Prometiam Company Data
NPM · PROMETIAM-RISK-MCP · SCANNED OCT 4
Company data: Spain, France, UK, Ireland, Poland, Norway, Finland, Sweden, Croatia, Belgium, Denmark
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 93 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 3 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability62
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 10988 tokens (~313/item across 35 items; 35 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability check failed: the tool surface changed between 0.2.9 and 0.4.10: 4 tool removals, 0 breaking changes, 9 additions. See how to fix → Fail
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 98% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "sanctions_unwatch" implies "remove" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 36 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Prometiam Company Data MCP server?
Prometiam Company Data runs locally as an npm package, launched with npx -y prometiam-risk-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · prometiam-risk-mcp
claude mcp add matiasmaquieira96-risk-mcp -- npx -y prometiam-risk-mcp
{
"mcpServers": {
"matiasmaquieira96-risk-mcp": {
"command": "npx",
"args": [
"-y",
"prometiam-risk-mcp"
]
}
}
} {
"servers": {
"matiasmaquieira96-risk-mcp": {
"command": "npx",
"args": [
"-y",
"prometiam-risk-mcp"
]
}
}
} codex mcp add matiasmaquieira96-risk-mcp -- npx -y prometiam-risk-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"matiasmaquieira96-risk-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"prometiam-risk-mcp"
],
"enabled": true
}
}
} openclaw mcp add matiasmaquieira96-risk-mcp --command npx --arg -y --arg prometiam-risk-mcp
mcp_servers:
matiasmaquieira96-risk-mcp:
command: "npx"
args: ["-y", "prometiam-risk-mcp"] {
"McpServers": {
"matiasmaquieira96-risk-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"prometiam-risk-mcp"
]
}
}
} assistant mcp add matiasmaquieira96-risk-mcp -t stdio -c npx -a -y prometiam-risk-mcp
{
"mcpServers": {
"matiasmaquieira96-risk-mcp": {
"command": "npx",
"args": [
"-y",
"prometiam-risk-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77.
- 2 Oct 26 0
- Package version: 0.2.8 → 0.4.10 functional
- 1 Oct 26 +16
- Malware scan: unverified → pass ▲ security
- 30 Sept 26 −19
- Malware scan: pass → unverified ▼ security
- Schema quality: 183 → 313 ▼ functional
- Package version: 0.2.8 → 0.4.10 functional
- 28 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- Package version: 0.4.2 → 0.4.4 functional
- Package version: 0.4.2 → 0.4.3 functional
- 26 Sept 26 −3
- Stability: 0.87 → fail ▼ security
- Schema quality: 4973 → 5870 ▼ functional
- Destructive annotations: pass → 0 functional
- Package version: 0.2.9 → 0.4.2 functional
- 25 Sept 26 −2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 6 Oct 2026 · Analysed npm/prometiam-risk-mcp@0.4.12
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 93 packages
| Packages resolved | 93 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
account ~53
Returns the calling API key's account info and current usage: plan tier, rate limits (per minute / day / month), remaining quota, and enabled scopes. Use this to check "how much quota do I have left?".
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
companies_lookup ~203
Resolve up to 100 companies in ONE call (POST /companies/lookup). Each item needs country plus an identifier (company_number; aliases nif, siren, vat) or a name (best fuzzy match with match_score). Results come back in request order with status found / not_found / error / timeout and the same company object companies_search returns. Every item counts as one request against the plan limits; a batch that does not fit is refused with 429 batch_exceeds_quota and max_items_now. Optional idempotency_key: replaying the same key with the same items within 24h returns the original response for free (409 if still running, 422 if the items differ).
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Optional. Safe-replay key for this exact batch (1-255 printable ASCII); a repeat within 24h is free and returns the stored result. |
| items | array | yes | Up to 100 companies to resolve. |
No output schema declared.
