Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

com.bidda/bidda-compliance

REMOTE · BIDDA.COM · SCANNED AUG 3

10,065 source-verified compliance nodes, 39 pillars, 25 MCP tools (EU AI Act, GDPR, NIST, MITRE).

Available components

+1 this week 58 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security46
Transport & Reachability100
Schema Quality & AI Usability68
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3735 tokens (~149/item across 25 items; 25 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities40
  • Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · bidda.com

# add to Claude Code
claude mcp add --transport http com-bidda-bidda-compliance https://bidda.com/mcp
# ~/.codex/config.toml
[mcp_servers.com-bidda-bidda-compliance]
url = "https://bidda.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-bidda-bidda-compliance": {
      "type": "remote",
      "url": "https://bidda.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-bidda-bidda-compliance --url https://bidda.com/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-bidda-bidda-compliance:
    url: "https://bidda.com/mcp"
// mcp.json
{
  "mcpServers": {
    "com-bidda-bidda-compliance": {
      "type": "http",
      "url": "https://bidda.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 −2
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

  • 29 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 27 Jul 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 56

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://bidda.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=bidda.com CN=YE1,O=Let's Encrypt,C=US 2 Aug 2026 31 Oct 2026 ECDSA 256 ECDSA-SHA384 5c2cf7b19384a5abdfe531a849e8a636743
SANs: *.bidda.com, bidda.com
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd
DNSSEC insecure

Validation of bidda.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
bidda.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://bidda.com/mcp Verified 200
http (plaintext) http://bidda.com/mcp Served over HTTP 200
MCP tools — 25 exposed · ~3,735 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
browse_topics ~93

Browse the registry by cross-cutting compliance TOPIC (for example data breach notification, AI transparency, AML and KYC). Returns each topic with how many rules carry it and across how many pillars and jurisdictions. Topics sit on top of the 39 pillars without replacing them. Free, no key required. Pass a topic string to drill into one.

NameTypeReqDescription
topicstringOptional topic name to filter or drill into.

No output schema declared.

No examples provided.

check_action_compliance ~135

Pre-flight regulatory check. Agent describes an intended action in natural language ("process EU resident biometric data", "transfer health records to a third-party AI vendor", "deploy autonomous trading model in Singapore") and receives a ranked list of regulations that may apply, plus a risk indicator (LOW/MODERATE/HIGH). The primary tool for runtime compliance gating in autonomous agent workflows.

NameTypeReqDescription
actionstringyesNatural-language description of the intended action.
jurisdictionstringOptional jurisdiction filter (eu, us, uk, etc.).
limitintegerMax matches to return. Default 10. Max 25.

No output schema declared.

No examples provided.

compare_jurisdictions ~122

Compare how different jurisdictions address a compliance topic, side by side, including where their numeric thresholds differ (for example a breach-notification deadline of 72 hours versus 30 days). It surfaces the real rules and numbers and does not rank which jurisdiction is stricter. Requires an active Bidda subscription: pass your key as api_key.

NameTypeReqDescription
api_keystringyesYour Bidda subscription API key (sent as x-bidda-api-key). A free trial counts.
topicstringyesTopic to compare, for example "data breach notification".

No output schema declared.

No examples provided.

consult_node ~266

The one-call governed turn: fetch the full vault node (this consumes one call on your key, exactly like unlocking a node) AND record a verified node_consulted entry for it on an open run, in a single step. The entry pins the node to its current version + integrity hash, so the run receipt proves what the agent actually consulted. Use this instead of get_node when you are inside a run. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
actionstringOptional: an action the agent took or checked.
api_keystringyesYour Bidda subscription API key. A free trial counts.
decisionstringOptional: what the agent decided using this node.
input_hashstringOptional: a sha256:... hash of the user's message instead of the text.
modelstringOptional: the model id/version making the decision.
node_idstringyesThe rule to fetch and record.
run_idstringyesThe open run to record into (from open_run).
subject_hashstringOptional: a sha256:... hash of an end-user identifier. Hash only.
user_inputstringOptional: the end user's message as text.

No output schema declared.

