global.rootz.private/companies
REMOTE · PRIVATE.ROOTZ.GLOBAL · SCANNED AUG 7
Confirm a US business is real and find who controls it. 32.6M official registry records.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security60
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 11 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability78
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1375 tokens (~125/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management13
- Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities20
- Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28. See how to fix → Fail
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · private.rootz.global
claude mcp add --transport http global-rootz-private-companies https://private.rootz.global/mcp
[mcp_servers.global-rootz-private-companies] url = "https://private.rootz.global/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"global-rootz-private-companies": {
"type": "remote",
"url": "https://private.rootz.global/mcp",
"enabled": true
}
}
} openclaw mcp add global-rootz-private-companies --url https://private.rootz.global/mcp --transport streamable-http
mcp_servers:
global-rootz-private-companies:
url: "https://private.rootz.global/mcp" {
"mcpServers": {
"global-rootz-private-companies": {
"type": "http",
"url": "https://private.rootz.global/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 7 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 5 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 4 Aug 26 +1
- Tool “private_browse” rewrote its description, which is the text the model reads security
- Tool “private_ceo_search” rewrote its description, which is the text the model reads security
- Tool “private_entity” rewrote its description, which is the text the model reads security
- Tool “private_owner_operated” rewrote its description, which is the text the model reads security
- Tool “private_search” rewrote its description, which is the text the model reads security
- Tool “private_stats” rewrote its description, which is the text the model reads security
- Tool “private_officer_search” rewrote its description, which is the text the model reads security
- Schema quality: pass → fail ▼ functional
- Stability: unverified → 0.03 ▲ functional
- 3 Aug 26 60
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 7 Aug 2026 · Probed https://private.rootz.global/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=private.rootz.global | CN=YE1,O=Let's Encrypt,C=US | 30 Jun 2026 | 28 Sept 2026 | ECDSA 256 | ECDSA-SHA384 | 59b2d4f525806287aeb3d0522f7e51f79ef |
| SANs: private.rootz.global | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC secure
Validation of private.rootz.global. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| global. | present | 13060 | 8 | Verified |
| rootz.global. | present | 40948, 52524 | 13, 13 | Verified |
| private.rootz.global. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| x-content-type-options | nosniff |
| x-frame-options | DENY |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://private.rootz.global/mcp | Verified | 200 | |
| http (plaintext) | http://private.rootz.global/mcp | HTTPS enforced | 301 | https://private.rootz.global/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
private_age_distribution ~74
Get business age distribution — how many entities are 0-4, 5-9, 10-14, 15-19, 20-29, 30-39, 40+ years old. Optionally filter by state.
| Name | Type | Req | Description |
|---|---|---|---|
| state | string | – | Filter by state: FL, NY |
No output schema declared.
No examples provided.
private_browse ~208
Build a list of companies matching criteria rather than looking one up: state, industry (NAICS), entity type, age, city, ZIP. Use it for prospecting, market sizing, or finding every business of a kind in a place. Ask for an industry with the naics filter — 23 is construction, 238 specialty trades, 238160 roofing.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | – | City name (partial match) |
| county | string | – | County (NY only) |
| limit | number | – | Max results (default 25) |
| max_age | number | – | Maximum business age in years |
| min_age | number | – | Minimum business age in years |
| offset | number | – | Pagination offset |
| state | string | – | Two-letter state code, e.g. FL, NY, CA, TX |
| type | string | – | Entity type: domestic_profit, domestic_llc, domestic_lp, foreign_profit |
| zip | string | – | ZIP code prefix |
No output schema declared.
No examples provided.
private_ceo_search ~100
Find the chief executive, president, chairman or manager behind a company, or find every company a named executive runs. Use when the question is "who is actually in charge here" rather than "does this company exist". Restricted to executive-level titles; use private_officer_search for any role including directors and secretaries.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max results (default 25) |
| name | string | yes | CEO/president name to search |
No output schema declared.