No examples provided.
companies_search ~1,613
Search EU + UK companies in official registries by name or identifier. Returns companies with legal form, capital, status, registry coordinates, plus a cross-country status_canonical/stage and legal_form_canonical/abbreviation/family next to each register's own status/legal_form (null when the dictionary does not recognise the stored value — never a guess). Use country to scope the search to Spain (BORME), France (BODACC), the UK (Companies House), Ireland (CRO), Poland (KRS), Norway (Brønnøysundregistrene), Finland (Kaupparekisteri), Sweden (Bolagsverket), Croatia (Sudski registar), Belgium (KBO/BCE), or Denmark (CVR). Fuzzy name results carry a match_score (0–100) and are ranked by relevance, best first. NOTE: "dissolved" means different things by country — ES/FR still exists pending liquidation, GB/IE/PL/NO/FI no longer exists — read status_canonical, not status, to compare across countries.
| Name | Type | Req | Description |
|---|---|---|---|
| company_number | string | – | Registry identifier — exact match. Resolves per country: Spanish NIF/CIF (A78053147), French SIREN, UK Companies House number (00445790, SC123456), the IE/PL/NO registration number, for country FI a… |
| country | string | – | Country code: ES (Spain, BORME), FR (France, BODACC), GB (UK, Companies House), IE (Ireland, CRO), PL (Poland, KRS), NO (Norway, Brønnøysundregistrene / Enhetsregisteret), FI (Finland, Kaupparekister… |
| cursor | string | – | Pagination cursor — pass the previous response's pagination.next_cursor to fetch the next page. |
| has_risk_flag | boolean | – | Spain only. Return only companies carrying a published risk flag (currently the AEAT >€600,000 tax-debtor list). |
| limit | integer | – | Maximum number of results to return (1–100, default 20). |
| name | string | – | Company name — fuzzy normalized match. |
| nif | string | – | Spanish NIF/CIF — exact match, e.g. A78053147. Alias of company_number. |
| nip | string | – | Polish NIP (10 digits), exact match — use with country PL. The KRS number goes on company_number. |
| oib | string | – | Croatian OIB (11 digits), exact match — use with country HR. The ISO 7064 check digit is verified and a wrong one is a 400. The MBS goes on company_number. |
| regon | string | – | Polish REGON (9 or 14 digits), exact match — use with country PL. |
| risk_flag_type | string | – | Restrict to one flag type. registry_compliance also works for GB, IE and NO. |
| siren | string | – | French SIREN (9 digits), e.g. 552032534. |
| siret | string | – | French SIRET (14 digits). |
| status_canonical | string | – | Filter by the cross-country canonical status rather than each country's own vocabulary. Works for every live country, but outside ES it must be combined with a name/company_number/siren/siret/nip/reg… |
| vat | string | – | VAT / tax identifier — exact match. Alias of company_number. For country FI, the Finnish VAT number FI plus the eight digits of the Y-tunnus, e.g. FI01120389; for country SE, the Swedish VAT number S… |
No output schema declared.
No examples provided.
company_detail ~832
Fetch a single company by Prometiam internal ID. Returns full profile including officers, registry coordinates, founding date, capital, current status (with status_canonical/stage) and legal form (with legal_form_canonical/abbreviation/family). recent_events (ES/FR/GB) carries the same served event_type + raw act_type as events_search. Get an ID from companies_search first. Pass include to attach extra blocks — notably risk_flags (published tax-debt / debarment signals) and insolvency.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Country code: ES (Spain, BORME), FR (France, BODACC), GB (UK, Companies House), IE (Ireland, CRO), PL (Poland, KRS), NO (Norway, Brønnøysundregistrene / Enhetsregisteret), FI (Finland, Kaupparekister… |
| id | – | yes | Prometiam internal company ID (integer). |
| include | string | – | Comma-separated extra blocks: procurement, insolvency, lei, prospect, risk_flags — or all. risk_flags is Spain only and each row states whether its identifier was read directly from the source or rec… |
No output schema declared.