No examples provided.

create_attestation ~159

Create a signed, time-stamped record of which Bidda rules a person or AI agent relied on for a decision. Returns a record ID and a public verify URL so anyone can later confirm the record has not been changed. Useful for agents that must keep an audit trail of what they checked. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
actionstringOptional: what the agent did.
agentstringyesThe system or AI agent that made the decision.
api_keystringyesYour Bidda subscription API key. A free trial counts.
nodesarrayyesnode_ids that were checked (max 50).
workflow_steps_followedarrayOptional: steps the agent followed.

No output schema declared.

No examples provided.

create_control_attestation ~267

Sign a tamper-evident record of one of YOUR OWN controls or policies and the Bidda obligation nodes it maps to. Each obligation is pinned to its current version + integrity hash at signing time, so the record shows what the control was mapped against on that date. This is the design-side evidence ('we operate this control, mapped to these obligations'); run receipts are the operating-side evidence. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
api_keystringyesYour Bidda subscription API key. A free trial counts.
controlstringyesThe name of your control or policy.
control_ownerstringOptional: the role or team that owns the control.
control_statusstringOptional: implemented | planned | in-progress.
effective_datestringOptional: YYYY-MM-DD the control took effect.
evidence_refstringOptional: a reference/URL/hash to your own evidence (kept by you).
frameworkstringOptional: the framework you are mapping to (e.g. "EU AI Act").
nodesarrayyesObligation node_ids the control maps to (max 50).
statementstringyesWhat the control does or asserts (plain text).

No output schema declared.

No examples provided.

drift_check ~133

Check whether the compliance rules an agent has cached in its own memory are still current. Submit the node_id and the integrity hash you stored when you last grounded on each rule; get back, per rule, whether it is fresh, has drifted (content changed), or was withdrawn (instrument repealed) - so the agent re-grounds before acting on stale law. Included with every API tier; the per-call batch size scales with your plan. Pass api_key.

NameTypeReqDescription
anchorsarrayyesThe cached rules to check.
api_keystringyesYour Bidda subscription API key. A free trial counts.

No output schema declared.

No examples provided.

gap_check ~139

Given the compliance rules a team says it covers, return the prerequisite rules Bidda's dependency graph links to them that were NOT listed - the 'you missed the prerequisite obligation' gaps - plus any covered rule the registry marks withdrawn. A coverage aid for a qualified reviewer; it does not rank or determine compliance. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
api_keystringyesYour Bidda subscription API key. A free trial counts.
depthnumberOptional: how many dependency hops to walk (1-3, default 1).
nodesarrayyesThe node_ids you cover (max 200).

No output schema declared.

No examples provided.

get_audit_pack ~147

Export a run as a governance evidence pack: the signed receipt, every entry, a roll-up of the nodes consulted (with pinned versions/hashes), an independent hash-chain + Merkle integrity self-check, and a coversheet mapping the receipt to the record-keeping obligations it supports (EU AI Act Art. 12/26, ISO/IEC 42001, NIST AI RMF). A sealed run is readable by id; a still-open run's draft pack needs your api_key.

NameTypeReqDescription
api_keystringOptional: your Bidda key, required for a still-open (unsealed) run.
run_idstringyesThe run to export.

No output schema declared.

No examples provided.

get_crosswalk ~82

Return the cross-framework mapping dimensions for a node: which other regulations, standards, or jurisdictions this rule maps to (e.g. GDPR Article 17 → CCPA right-to-delete → POPIA Section 24). Discovery returns the available dimensions; full mapping values are vault-gated.

NameTypeReqDescription
node_idstringyesNode ID to inspect crosswalks for.

No output schema declared.

No examples provided.

get_dependency_chain ~107

Walk the prerequisite chain for a compliance node. Given one node, returns its full dependency tree (the prior obligations an agent must satisfy before this one applies). Use this to plan a complete compliance posture: unlocking one node usually requires understanding 3-8 upstream nodes. Defaults to depth 2; max 4.

NameTypeReqDescription
max_depthintegerHow many hops to walk (1-4). Default 2.
node_idstringyesRoot node ID to expand from.

