools for assessment, gap analysis, Byzantine consensus simulation, roadmap planning, and audit preparation.\n\n### Key Features\n\n- **4-Tier Certification Framework**: T1 (Self-Assessment), T2 (Third-Party Audit), T3 (Continuous Monitoring), T4 (Byzantine Council)\n- **Comprehensive Assessment**: Evaluates systems across 5 critical domains (Governance, Data, Model, Deployment, Monitoring)\n- **Byzantine Council Simulation**: 33-LLM consensus voting with supermajority requirements\n- **Gap Analysis**: Ranked gap identification with severity, effort, and cost estimates\n- **Certification Roadmaps**: Phased timelines with milestones and resource requirements\n- **Audit Checklists**: Domain-specific evidence requirements and tier-appropriate items\n- **Quick Scoring**: Rapid compliance assessment from key questions\n\n## Installation\n\n```bash\n# Clone or download the server\ncd /path/to/casa-certification\n\n# Install dependencies\nnpm install\n\n# Build TypeScript\nnpm run build\n\n# Start the server\nnpm start\n```\n\n## Architecture\n\n### Directory Structure\n\n```\ncasa-certification/\n├── src/\n│   ├── index.ts                 # Main MCP server and tool handlers\n│   ├── schemas.ts               # Zod validation schemas and types\n│   ├── assessment.ts            # Full assessment logic\n│   ├── gap-analysis.ts          # Gap analysis and prioritization\n│   ├── byzantine.ts             # Byzantine Council simulation\n│   ├── roadmap-checklist.ts     # Roadmap and checklist generation\n│   └── resources.ts             # Knowledge resources and methodologies\n├── package.json\n├── tsconfig.json\n└── README.md\n```\n\n### Key Components\n\n**1. Assessment Engine (`assessment.ts`)**\n- Domain-based scoring (governance, data, model, deployment, monitoring)\n- Risk-adjusted compliance calculations\n- Tier determination based on total score\n- Remediation step generation\n- Timeline and cost estimation\n\n**2. Gap Analysis (`gap-analysis.ts`)**\n- Current state vs. target tier comparison\n- Domain-specific gap identification\n- Severity-based prioritization\n- Effort and cost estimation\n- Tier-specific requirements mapping\n\n**3. Byzantine Council (`byzantine.ts`)**\n- 33-judge diversity engine (specialties, orientations)\n- Independent evaluation simulation\n- Supermajority voting (22/33 required)\n- Dissenting opinion capture\n- Confidence score calculation\n\n**4. Roadmap Generation (`roadmap-checklist.ts`)**\n- Multi-phase implementation plans\n- Resource allocation by phase\n- Milestone definition and success criteria\n- Cost breakdown and timeline adjustment\n- Risk factor identification\n\n**5. Schema Validation (`schemas.ts`)**\n- Zod-based input validation\n- Type-safe response structures\n- Enum constraints for consistency\n- Comprehensive type definitions\n\n## Tools\n\n### 1. casa_full_assessment\n\nComplete 4-tier CASA certification assessment providing comprehensive evaluation across all domains.\n\n**Input:**\n```typescript\n{\n  aiSystemName: string;           // Name of the AI system\n  description: string;             // Detailed system description\n  sector: Sector;                  // Industry: healthcare, finance, autonomous-systems, etc.\n  deploymentContext: string;       // Where/how deployed\n  estimatedRiskLevel: RiskLevel;   // minimal, low, moderate, high, critical\n}\n```\n\n**Output:**\n```typescript\n{\n  assessmentId: string;\n  systemName: string;\n  completionDate: string;\n  tierRecommendation: CertificationTier;  // T1-T4\n  complianceScore: number;         // 0-100\n  gaps: Gap[];                     // Identified gaps with severity\n  remediationSteps: string[];      // Phased remediation plan\n  estimatedTimeline: string;       // Timeline to certification\n  costRange: [number, number];     // Cost estimate\n  confidenceLevel: string;         // low, medium, high\n  nextSteps: string[];            // Recommended next actions\n}\n```\n\n**Example:**\n```bash\ncurl -X POST http://localhost:3000/tools/casa_full_assessment \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"aiSystemName\": \"ContentGuardian LLM\",\n    \"description\": \"Large language model for content moderation with multi-lingual support\",\n    \"sector\": \"content-generation\",\n    \"deploymentContext\": \"Cloud-based API serving 2M+ daily requests\",\n    \"estimatedRiskLevel\": \"high\"\n  }'\n```\n\n### 2. casa_gap_analysis\n\nIdentify specific gaps between current practices and target certification tier.\n\n**Input:**\n```typescript\n{\n  currentPractices: string;   // Description of current practices\n  targetTier: CertificationTier;  // T1, T2, T3, or T4\n}\n```\n\n**Output:**\n```typescript\nGap[]  // Array of gaps with:\n// - id, area, description\n// - severity (critical, high, medium, low)\n// - remediationEffort (low, medium, high)\n// - priority (numeric ranking)\n// - estimatedHours, costRange\n```\n\n### 3. casa_byzantine_simulate\n\nSimulate Byzantine Council consensus process with 33 independent LLM judges.\n\n**Input:**\n```typescript\n{\n  assessmentData: Record<string, unknown>;  // Assessment metrics\n  numJudges?: number;  // 3-99, default 33\n}\n```\n\n**Output:**\n```typescript\n{\n  votes: Record<string, number>;  // approve, reject, abstain counts\n  consensus: boolean;\n  consensusDecision: string;\n  supermajority: {\n    achieved: boolean;\n    votesFor: number;\n    votesAgainst: number;\n    abstained: number;\n    required: number;  // 22/33 for T4\n  };\n  confidenceScore: number;  // 0-100\n  dissentingOpinions: string[];  // Top dissenting views\n  deliberationNotes: string[];  // Sample of judge reasoning\n}\n```\n\n### 4. casa_certification_roadmap\n\nGenerate phased certification roadmap with timelines and resource requirements.\n\n**Input:**\n```typescript\n{\n  organizationSize: \"small\" | \"medium\" | \"large\" | \"enterprise\";\n  sector: Sector;\n  currentMaturityLevel: \"initial\" | \"developing\" | \"managed\" | \"optimized\";\n  targetTier: CertificationTier;\n  timelinePreference: \"accelerated\" | \"standard\" | \"extended\";\n}\n```\n\n**Output:**\n```typescript\n{\n  organizationProfile: {...};\n  totalDuration: string;  // \"24 weeks (approximately 6 months)\"\n  totalEstimatedCost: [number, number];\n  phases: RoadmapPhase[];  // Each with milestones, activities, criteria\n  riskFactors: string[];\n  criticalSuccessFactors: string[];\n}\n```\n\n### 5. casa_audit_checklist\n\nGenerate audit preparation checklist with evidence requirements.\n\n**Input:**\n```typescript\n{\n  tier: CertificationTier;\n  sector: Sector;\n  aiSystemType: string;  // LLM, recommendation engine, etc.\n}\n```\n\n**Output:**\n```typescript\n{\n  tier: string;\n  sector: string;\n  systemType: string;\n  generatedDate: string;\n  sections: {\n    [domain: string]: ChecklistItem[];  // governance, data, model, etc.\n  };\n  estimatedCompletionHours: number;\n  totalItems: number;\n}\n```\n\n### 6. casa_score\n\nQuick compliance scoring from key assessment questions.\n\n**Input:**\n```typescript\n{\n  answers: Record<string, string | number | boolean>;\n  // Example keys: governance_board, data_lineage, safety_testing, etc.\n}\n```\n\n**Output:**\n```typescript\n{\n  score: number;  // 0-100\n  percentage: string;\n  qualifyingTier: CertificationTier;\n  gaps: Array<{area: string; gap: string}>;  // Top 3\n  recommendations: string[];\n}\n```\n\n## Resources\n\nThe server provides three key resources accessible via the MCP resource protocol:\n\n### casa://methodology\nComplete CASA methodology documentation including:\n- Core principles (risk-based, transparency, continuous assurance)\n- Assessment domains and scoring methodology\n- Tier advancement criteria\n\n### casa://tiers\nDetailed tier definitions:\n- **T1**: Self-Assessment (40+ points, 6-month validity)\n- **T2**: Third-Party Audit (65+ points, 12-month validity)\n- **T3**: Continuous Monitoring (80+ points, 18-month validity)\n- **T4**: Byzantine Council Review (90+ points, 24-month validity)\n\n### casa://pricing\nCASA pricing structure:\n- Tier-specific cost ranges\n- Volume discounts\n- Academic/non-profit rates\n- Payment terms and additional services\n\n## Certification Tiers\n\n### Tier 1: Self-Assessment (T1)\n- **Minimum Score**: 40/100\n- **Duration**: 2-6 weeks\n- **Cost**: $5,000 - $15,000\n- **Validity**: 6 months\n- **Process**: Internal self-assessment with structured guidance\n\n### Tier 2: Third-Party Audit (T2)\n- **Minimum Score**: 65/100\n- **Duration**: 8-16 weeks\n- **Cost**: $25,000 - $75,000\n- **Validity**: 12 months\n- **Process**: CASA-accredited auditor conducts comprehensive evaluation\n\n### Tier 3: Continuous Monitoring (T3)\n- **Minimum Score**: 80/100\n- **Duration**: 12-20 weeks initial, ongoing monitoring\n- **Cost**: $75,000 - $200,000/year\n- **Validity**: 18 months (with continuous monitoring)\n- **Process**: T2 audit + real-time monitoring + quarterly reassessments\n\n### Tier 4: Byzantine Council Review (T4)\n- **Minimum Score**: 90/100\n- **Duration**: 20-32 weeks\n- **Cost**: $200,000 - $500,000+\n- **Validity**: 24 months (with continuous monitoring)\n- **Process**: 33-judge panel with 22/33 supermajority requirement\n\n## Assessment Domains\n\nAll assessments evaluate five critical domains:\n\n1. **Governance** (20 points)\n   - Safety review board, incident response, compliance tracking\n\n2. **Data** (20 points)\n   - Data lineage, quality assurance, bias mitigation, privacy\n\n3. **Model** (20 points)\n   - Training methodology, safety testing, failure analysis, alignment\n\n4. **Deployment** (20 points)\n   - Monitoring, access controls, safeguards, audit logging\n\n5. **Monitoring** (20 points)\n   - Performance tracking, anomaly detection, reassessment schedule\n\n## Usage Examples\n\n### Quick Assessment of System\n\n```bash\n# Generate quick compliance score\ncurl -X POST http://localhost:3000/tools/casa_score \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"answers\": {\n      \"governance_board\": true,\n      \"data_lineage\": true,\n      \"safety_testing\": false,\n      \"deployment_monitoring\": true,\n      \"continuous_monitoring\": false\n    }\n  }'\n```\n\n### Full Assessment for AI System\n\n```bash\n# Run comprehensive assessment\ncurl -X POST http://localhost:3000/tools/casa_full_assessment \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"aiSystemName\": \"ContentGuardian LLM\",\n    \"description\": \"Multi-lingual content moderation system using fine-tuned LLM\",\n    \"sector\": \"content-generation\",\n    \"deploymentContext\": \"Cloud API, production, 2M daily requests\",\n    \"estimatedRiskLevel\": \"high\"\n  }'\n```\n\n### Generate Certification Roadmap\n\n```bash\n# Get phased implementation plan\ncurl -X POST http://localhost:3000/tools/casa_certification_roadmap \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"organizationSize\": \"large\",\n    \"sector\": \"finance\",\n    \"currentMaturityLevel\": \"developing\",\n    \"targetTier\": \"T3\",\n    \"timelinePreference\": \"standard\"\n  }'\n```\n\n### Simulate Byzantine Council\n\n```bash\n# Test consensus mechanism\ncurl -X POST http://localhost:3000/tools/casa_byzantine_simulate \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"assessmentData\": {\n      \"complianceScore\": 92,\n      \"riskLevel\": \"moderate\",\n      \"incidentHistory\": \"clean\"\n    },\n    \"numJudges\": 33\n  }'\n```\n\n## Validation\n\nAll inputs are validated using Zod schemas. Validation errors provide clear feedback:\n\n```typescript\n// Invalid input\n{\n  \"aiSystemName\": \"\",  // Too short\n  \"description\": \"Short\",  // Too short\n  \"sector\": \"invalid\",  // Invalid enum\n  \"deploymentContext\": \"Cloud\",  // Too short\n  \"estimatedRiskLevel\": \"unknown\"  // Invalid enum\n}\n\n// Returns error with details on each field\n```\n\n## Error Handling\n\nThe server handles errors gracefully:\n\n```json\n{\n  \"error\": \"Validation error: aiSystemName is required\",\n  \"details\": {\n    \"field\": \"aiSystemName\",\n    \"message\": \"String must contain at least 1 character(s)\"\n  }\n}\n```\n\n## Development\n\n### Build\n```bash\nnpm run build\n```\n\n### Watch Mode\n```bash\nnpm run watch\n```\n\n### Development Server\n```bash\nnpm run dev\n```\n\n### Type Checking\n```bash\nnpm run build  # Includes type checking\n```\n\n## Testing Scenarios\n\n### Scenario 1: Early-Stage Startup\n\n```bash\n# Assessment for new AI company\nPOST /tools/casa_full_assessment\n{\n  \"aiSystemName\": \"NewAI ChatBot\",\n  \"description\": \"Conversational AI for customer support\",\n  \"sector\": \"other\",\n  \"deploymentContext\": \"Internal testing\",\n  \"estimatedRiskLevel\": \"low\"\n}\n\n# Expected: T1 recommendation, 45-55 compliance score\n```\n\n### Scenario 2: Regulated Industry\n\n```bash\n# Assessment for healthcare AI\nPOST /tools/casa_full_assessment\n{\n  \"aiSystemName\": \"MediDiagnose\",\n  \"description\": \"Medical imaging analysis with FDA requirements\",\n  \"sector\": \"healthcare\",\n  \"deploymentContext\": \"Hospital systems, clinical decision support\",\n  \"estimatedRiskLevel\": \"critical\"\n}\n\n# Expected: T3/T4 recommendation, 75+ compliance score required\n```\n\n### Scenario 3: Compliance Journey\n\n```bash\n# Identify gaps for T3 certification\nPOST /tools/casa_gap_analysis\n{\n  \"currentPractices\": \"We have basic monitoring and incident response\",\n  \"targetTier\": \"T3\"\n}\n\n# Then generate roadmap\nPOST /tools/casa_certification_roadmap\n{\n  \"organizationSize\": \"medium\",\n  \"sector\": \"finance\",\n  \"currentMaturityLevel\": \"managed\",\n  \"targetTier\": \"T3\",\n  \"timelinePreference\": \"standard\"\n}\n```\n\n## Configuration\n\nEnvironment variables (optional):\n\n```bash\n# Server binding\nMCP_SERVER_HOST=localhost\nMCP_SERVER_PORT=3000\n\n# Resource paths\nCASA_RESOURCES_PATH=./resources\n\n# Logging\nLOG_LEVEL=info  # debug, info, warn, error\n```\n\n## Performance Considerations\n\n- **Assessment Generation**: ~100-500ms (depends on system complexity)\n- **Byzantine Simulation**: ~200-1000ms (scales with judge count)\n- **Roadmap Generation**: ~100-300ms\n- **Gap Analysis**: ~50-200ms\n\nAll tools are stateless and can handle concurrent requests.\n\n## Security\n\n- No external API calls or network dependencies\n- All computation is local\n- No data persistence or logging\n- Zod validation prevents injection attacks\n- Type-safe TypeScript throughout\n\n## Contributing\n\nThis is a reference implementation of the CASA methodology. Contributions welcome:\n\n1. Fork the repository\n2. Create a feature branch\n3. Submit a pull request with tests\n\n## License\n\nCC0-1.0 — Public Domain. See LICENSE file.\n\n## Support\n\nFor questions about CASA methodology:\n- Visit: https://csoai.org/casa\n- Contact: casa-team@csoai.org\n\nFor MCP server issues:\n- GitHub Issues: [project-repo]/issues\n- Documentation: [project-repo]/docs\n\n## Changelog\n\n### v1.0.0 (Initial Release)\n- Full MCP server implementation\n- 6 core tools (full assessment, gap analysis, Byzantine simulation, roadmap, checklist, quick score)\n- 3 knowledge resources (methodology, tiers, pricing)\n- Zod validation on all inputs\n- TypeScript strict mode\n- Production-ready code quality\n\n## Acknowledgments\n\nCASA framework developed by the Council for the Safety of Artificial Intelligence (CSOAI).\n\nThis MCP implementation follows best practices from the Model Context Protocol specification.\n","readmeFilename":"README.md","_rev":"1-7ade9360b75eab8cd2405f4ade5a84bb"}