No examples provided.
coverage ~55
Returns dataset coverage statistics: per-country company count, event count, person count, latest filing date, and data sources. Use this when a user asks "what countries does Prometiam cover?" or "how fresh is the data?".
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
directors_network ~808
List directors/officers who sit on many companies (cross-directorship rollup), optionally filtered by name. Useful for spotting nominee directors and network hubs in due diligence. Currently Spain (ES) only; other countries return an empty set with a notice.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Country code: ES (Spain, BORME), FR (France, BODACC), GB (UK, Companies House), IE (Ireland, CRO), PL (Poland, KRS), NO (Norway, Brønnøysundregistrene / Enhetsregisteret), FI (Finland, Kaupparekister… |
| legal_entities | boolean | – | If true, include corporate directors (legal entities) instead of only natural persons. |
| limit | integer | – | Maximum results (1–200, default 50). |
| min_companies | integer | – | Only return people appointed to at least this many companies (2–100, default 5). |
| name | string | – | Director name filter — trigram match (min 3 characters). |
| offset | integer | – | Result offset for pagination. |
No output schema declared.
No examples provided.
event_detail ~58
Fetch a single corporate-event record by Prometiam internal ID, with its full before/after values and the source registry notice. Get an ID from events_search or events_timeline first.
| Name | Type | Req | Description |
|---|---|---|---|
| id | – | yes | Prometiam internal company-event ID. |
No output schema declared.
No examples provided.
events_search ~1,035
Search normalized corporate-event records (capital changes, director changes, dissolutions, mergers, insolvency, name changes, etc.) by company or date range, for Spain, France and the UK (from their gazettes) and, as register-change events, for Finland, Sweden, Belgium, Croatia and Denmark. Returns events with a served event_type matching this enum for each of those countries (each row also carries act_type, the raw BORME/BODACC/Companies House code it was derived from, or null when not yet covered), event date, before/after values, and source notice URL. The register-change events of the five (name, status, legal form and registered address; share capital for HR) are dated when the change first appears in the register data, are not gazette notices and start on 2026-09-30. Norway publishes no corporate-event gazette; Ireland and Poland are company-level (no event stream) — NO, IE and PL return an empty list.
| Name | Type | Req | Description |
|---|---|---|---|
| company_name | string | – | Company name — fuzzy match. |
| company_number | string | – | Registry registration number — exact match. |
| country | string | – | Country code: ES (Spain, BORME), FR (France, BODACC), GB (UK, Companies House), IE (Ireland, CRO), PL (Poland, KRS), NO (Norway, Brønnøysundregistrene / Enhetsregisteret), FI (Finland, Kaupparekister… |
| cursor | string | – | Pagination cursor — pass the previous response's pagination.next_cursor to fetch the next page. |
| date_from | string | – | Filter events on or after this date (YYYY-MM-DD). |
| date_to | string | – | Filter events on or before this date (YYYY-MM-DD). |
| event_type | string | – | One of dissolution, director_change, capital_change, new_incorporation, name_change, address_change, liquidation, merger, demerger, status_change, insolvency — or a raw register code kept as an alias… |
| limit | integer | – | Maximum number of results to return (1–100, default 20). |
No output schema declared.
No examples provided.
events_timeline ~747
Returns the event history for one company, newest first. Useful for building lifecycle timelines from incorporation through capital changes, director appointments, and dissolution. One of company_number or company_name is required.
| Name | Type | Req | Description |
|---|---|---|---|
| company_name | string | – | Company name — fuzzy match. |
| company_number | string | – | Registry number — exact match (recommended). |
| country | string | – | Country code: ES (Spain, BORME), FR (France, BODACC), GB (UK, Companies House), IE (Ireland, CRO), PL (Poland, KRS), NO (Norway, Brønnøysundregistrene / Enhetsregisteret), FI (Finland, Kaupparekister… |
| limit | integer | – | Maximum events to return (1–200, default 50). |
No output schema declared.