No output schema declared.

No examples provided.

get_jurisdiction_bundle ~120

Return all compliance nodes that apply in a specific jurisdiction (EU, US, UK, Australia, Singapore, India, Canada, China, South Africa, Japan, Brazil and others). Use when an agent enters a new market and needs the full regulatory surface for that geography.

NameTypeReqDescription
jurisdictionstringyesJurisdiction code or name: eu, us, uk, au, sg, india, canada, china, south-africa, japan, brazil.
limitintegerMax nodes to return. Default 25. Max 100.

No output schema declared.

No examples provided.

get_latest_changes ~99

List the most recently updated compliance nodes: the regulatory change feed. Use to monitor incoming amendments, new guidance, or freshly added rules. Filter by pillar to focus on a domain. Agents should call this on a schedule to keep compliance posture current.

NameTypeReqDescription
daysintegerLook back N days. Default 30. Max 180.
pillarstringOptional pillar filter, e.g. "AI Governance" or "Cybersecurity".

No output schema declared.

No examples provided.

get_mitre_mapping ~294

The MITRE Rosetta Stone. Given a MITRE technique ID across 5 frameworks (ATT&CK Enterprise, ATT&CK Mobile, ATT&CK ICS, D3FEND, ATLAS), return the Bidda node for that technique plus its mapped compliance obligations: NIST 800-53 controls, ISO 27001 Annex A clauses, PCI DSS requirements, NIS2 articles, HIPAA Security Rule, DORA articles, NERC CIP, IEC 62443. The bridge between how SOC teams think (technique IDs) and how compliance teams think (control families). Free.

NameTypeReqDescription
technique_idstringyesMITRE technique ID. ATT&CK Enterprise (T1566, T1486, T1078, T1003.001, T1547.001); ATT&CK Mobile (T1474, T1521, T1471, T1430, T1417); ATT&CK ICS (T0883, T0809, T0879, T0886, T0814); D3FEND (D3-FIM, D…

No output schema declared.

No examples provided.

get_node ~118

Get a specific compliance node by its ID. Returns the node summary: title, compliance pillar, version, last updated, and BLUF. The full node (machine-executable deterministic workflow, actionable schema, primary legal citations, dependency chain) is available at bidda.com.

NameTypeReqDescription
idstringyesNode ID, e.g. "basel-iii-capital", "gdpr-article-5-principles", "fatf-40-recommendations-2023-consolidated", "us-hipaa-privacy-rule"

No output schema declared.

No examples provided.

get_run ~82

Fetch a run and its entries. The owner can read an open or sealed run (pass api_key); a sealed run is also publicly readable by id and reports whether its signature is valid.

NameTypeReqDescription
api_keystringOptional: your Bidda key, required to read your own still-open run.
run_idstringyesThe run_id to fetch.

No output schema declared.

No examples provided.

list_pillars ~101

List all compliance pillars in the Bidda Sovereign Intelligence registry with node counts. Use this first to discover available compliance domains before searching. Bidda has 10,085 cryptographically-verified nodes across 39 pillars, including a MITRE layer spanning 6 frameworks (ATT&CK Enterprise/Mobile/ICS, D3FEND, ATLAS, CAPEC) plus Banking, AI Governance, Cybersecurity, Healthcare, Legal, ESG and more.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

obligation_deltas ~164

The obligation-level change feed: primary sources whose content changed (or whose node was withdrawn), mapped to the Bidda obligation nodes they affect, filterable by time, pillar, or specific nodes. Use it to answer 'what obligations changed since I last reviewed?'. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
api_keystringyesYour Bidda subscription API key. A free trial counts.
limitnumberOptional: max deltas to return (default 100, max 500).
nodesarrayOptional: restrict to deltas affecting these node_ids.
pillarstringOptional: restrict to one pillar.
sincestringOptional: ISO timestamp; only deltas newer than this are returned.

No output schema declared.

