Connectors / Compliance
Compliance MCP connectors for Claude, ChatGPT and Cursor
10+ Compliance connectors in the catalog, each behind the same governed MCP endpoint as everything else in Elaichi.
https://api.elaichi.ai/mcp
The same for every user.
-
Their own access. An agent never gets more than the person it acts for.
-
One connection, every client. Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent.
The connectors
Compliance connectors in the catalog
Connect one and your whole team reaches it, each inside the access they already have, without anyone handling a credential.
12 connectors
-
Alloy API key 138 tools
-
Cakewalk API key 25 tools
-
Comp AI API key 248 tools
-
ComplyCube API key 63 tools
-
Drata API key 165 tools
-
LawVu Hosted sign-in
-
Lumos API key 88 tools
-
OneTrust App credentials 622 tools
-
Secureframe API key 57 tools
-
Sprinto Hosted sign-in
-
Vanta App credentials 182 tools
-
Veeva Vault API key 3 tools
No Compliance connector by that name
It may sit under another category, or not be in the catalog yet — any documented API can become a connector.
In practice
What teams do with Compliance connectors
Drawn from the connector pages in this category, so every line describes something one of these connectors actually does.
Compliance
-
Assign and update AI review tasks
Create a OneTrust AI governance task for the owner of a system, then update its status and notes straight after the review call.
-
Find who still owes training before the audit
Ask which people in Comp AI have not finished their security training videos and get a list you can chase, without opening every profile.
-
Find every control still missing an owner
Ask which Vanta controls have no owner assigned, then set the right person on each one without opening every record by hand.
IT
-
Check who is in Drata and who is not
Compare the Drata personnel list against the new hires and leavers from last month so nobody is missing from onboarding checks or lingering after they left.
-
Answer who has access to what
Ask which accounts a person holds across every app in Lumos, or which people hold accounts in one app, without opening a single admin console.
-
Review devices and bring them into scope
See every laptop and workstation Secureframe is tracking, check which ones fall under a given framework, and put a new hire's machine in scope the same afternoon.
Security
-
Deactivate a leaver and remove group access
When someone leaves, deactivate their Cakewalk user and pull them out of the user groups that grant work apps, all in one conversation.
-
Catch failing controls the day they fail
Check which controls in Sprinto dropped out of compliance this week and who owns them, instead of waiting for the next review meeting.
-
Prepare for an audit in minutes
Pull the list of audit event types OneTrust tracks and the preference settings in place, so you know what evidence exists before the auditors ask.
Legal
-
Redact documents after a retention deadline
Redact ComplyCube documents and live photos for clients past your retention period, and remove the record entirely when a deletion request comes in.
-
Get the story on a matter before the meeting
Ask for a summary of a matter, its latest updates and its open tasks before you walk into the steering meeting. The answer comes from the live LawVu record, not from memory.
-
Check what is on record before a review
Search OneTrust for an AI governance entity by name and read back its details and links before the meeting, instead of clicking through the inventory yourself.
Once it is connected
Things to ask
Each of these is answered against the access the person asking already has, in the Compliance account you connected.
-
List open Alloy cases created this week by reviewer.
-
List Cakewalk users in the Finance group.
-
Which Comp AI organizations still have onboardings unfinished?
-
Show ComplyCube clients with a high risk profile
-
List open audit requests for our SOC 2 audit.
-
Summarize the open matters for the sales team this month
-
List Lumos apps added in the last 30 days.
-
Summarize AI governance entities created this quarter by type
The tools
What an agent can call in Compliance
- Connectors
- 10+
- Tools
- 1,591
- Hosted sign-in
- 2
in the Compliance catalog
callable the moment you connect
connect with nothing to register
Of those 1,591 tools, 8% delete something. Restricting an agent to reads is not a promise here, it is 680 tools admitted and the rest left out — and a restricted tool is never advertised to the model at all.
- Read 43%
- 680 tools · list, get, search
- Write 32%
- 511 tools · create, update, send
- Delete 8%
- 120 tools · delete, remove, archive
- Other 18%
- 280 tools · vendor-specific verbs
One endpoint
https://api.elaichi.ai/mcp
Every connector above answers here.
Every Compliance connector, by depth
Tool counts are what the connector exposes today; the split is what those tools do.
Hosted sign-in takes a partnership with each vendor, and more are in progress. Until one lands, Your own app means the connector works today — you register an OAuth app once and connect. API key and App credentials mean an admin pastes them once, with nothing to register.
| Connector | Tools | Read · write · delete | Sign-in |
|---|---|---|---|
| OneTrust | 622 | App credentials | |
| Comp AI | 248 | API key | |
| Vanta | 182 | App credentials | |
| Drata | 165 | API key | |
| Alloy | 138 | API key | |
| Lumos | 88 | API key | |
| ComplyCube | 63 | API key | |
| Secureframe | 57 | API key | |
| Cakewalk | 25 | API key | |
| Veeva Vault | 3 | API key | |
| LawVu | Hosted | ||
| Sprinto | Hosted |
FAQ
Frequently asked questions
How many Compliance connectors does Elaichi have?
10+ Compliance connectors are in the catalog today, and the list grows as connectors are added. Each one arrives as a set of MCP tools an agent can call through https://api.elaichi.ai/mcp.
Can Claude, ChatGPT and Cursor all use Compliance connectors?
Yes. Elaichi exposes one organization-wide endpoint, https://api.elaichi.ai/mcp, and Claude, ChatGPT, Cursor or any MCP client connects to that same address with OAuth, while the Elaichi Agent reaches the same tools inside the app. Connecting a Compliance account once makes it reachable from every one of them.
Do Compliance connectors work with Gemini, Codex, Claude Code or other MCP clients?
Yes. Compliance connectors are reached over the same MCP endpoint every client uses, so anything that speaks MCP can call them — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor and the Elaichi Agent. There is no per-client setup beyond pointing the client at https://api.elaichi.ai/mcp.
Do Compliance connectors need me to bring my own OAuth app?
No. 2 of the Compliance connectors use Elaichi's hosted sign-in, with nothing to register. 10 connect with an API key or app credentials that an admin pastes once, with no app to register. Nothing in this category asks you to register an OAuth app before you start.
Can I stop an agent from writing to Compliance tools?
Yes. Tool restrictions apply at role and individual level, and a restricted tool is left out of the model's tool list and cannot be called. Read-only access to a Compliance connector is a matter of allowing the reads and leaving the writes out.
Nearby
Teams that connect Compliance usually connect these too
Put Compliance connectors in front of your team
14 days on Gold, no credit card. Connect one and pick what each team can call.
- Works with
-
and any other MCP client, or the Elaichi Agent.
- When the trial ends
- Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.