No examples provided.
insolvency_check ~218
Check up to 100 counterparties for CORPORATE insolvency notices in ONE call (POST /insolvency/check) across FR, DE, GB, AT, CH, NO, FI, US, NL, DK, HR and SE. Each item: country plus company_number (alias siren; exact, as printed on the notice) or name. Returns up to 5 notices per item, newest first, plus latest_filing_date; status found / none / error / timeout. "none" is not proof of solvency. Every item counts as one request. Optional idempotency_key: replaying the same key with the same items within 24h returns the original response for free (409 if still running, 422 if the items differ).
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Optional. Safe-replay key for this exact batch (1-255 printable ASCII); a repeat within 24h is free and returns the stored result. |
| items | array | yes | Up to 100 counterparties to check. |
No output schema declared.
No examples provided.
insolvency_notices_search ~446
Search CORPORATE insolvency notices published in official gazettes and registers across France, Germany, the UK, Austria, Switzerland, Norway, Finland, the US, the Netherlands, Denmark, Croatia and Sweden. Use this for distress coverage in markets where no company registry is held (DE, AT, CH, US, NL) — there the notices stand alone and are not linked to a company record. Norway, Finland, Denmark, Croatia and Sweden have registry coverage, so their notices can be cross-referenced against companies_search with the same country code (for FI, DK, HR and SE the notices are linked by business ID, CVR number, MBS and organisationsnummer: a company record with include=insolvency returns them). DK notices come from CVR credit information (konkurs and tvangsakkord decisions, dated by the decision, no court or case number); HR notices are court decisions from the Croatian court register (only companies still on the register); SE notices are Bolagsverket's procedure data (konkurs, företagsrekonstruktion, ackordsförhandling), updated weekly, with no court, case number or link, and proceedings that ended before collection are not included. Belgium is not an insolvency market. Personal/consumer insolvency is deliberately excluded and is never returned. Distinct from insolvency_search, which covers the linked ES/FR/GB risk-notice corpus.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Insolvency-coverage country. This is NOT the same set as the company-registry countries. |
| cursor | string | – | Pagination cursor — pass the previous response's pagination.next_cursor to fetch the next page. |
| date_from | string | – | Filing date on or after this date (YYYY-MM-DD). |
| date_to | string | – | Filing date on or before this date (YYYY-MM-DD). |
| event_type | string | – | Notice type, e.g. insolvency, dissolution, liquidation, forced_sale. |
| limit | integer | – | Maximum number of results to return (1–100, default 20). |
| name | string | – | Company name — matched anywhere in the normalized name (min 2 characters). |
No output schema declared.
No examples provided.
insolvency_record ~50
Fetch a single insolvency / risk notice by Prometiam internal ID, with related corporate events. Get an ID from insolvency_search.
| Name | Type | Req | Description |
|---|---|---|---|
| id | – | yes | Prometiam internal insolvency-record ID. |
No output schema declared.
No examples provided.
insolvency_search ~871
Search insolvency and risk notices (bankruptcies, liquidations, court judgments) by company name or identifier. Complements company registry data with distress signals. Scope with country and date range.
| Name | Type | Req | Description |
|---|---|---|---|
| company_number | string | – | UK Companies House number. |
| country | string | – | Country code: ES (Spain, BORME), FR (France, BODACC), GB (UK, Companies House), IE (Ireland, CRO), PL (Poland, KRS), NO (Norway, Brønnøysundregistrene / Enhetsregisteret), FI (Finland, Kaupparekister… |
| cursor | string | – | Pagination cursor — pass the previous response's pagination.next_cursor to fetch the next page. |
| date_from | string | – | On or after this date (YYYY-MM-DD). |
| date_to | string | – | On or before this date (YYYY-MM-DD). |
| event_type | string | – | Filter by notice/event type (e.g. insolvency, liquidation, judgment). |
| limit | integer | – | Maximum number of results to return (1–100, default 20). |
| name | string | – | Company name — fuzzy match. |
| siren | string | – | French SIREN (9 digits). |
| siret | string | – | French SIRET (14 digits). |
| vat | string | – | Spanish NIF/CIF — exact match. |
No output schema declared.
