DSGVO.pro — German Digital-Law Compliance
REMOTE · DSGVO.PRO · SCANNED AUG 20
Search 26 German/EU statutes free — then scan any website against 33 compliance modules.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability86
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 2082 tokens (~63/item across 33 items; 6 tools + 27 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities20
- Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28. See how to fix → Fail
Unverified: 1 category
A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · dsgvo.pro
claude mcp add --transport http pro-dsgvo-dsgvo-pro https://dsgvo.pro/api/mcp
[mcp_servers.pro-dsgvo-dsgvo-pro] url = "https://dsgvo.pro/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"pro-dsgvo-dsgvo-pro": {
"type": "remote",
"url": "https://dsgvo.pro/api/mcp",
"enabled": true
}
}
} openclaw mcp add pro-dsgvo-dsgvo-pro --url https://dsgvo.pro/api/mcp --transport streamable-http
mcp_servers:
pro-dsgvo-dsgvo-pro:
url: "https://dsgvo.pro/api/mcp" {
"mcpServers": {
"pro-dsgvo-dsgvo-pro": {
"type": "http",
"url": "https://dsgvo.pro/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Aug 26 63
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Aug 2026 · Probed https://dsgvo.pro/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=dsgvo.pro | CN=YR1,O=Let's Encrypt,C=US | 14 Aug 2026 | 12 Nov 2026 | RSA 2048 | SHA256-RSA | 635006bee9e9d24e9f132f2c3b844641943 |
| SANs: dsgvo.pro | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of dsgvo.pro. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| pro. | present | 42154 | 8 | Verified |
| dsgvo.pro. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://*.supabase.co; font-src 'self'; connect-src 'self' https://*.supabase.co wss://*.supabase.co https://api.trigger.dev wss://api.trigger.dev; frame-ancestors 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://dsgvo.pro/api/mcp | Verified | 200 | |
| http (plaintext) | http://dsgvo.pro/api/mcp | HTTPS enforced | 308 | https://dsgvo.pro/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
check-compliance ~455
🔑 Requires API key (Bearer header in MCP client config). Free tier: 3 scans/month — get a key at https://dsgvo.pro/api-keys. Start a compliance scan against up to 33 German digital law modules. Standard tier covers 20 modules across DSGVO, TDDDG, DDG, BFSG, UWG, BGB, PAngV including Schrems II hosting-location verification with SCC declaration audit, §312k BGB Kündigungsbutton, BFSG accessibility (active 28.06.2025). Pro/Agency tier (13 exclusive modules): §356a BGB Widerrufsbutton (active 19.06.2026 — currently the only EU compliance-scanner with this check), KI-VO transparency and data-processing requirements (Article 13/14 + Article 50 AI Act), advanced security audit (Art. 32 DSGVO — TLS protocol, mixed content, CMS-version CVE detection), tech-stack staleness (CMS/framework versions vs NVD CVE database), plus 8 industry-specific compliance modules — lawyer (BORA/BRAO), real-estate broker (§34c GewO + MaBV + §87 GEG energy-pass disclosure in listings), physician (BOÄ + HWG + Art. 9 GDPR sensitive-data), financial intermediary (§34d/f/h/i GewO + FinVermV), gastronomy (LMIV allergen labeling + PAngV + IfSG hygiene), cosmetics studio (KosmetikVO + HWG before/after imagery), construction (§34c GewO Bauträger-Erlaubnis + HwO + MiLoG/SOKA), hotel (BMG registration + PAngV tourist-tax inclusive pricing + GEG). Industry detection runs from page content — only triggers relevant checks. ⚠️ IMPORTANT: This tool returns only a scanId — NOT the results. The scan takes 60–120 seconds. After calling this, wait 60–90 seconds, then call get-scan-result with the scanId. Use get-scan-status to check progress without waiting for completion.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The website URL to scan (e.g. https://example.com) |
No output schema declared.
No examples provided.
get-article ~86
Get the full German text of a specific article or paragraph from a law. Returns full text and metadata.
| Name | Type | Req | Description |
|---|---|---|---|
| article | string|number | yes | The article or paragraph number. Letter suffixes are supported and required for norms like "356a" (§356a BGB Widerrufsbutton), "312k", "312j". |
| law | string | yes | The law identifier |
No output schema declared.
No examples provided.
get-scan-result ~102
Get the full compliance report for a completed scan. Returns score (0–100), financial risk in EUR, per-module results, and all violations with law references, fine estimates, and fix instructions. ⚠️ Only call after the scan is complete — check status first with get-scan-status. If called while scan is still running, returns current progress instead of an error.
| Name | Type | Req | Description |
|---|---|---|---|
| scanId | string | yes | The scan ID returned by check-compliance |
No output schema declared.
No examples provided.
get-scan-status ~302
Lightweight progress check for an in-progress compliance scan. Returns current status (pending/crawling/scanning/completed/failed) and how many modules have finished (20 Standard or up to 33 with Pro/Agency tier including Hosting-Standort (Schrems II) (Art. 13 lit. f DSGVO), Widerrufsbutton (§356a BGB), KI-Transparenz (Art. 50 KI-VO), Tech-Stack-Aktualität (Art. 32 DSGVO), Anwaltsspezifische Prüfung (BORA / BRAO), Maklerspezifische Prüfung (§34c GewO + MaBV + GEG), Arztspezifische Prüfung (BOÄ + HWG + Art. 9 DSGVO), Finanzvermittler-Prüfung (§34d/f/h/i GewO + FinVermV), Gastronomie-Prüfung (LMIV + PAngV + IfSG), Kosmetik-Prüfung (KosmetikVO + HWG + UWG), Bau-/Sanierung-Prüfung (§34c GewO + HwO + MiLoG), Hotel-/Beherbergung-Prüfung (BMG + PAngV + GEG + DSGVO)). Use this to poll progress. When status is 'completed', call get-scan-result for the full report.
| Name | Type | Req | Description |
|---|---|---|---|
| scanId | string | yes | The scan ID returned by check-compliance |
No output schema declared.
No examples provided.
list-laws ~23
List all available German/EU digital-law statutes with article/paragraph counts.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
search-law ~211
Search across all 26 German/EU statutes (DSGVO, KI-VO, BDSG, TDDDG, DDG, BFSG, UWG, BGB, PAngV, VSBG, UrhG, VerpackG, VerpackDG, ElektroG, JuSchG, GewO, MaBV, GEG, BRAO, FinVermV, HwO, IfSG, KosmetikVO, HWG, HOAI, MiLoG). Accepts paragraph references ("356a", "§ 312k", "Art. 42") for direct lookup AND free-text keywords ("Cookie", "Widerrufsbutton", "Einwilligung"). Returns matching articles/paragraphs with excerpts. Covers data protection, telecom & digital-services law, AI regulation, accessibility, unfair-competition (UWG), consumer and sector-specific law.
| Name | Type | Req | Description |
|---|---|---|---|
| law | string | – | Optional: limit search to a specific law |
| query | string | yes | Search query text |
No output schema declared.
No examples provided.