No examples provided.

open_run ~132

Open a run ledger: a signed, tamper-evident log of what an agent does across a whole task or conversation (for example a support-bot chat). Returns a run_id. Record one entry per turn with record_run_entry, then seal_run to get a single signed Run Receipt. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
agentstringyesThe system or agent running the task or conversation.
api_keystringyesYour Bidda subscription API key. A free trial counts.
labelstringOptional human label, for example the chat or ticket id.

No output schema declared.

No examples provided.

oscal_assessment_results ~125

Export a governed run's evidence as a NIST OSCAL assessment-results document (the machine-readable format GRC and audit tooling consumes): reviewed-controls (the obligation nodes consulted), observations (each pinned to its version + integrity hash), and props recording the independent integrity self-check. A sealed run is readable by id; a still-open run needs your api_key.

NameTypeReqDescription
api_keystringOptional: your Bidda key, required for a still-open (unsealed) run.
run_idstringyesThe run to export as OSCAL assessment-results.

No output schema declared.

No examples provided.

point_in_time ~114

Get a signed record of which committed version of a rule was authoritative at a specific past date, anchored to the public history chain. Useful when an agent must show what a rule said at the moment it acted. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
api_keystringyesYour Bidda subscription API key. A free trial counts.
as_ofstringISO date or time, or epoch milliseconds. Defaults to now.
node_idstringyesThe rule (node_id).

No output schema declared.

No examples provided.

record_run_entry ~339

Append one entry to an open run: which Bidda rules the agent consulted, what it decided, and the end user's input (as text via note, or privately as input_hash). Each entry is hash-chained to the previous one. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
actionstringOptional: an action the agent took or checked.
api_keystringyesYour Bidda subscription API key. A free trial counts.
decisionstringOptional: what the agent decided or did this turn.
entry_typestringOptional: node_consulted | action_checked | decision | note. Defaults to note.
input_hashstringOptional: a sha256:... hash of the user's message instead of the text.
modelstringOptional: the model id/version that produced this decision (e.g. gpt-4o-2024-08-06).
nodesarrayOptional node_ids the agent consulted (max 50).
notestringOptional: the end user's message as text.
output_hashstringOptional: a sha256:... hash of the agent's output.
run_idstringyesThe run_id returned by open_run.
subject_hashstringOptional: a sha256:... hash of an end-user identifier for per-subject traceability. Hash only, never plaintext.
verify_nodesbooleanOptional: pin each node in "nodes" to its current version + integrity hash (proof, not just a claim). No extra call charge.

No output schema declared.

No examples provided.

seal_run ~85

Seal an open run into one signed Run Receipt covering every entry, with a public verify URL. Idempotent: sealing an already-sealed run returns the same receipt. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
api_keystringyesYour Bidda subscription API key. A free trial counts.
run_idstringyesThe run_id to seal.

No output schema declared.

No examples provided.

search_nodes ~171

Search Bidda compliance nodes by keyword. Returns matching node summaries including a one-sentence BLUF (Bottom Line Up Front): the exact compliance obligation in plain language. Every node traces to a primary legal source (no hallucination). Examples: "Basel III capital", "GDPR data breach", "AML transaction monitoring", "SOC 2 Type II".

NameTypeReqDescription
limitnumberMax results (default 10, max 25)
pillarstringOptional: filter by pillar name, e.g. "Banking & Global Finance", "Cybersecurity", "AI Governance & Law", "Medical & Healthcare"
querystringyesSearch terms, e.g. "Basel III capital requirements", "GDPR data breach notification 72 hours", "FATF travel rule"

No output schema declared.

No examples provided.

watch_changes ~141

Subscribe to regulatory change alerts: watch specific rules and/or whole pillars and get notified by email or webhook when their primary source changes. Requires an active Bidda subscription: pass api_key.

NameTypeReqDescription
api_keystringyesYour Bidda subscription API key. A free trial counts.
channelsobjectDelivery channels, for example { "email": true, "webhook": false }. Defaults to email.
labelstringOptional name for the alert.
nodesarraynode_ids to watch.
pillarsarrayPillar names to watch.
webhook_urlstringRequired if the webhook channel is enabled.

No output schema declared.

No examples provided.