# Compliance MCP connectors for Claude, ChatGPT and Cursor

10+ Compliance connectors in the Elaichi catalog, each callable through https://api.elaichi.ai/mcp once connected, under the same roles, restrictions and audit log as the rest of the catalog.

Source: https://elaichi.ai/connectors/category/compliance/

| | |
| --- | --- |
| Category | Compliance |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |

## Compliance connectors

- [Alloy](https://elaichi.ai/connectors/alloy/) — 138 tools · hosted sign-in
- [Cakewalk](https://elaichi.ai/connectors/cakewalk/) — 25 tools · hosted sign-in
- [Comp AI](https://elaichi.ai/connectors/compai/) — 248 tools · hosted sign-in
- [ComplyCube](https://elaichi.ai/connectors/complycube/) — 63 tools · hosted sign-in
- [Drata](https://elaichi.ai/connectors/drata/) — 165 tools · hosted sign-in
- [Lumos](https://elaichi.ai/connectors/lumos/) — 88 tools · hosted sign-in
- [OneTrust](https://elaichi.ai/connectors/onetrust/) — 622 tools · hosted sign-in
- [Secureframe](https://elaichi.ai/connectors/secureframe/) — 57 tools · hosted sign-in
- [Sprinto](https://elaichi.ai/connectors/sprinto/) — 5 tools · hosted sign-in
- [Vanta](https://elaichi.ai/connectors/vanta/) — 182 tools · hosted sign-in
- [Veeva Vault](https://elaichi.ai/connectors/veevavault/) — 1 tools · hosted sign-in

## What teams do with Compliance connectors

### Compliance

- **Assign and update AI review tasks** (OneTrust) — Create a OneTrust AI governance task for the owner of a system, then update its status and notes straight after the review call.
- **Find who still owes training before the audit** (Comp AI) — Ask which people in Comp AI have not finished their security training videos and get a list you can chase, without opening every profile.
- **Find every control still missing an owner** (Vanta) — Ask which Vanta controls have no owner assigned, then set the right person on each one without opening every record by hand.

### IT

- **Check who is in Drata and who is not** (Drata) — Compare the Drata personnel list against the new hires and leavers from last month so nobody is missing from onboarding checks or lingering after they left.
- **Answer who has access to what** (Lumos) — Ask which accounts a person holds across every app in Lumos, or which people hold accounts in one app, without opening a single admin console.
- **Review devices and bring them into scope** (Secureframe) — See every laptop and workstation Secureframe is tracking, check which ones fall under a given framework, and put a new hire's machine in scope the same afternoon.

### Security

- **Deactivate a leaver and remove group access** (Cakewalk) — When someone leaves, deactivate their Cakewalk user and pull them out of the user groups that grant work apps, all in one conversation.
- **Attach evidence the moment work is done** (Sprinto) — After a review or a fix is finished, add the evidence to the right Sprinto workflow check while it is still fresh, instead of leaving it for the week before the audit.
- **Prepare for an audit in minutes** (OneTrust) — Pull the list of audit event types OneTrust tracks and the preference settings in place, so you know what evidence exists before the auditors ask.

### People

- **Add new hires in one go** (Comp AI) — Give the agent the names and emails from this week's start list and it creates them as people in Comp AI in bulk, then resends portal invites to anyone who has not accepted.
- **Kick off background checks on day one** (Drata) — When a new hire is added, start their background check in Drata straight away instead of waiting for someone to remember the compliance step.
- **Set up a new hire's apps on day one** (Cakewalk) — Add the new starter to the right Cakewalk user group and grant the group's default work apps in one go instead of app by app.

## Things to ask once it is connected

- "List open Alloy cases created this week by reviewer." (Alloy)
- "List Cakewalk users in the Finance group." (Cakewalk)
- "Which Comp AI organizations still have onboardings unfinished?" (Comp AI)
- "Show ComplyCube clients with a high risk profile" (ComplyCube)
- "List open audit requests for our SOC 2 audit." (Drata)
- "List Lumos apps added in the last 30 days." (Lumos)
- "Summarize AI governance entities created this quarter by type" (OneTrust)
- "List all Secureframe repositories missing a framework asset scope." (Secureframe)

## What an agent can call in Compliance

1594 tools across the category. 11 of these connectors use hosted sign-in with nothing to register first; 0 ask you to bring your own OAuth app.

## Frequently asked questions

### How many Compliance connectors does Elaichi have?

10+ Compliance connectors are in the catalog today, and the list grows as connectors are added. Each one arrives as a set of MCP tools an agent can call through https://api.elaichi.ai/mcp.

### Can Claude, ChatGPT and Cursor all use Compliance connectors?

Yes. Elaichi exposes one organization-wide endpoint, https://api.elaichi.ai/mcp, and Claude, ChatGPT, Cursor, any MCP client and the Elaichi Agent all connect to that same address with OAuth. Connecting a Compliance account once makes it reachable from every one of them.

### Do Compliance connectors work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Compliance connectors are reached over the same MCP endpoint every client uses, so anything that speaks MCP can call them — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor and the Elaichi Agent. There is no per-client setup beyond pointing the client at https://api.elaichi.ai/mcp.

### Do Compliance connectors need me to bring my own OAuth app?

No. Every Compliance connector in the catalog connects through Elaichi's hosted sign-in, so there is nothing to register before you start.

### Can I stop an agent from writing to Compliance tools?

Yes. Tool restrictions apply at role and individual level, and a restricted tool is never advertised to the model, so it cannot be called or guessed at from the tool list. Read-only access to a Compliance connector is a matter of allowing the reads and leaving the writes out.

### Whose access does an agent get on a shared Compliance connection?

The access of the person the agent is acting for, resolved against their current role on every call — not the access of whoever connected the account. A colleague can use a connection without ever seeing its credential.

## Related categories

- [Security](https://elaichi.ai/connectors/category/security/)
- [HRIS](https://elaichi.ai/connectors/category/hris/)
- [ATS](https://elaichi.ai/connectors/category/ats/)

[Browse the full connector catalog](https://elaichi.ai/connectors/)