No examples provided.
lei_lookup ~105
Look up a Legal Entity Identifier (LEI) in the GLEIF global register by its 20-character ISO 17442 code. Returns legal name, jurisdiction, entity and registration status, legal/HQ address, managing LOU, and next renewal date. Use to validate or enrich a counterparty that publishes an LEI.
| Name | Type | Req | Description |
|---|---|---|---|
| lei | string | yes | 20-character alphanumeric LEI, e.g. HWUPKR0MPOU8FGXBT394. |
No output schema declared.
No examples provided.
lei_relationships ~115
GLEIF Level 2 corporate ownership ("who owns whom") for a 20-character LEI: its direct parent, ultimate parent, and direct children — each with LEI, legal name, jurisdiction, status, and city/country. Reveals the accountable ownership chain behind an entity. Only relationships reported to GLEIF are returned (many entities report none).
| Name | Type | Req | Description |
|---|---|---|---|
| lei | string | yes | 20-character alphanumeric LEI, e.g. 5493001KJTIIGC8Y1R12. |
No output schema declared.
No examples provided.
lei_search ~89
Search the GLEIF global LEI register by legal-entity name (full-text). Returns candidate LEIs with legal name, jurisdiction, status, and city/country — use to resolve a company name to its LEI before lei_lookup.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Maximum candidates to return (1–25, default 10). |
| name | string | yes | Legal entity name to search for. |
No output schema declared.
No examples provided.
monitor_get ~48
Get one monitored company by its monitor ID, including its alert history (events/status/sanctions matches detected since subscription).
| Name | Type | Req | Description |
|---|---|---|---|
| id | – | yes | Monitor subscription ID (from monitor_subscribe or monitor_list). |
No output schema declared.
No examples provided.
monitor_list ~78
List the companies currently subscribed to ongoing monitoring for this API key, with their labels and last-alert timestamps. Company monitoring (ES, IE, PL, FI, SE, BE, HR, DK) emits status changes, dissolutions, sanctions matches and, for ES and FI/SE/BE/HR/DK, corporate events to a webhook.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
monitor_stop ~40
Stop monitoring a company and delete its subscription by monitor ID. This is irreversible — the alert history is removed.
| Name | Type | Req | Description |
|---|---|---|---|
| id | – | yes | Monitor subscription ID to delete. |
No output schema declared.
No examples provided.
monitor_subscribe ~231
Subscribe a company to ongoing monitoring. Status changes, dissolutions, sanctions matches and corporate events (ES and FI/SE/BE/HR/DK) are scanned daily and POSTed to your webhook_url (HMAC-SHA256 signed). Returns the monitor ID and a webhook_secret (shown once). Available for Spain (ES), Ireland (IE), Poland (PL), Finland (FI), Sweden (SE), Belgium (BE), Croatia (HR) and Denmark (DK) only. This creates a persistent subscription — confirm intent before calling.
| Name | Type | Req | Description |
|---|---|---|---|
| company_id | – | yes | Prometiam internal company ID to monitor (from companies_search / company_detail). |
| country | string | – | Country of the company to monitor: ES (default), IE, PL, FI, SE, BE, HR or DK. Monitoring is not available for FR, GB or NO. |
| events | array | – | Optional list of event types to filter alerts to (default: all). |
| label | string | – | Optional human-friendly label for this subscription. |
| webhook_url | string | yes | HTTPS URL that receives signed alert POSTs. |
No output schema declared.