No examples provided.
private_entity ~121
You have already identified a company and now need the full official record: current status, incorporation date, EIN, registered agent, every officer with their role, addresses, and filing history. This is the record a state government actually holds, so use it to settle questions that web sources disagree about — mirrors frequently report stale status or the wrong registered agent.
| Name | Type | Req | Description |
|---|---|---|---|
| state | string | yes | Two-letter state code, e.g. FL, NY, CA, TX |
| state_id | string | yes | State entity ID (FL: Corporation Number, NY: DOS ID) |
No output schema declared.
No examples provided.
private_geography ~74
Geographic distribution of private businesses. Group by city, zip, county, or state. Shows where businesses are concentrated.
| Name | Type | Req | Description |
|---|---|---|---|
| group_by | string | – | Group by: city, zip, county, state |
| limit | number | – | Top N locations (default 30) |
| state | string | – | Filter by state |
No output schema declared.
No examples provided.
private_officer_search ~149
Find which companies a named person is an officer, director or registered agent of. Use it to check whether a counterparty is who they claim, to map the other entities behind one operator, or to find every company a person controls before signing with any of them. Covers 21.2M officer records.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max results (default 25) |
| name | string | yes | Officer/CEO name or partial name |
| state | string | – | Two-letter state code, e.g. FL, NY, CA, TX |
| title | string | – | Filter by title: ceo, president, director, secretary, treasurer, vp, chairman, manager |
No output schema declared.
No examples provided.
private_owner_operated ~160
Find businesses where an officer is also the registered agent — the filing lists the same person in both roles. This is a succession and acquisition signal: it usually means an owner-operated company with no management layer. Use it to build acquisition target lists or to judge whether a supplier depends on one person. It indicates what the filing says, not legal ownership or control.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | – | City filter |
| limit | number | – | Max results (default 50) |
| min_age | number | – | Minimum business age (default 15) |
| offset | number | – | Pagination offset |
| state | string | – | Two-letter state code, e.g. FL, NY, CA, TX |
| type | string | – | Entity type filter |
No output schema declared.
No examples provided.
private_resolve ~148
Resolve a messy or partial business name to ONE canonical government record, with a computed confidence score (0-1), an ambiguity flag and ranked alternatives. Use this when you have a company name from a document, email or user message and need to identify the actual registered entity. Prefer this over private_search when the goal is identification rather than browsing. If confidence is below 0.6, show the user the alternatives instead of choosing one.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | – | City, used as a corroborating signal |
| query | string | yes | Business name as you have it, however messy |
| state | string | – | Two-letter state code to narrow the search, e.g. FL |
No output schema declared.
No examples provided.
private_search ~204
Find US businesses by name when you do not yet know which one you want. Full-text ranked search over 30.6M entities from 56 state and territory registries. Use it to browse candidates or check whether a name exists at all; use private_resolve instead when you need to identify one specific company. Note: this matches NAMES. There is no industry classification in the search itself, so "roofing" returns companies named "Roofing ...", not every roofer — use private_list with a naics filter for that.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max results (default 25, max 200) |
| query | string | yes | Business name or partial name to search |
| state | string | – | Two-letter state code, e.g. FL, NY, CA, TX. 56 jurisdictions covered. |
| type | string | – | Filter by entity type: domestic_profit, domestic_llc, domestic_lp, foreign_profit, domestic_nonprofit |
No output schema declared.
No examples provided.
private_stats ~84
Check what this dataset actually covers before relying on it. Returns per-state record counts AND the government source behind each state, which matters: some states are full business registries with officer records, while others (California, Illinois) hold only federal SAM.gov registrants with no officer data at all. Read this before asking who runs a company in a state you have not used before.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
private_type_breakdown ~53
Entity type breakdown — how many domestic profit corps, LLCs, LPs, nonprofits, foreign corps, etc. Optionally filter by state.
| Name | Type | Req | Description |
|---|---|---|---|
| state | string | – | Filter by state: FL, NY |
No output schema declared.
No examples provided.