No examples provided.
notice_detail ~67
Fetch a registry gazette notice (PDF edition) by Prometiam internal ID. Returns edition metadata, parse status, the PDF URL, SHA-256 hash, and raw extracted text. Each Spanish BORME edition is one notice.
| Name | Type | Req | Description |
|---|---|---|---|
| id | – | yes | Prometiam internal notice ID. |
No output schema declared.
No examples provided.
people_search ~807
Search officers / directors / shareholders by name across EU + UK registries. Returns matching people with their appointment counts, ranked by a fuzzy-match match_score (0–100), best first. Use person_detail for a full appointment history. Scope with country — officer-level data is held for Spain, France, the UK and Norway; Ireland, Poland, Finland, Sweden, Croatia, Belgium and Denmark are company-level only.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Country code: ES (Spain, BORME), FR (France, BODACC), GB (UK, Companies House), IE (Ireland, CRO), PL (Poland, KRS), NO (Norway, Brønnøysundregistrene / Enhetsregisteret), FI (Finland, Kaupparekister… |
| cursor | string | – | Pagination cursor — pass the previous response's pagination.next_cursor to fetch the next page. |
| limit | integer | – | Maximum number of results to return (1–100, default 20). |
| name | string | yes | Person name — normalized pattern match (min 2 characters). |
No output schema declared.
No examples provided.
person_detail ~71
Fetch a single person (officer / director) by Prometiam internal ID. Returns the person's full appointment history across all companies. Useful for director-network analysis and counterparty due diligence. Get the ID from a company_detail or people_search response.
| Name | Type | Req | Description |
|---|---|---|---|
| id | – | yes | Prometiam internal person ID (integer). |
No output schema declared.
No examples provided.
procurement_awards ~466
List public-contract awards by supplier, buyer, supplier tax id, CPV code and date, newest first. Spain (PLACSP, including minor contracts), France (DECP), the United Kingdom (Contracts Finder, Find a Tender) and Ireland, Poland and Norway (TED, above the EU thresholds only); pass country to restrict, omit it for all countries. One row per award to one supplier: amount_eur is that supplier's share as published, before VAT where the source distinguishes; amount_contract_eur is the whole contract; amount_is_ceiling marks a framework or dynamic-purchasing ceiling that is not spend; amount_suspect marks a form default rather than a price. bids_received is the competition signal where the source publishes it. company_id is set when the supplier resolves to a company record in that country (use company_detail on it). Natural-person suppliers are never returned. Requires at least one of company_id, nif, supplier, buyer, cpv or date_from.
| Name | Type | Req | Description |
|---|---|---|---|
| buyer | string | – | Contracting body name, matched anywhere (min 3 characters), e.g. "Ayuntamiento de Madrid". |
| company_id | – | – | Prometiam company id of the supplier (from companies_search). |
| country | string | – | Restrict to one country; omit for all countries. |
| cpv | string | – | CPV code or prefix, 2-8 digits (45 = construction works). |
| cursor | string | – | Pagination cursor — pass the previous response's pagination.next_cursor to fetch the next page. |
| date_from | string | – | Award date on or after (YYYY-MM-DD). |
| date_to | string | – | Award date on or before (YYYY-MM-DD). |
| limit | integer | – | Maximum number of results to return (1–100, default 20). |
| min_amount | number | – | Minimum awarded amount in EUR. |
| nif | string | – | Supplier identifier as published, exact match: NIF/CIF (Spain), SIRET (France), Companies House number (United Kingdom), CRO number (Ireland), NIP or KRS (Poland), organisasjonsnummer (Norway); suppl… |
| supplier | string | – | Supplier name, matched anywhere (min 3 characters). |
No output schema declared.
No examples provided.
procurement_buyer ~211
Risk profile of a PUBLIC BUYER (a contracting body) in Spain or France — BETA. Two calibrated scores about the buyer, never about a supplier or a tender: competition = probability that its next award receives a single bid; counterparty = probability that a supplier it awards to enters insolvency within 24 months (weak signal). Each carries score 1-10 (log-odds ladder, 1 = 1st percentile of the country's buyers, 10 = 99th), probability, base_rate, relative_risk, percentile of the residual, observed/expected rates, awards_scored, confidence; plus behaviour ratios, up to three evidence awards and the five largest supplier relationships. Find the id with procurement_buyers. A score is a prompt to look, not a finding of wrongdoing.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Defaults to ES. |
| id | string | yes | National identifier of the contracting body: DIR3 code or NIF (Spain), SIRET (France). |
No output schema declared.
No examples provided.
procurement_buyers ~204
List scored public buyers (contracting bodies) in Spain or France ordered by one buyer score, highest first — BETA. Use it to screen a portfolio (min_score), to see a region, or to find a buyer's identifier by name before calling procurement_buyer. Rows carry the buyer, its coverage and both risk blocks (score 1-10, probability, base_rate, relative_risk).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Defaults to ES. |
| cursor | string | – | Pagination cursor — pass the previous response's pagination.next_cursor to fetch the next page. |
| limit | integer | – | Maximum number of results to return (1–100, default 20). |
| min_score | integer | – | Keep buyers at or above this score. |
| model | string | – | Which score orders the list (default competition). |
| name | string | – | Buyer name, matched anywhere (min 3 characters). |
| region | string | – | Region name, matched anywhere. |
No output schema declared.
No examples provided.
procurement_relationship ~159
How dependent a public buyer and one of its five largest suppliers are on each other (Spain or France, BETA): awards, awarded value, the supplier's share of the buyer's awarded value, first/last award, single-bid awards, average bids, and the supplier's insolvency date when it failed. Only the five largest relationships per buyer are held; a supplier outside them returns 404 — use procurement_awards for its full award list (Spain).
| Name | Type | Req | Description |
|---|---|---|---|
| buyer | string | yes | National identifier of the contracting body (DIR3/NIF for Spain, SIRET for France). |
| country | string | – | Defaults to ES. |
| supplier | string | yes | Supplier tax id (NIF for Spain, SIREN for France). |
No output schema declared.
No examples provided.
sanctions_changes ~136
List additions, removals and amendments detected on the sanctions lists, newest first. Use this to answer "what changed recently" without re-screening a whole book of business — each change carries the entity it affects, so a hit can be joined back to sanctions_entity.
| Name | Type | Req | Description |
|---|---|---|---|
| change_type | string | – | Restrict to one kind of change. |
| limit | integer | – | Maximum changes to return (1–100, default 20). |
| list | string | – | Comma-separated source lists, e.g. "EU,OFAC". |
| since | string | – | ISO date (YYYY-MM-DD). Only changes detected after it. |
No output schema declared.
No examples provided.
sanctions_entity ~60
Fetch full detail for a single sanctions entity by Prometiam internal ID: all aliases, the issuing programme/list, listing date, and identifying data. Get an ID from a sanctions_screen match.
| Name | Type | Req | Description |
|---|---|---|---|
| id | – | yes | Prometiam internal sanctions-entity ID. |
No output schema declared.
No examples provided.
sanctions_screen ~347
Screen a person or entity name against 44,000+ active sanctions and export-control designations with trigram fuzzy match. Covers five sanctions lists — EU consolidated, UN, OFAC, UK OFSI, and the French Registre des gels — plus 11 US export-control lists (BIS Entity List, Denied Persons, Unverified, Military End User; State ITAR-Debarred and Nonproliferation; OFAC SSI, CMIC, MBS, PLC, CAPTA). Refreshed daily. Returns matches with confidence score (0–100), source list, and aliases. Use threshold to control match strictness.
| Name | Type | Req | Description |
|---|---|---|---|
| entity_type | string | – | Restrict to one entity type. Omit to screen all types. |
| include_pep | boolean | – | Also screen against politically exposed persons (BETA, Spain only, from Wikidata) and return a separate pep block. Membership is by OCCUPATION, not office: 44% of the set has no recorded office and l… |
| limit | integer | – | – |
| name | string | yes | Name to screen. |
| pep_min_tier | string | – | Only return PEP hits at or above this tier. Omit to receive every hit, including those with no recorded office. |
| threshold | integer | – | Minimum match-confidence percentage (50–100, default 80). |
No output schema declared.
No examples provided.
sanctions_screen_batch ~278
Screen up to 50 names against the sanctions lists in ONE call (POST /sanctions/screen). Requires the sanctions scope (batch calls do not use the free trial allowance); every item counts as one request. Per-item status: match / clear / error / timeout. "clear" means no hit at or above the threshold on the active lists, not a certification. Optional idempotency_key: replaying the same key with the same items within 24h returns the original response for free (409 if still running, 422 if the items differ).
| Name | Type | Req | Description |
|---|---|---|---|
| active_only | boolean | – | Only currently listed entries (default true). |
| group | string | – | entity: one row per listed person/company with lists[] and sources[] instead of one row per source list. |
| idempotency_key | string | – | Optional. Safe-replay key for this exact batch (1-255 printable ASCII); a repeat within 24h is free and returns the stored result. |
| limit | integer | – | Hits returned per name (default 10). |
| list | string | – | Comma-separated source lists to restrict to, e.g. OFAC,EU,UN. |
| names | array | yes | Names to screen (people, companies, vessels). |
| threshold | integer | – | Minimum similarity 30-100 (default 80). |
No output schema declared.
No examples provided.
sanctions_unwatch ~36
Remove one of your sanctions watchlist entries by id (from sanctions_watchlist).
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Watchlist entry id. |
No output schema declared.
No examples provided.
sanctions_watch ~86
Add a name to your sanctions watchlist (sanctions_watch scope, Starter and above): the API re-screens it against every list update and reports new hits on sanctions_watchlist, or calls webhook_url when set.
| Name | Type | Req | Description |
|---|---|---|---|
| entity_type | string | – | – |
| name | string | yes | Name to watch. |
| webhook_url | string | – | https URL called when a new hit appears. |
No output schema declared.
No examples provided.
sanctions_watchlist ~50
Return your sanctions watchlists and any recent hits against them. Requires the sanctions_watch scope; the number of entries allowed depends on your tier. Add entries with sanctions_watch and remove them with sanctions_unwatch.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
vat_validate ~129
Validate an EU VAT number against VIES (the European Commission's VAT Information Exchange System) and return the registered trader name and address when valid. Covers the 27 EU member states plus XI (Northern Ireland); Greek numbers use the EL prefix and GB VAT is out of scope post-Brexit. Live official check — returns a retryable error when a member-state registry is temporarily down (not a false "invalid").
| Name | Type | Req | Description |
|---|---|---|---|
| vat | string | yes | Full VAT number including the 2-letter country prefix, e.g. IE6388047V or DE811569869. Spaces and punctuation are ignored. |
No output schema declared.
No examples provided.
What is the Prometiam Company Data MCP server?
Prometiam Company Data is an MCP server listed in the public MCP registry as io.github.matiasmaquieira96/risk-mcp. Company data: Spain, France, UK, Ireland, Poland, Norway, Finland, Sweden, Croatia, Belgium, Denmark. This page covers its npm package (prometiam-risk-mcp).
Is the Prometiam Company Data MCP server safe to use?
Prometiam Company Data scores 77 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Prometiam Company Data MCP server expose?
Prometiam Company Data exposes 35 tools: companies_search, company_detail, events_search, events_timeline, event_detail, and 30 more. Their descriptions and schemas cost roughly 10,802 tokens of context every time the server is loaded.
Is the Prometiam Company Data MCP server still maintained?
Prometiam Company Data is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Prometiam Company Data MCP server under?
Prometiam Company Data declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.