Skip to main content
ClaudeWave

EU AI Act runtime deny for AI agents. Python SDK, TrustLint, MCP.

MCP ServersRegistry oficial4 estrellas0 forks● PythonApache-2.0Actualizado today
ClaudeWave Trust Score
95/100
✓ Verified
Passed
  • ✓Open-source license (Apache-2.0)
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Topics declared
  • ✓Documented (README)
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: NPX · @complyedge/mcp
Claude Code CLI
claude mcp add complyedge -- npx -y @complyedge/mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "complyedge": {
      "command": "npx",
      "args": ["-y", "@complyedge/mcp"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Casos de uso

Resumen de MCP Servers

# ComplyEdge

[![PyPI](https://img.shields.io/pypi/v/complyedge)](https://pypi.org/project/complyedge/)
[![License: Apache 2.0](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](LICENSE)
[![Smithery](https://img.shields.io/badge/Smithery-listed-6b46c1)](https://smithery.ai/servers/complyedge/complyedge)

EU AI Act Article 5 and Article 50 runtime deny for AI agents. The platform enforces in production, on every request — and the same discipline is available to your agent as an **MCP server** that checks and scans the text you pass it, offline, with an article citation on every finding. Classifiers (`eu-ai-act-*`) score the *system*; ComplyEdge denies *this* prompt or output. Article 50 here is unlabeled or deceptive use, not C2PA.

Ships three ways: a Python SDK, an offline CI linter (TrustLint), and an **MCP server** — a Model Context Protocol server that exposes compliance checks as tools to any MCP host (Claude, Cursor, MCP Inspector).

**Article 5 is already law.** GPAI fines have applied since 2 August 2026. Your AI is either compliant right now, or it isn't.

> What does your compliance tool tell a regulator when it blocks a request? A probability score?
>
> ComplyEdge says: **Article 5(1)(a), rule `rego-art5-1a-001`, timestamp, input hash.** One is an audit trail. One is a guess.

## MCP Server (Model Context Protocol)

ComplyEdge TrustLint is an MCP server built on the official [MCP Python SDK](https://github.com/modelcontextprotocol/python-sdk) (`mcp>=1.9`). It gives an agent article-cited compliance checks instead of a probability score, and it runs fully offline: no API key, no network call, rules evaluated from the bundled YAML corpus.

**Tools** (the server exposes MCP tools only — no resources, no prompts; all are read-only and idempotent):

| Tool | What it does |
|---|---|
| `check_compliance` | Check text against the TrustLint rule corpus. Returns PASS/FAIL with rule ID, severity, and the article citation behind each finding. |
| `list_rules` | List available rules, filterable by jurisdiction (`EU`, `US`, `Global`, `Universal`). |
| `scan_prompt` | Pre-generation prompt scan. Returns `SAFE` or `RISK_DETECTED` before the model is called. |
| `sandbox_check` | Optional, with your API key: hosted enforcement in sandbox mode (`POST /v1/sandbox/check`). Your tenant's real rules and settings, the same verdict as production, and nothing recorded: no audit entry, no usage, no rate-limit count. Returns `BLOCKED`/`ALLOWED` with rule ID and article citation. Never evidence. |

**Local (stdio)** — for Claude Desktop, Cursor, MCP Inspector, or any MCP host:

```bash
pip install 'complyedge[mcp]'
complyedge-mcp          # or: python -m complyedge.mcp_server
```

```json
{
  "mcpServers": {
    "complyedge": {
      "command": "complyedge-mcp"
    }
  }
}
```

**Remote (Streamable HTTP):** `https://mcp.complyedge.io/mcp`

`sandbox_check` is the one tool that needs a key. Locally, set `COMPLYEDGE_API_KEY`
in the server's environment (without it the tool is not listed and the server stays
fully offline). On the hosted server it is always listed and works only for a caller
that sends its own key as the `Authorization: Bearer <key>` header on the MCP
connection; the key is never a tool argument, never logged, and the hosted server
keeps no keys.

```json
{
  "mcpServers": {
    "complyedge": {
      "url": "https://mcp.complyedge.io/mcp",
      "headers": { "Authorization": "Bearer ce_live_your_api_key" }
    }
  }
}
```

Server source: [`sdks/python/complyedge/mcp_server.py`](sdks/python/complyedge/mcp_server.py). Full MCP docs: [`sdks/python/README.md`](sdks/python/README.md). The three offline tools use the TrustLint engine and never call the hosted OPA/Rego policy API; `sandbox_check` is the one that does, and only with your key.

**Install (coding agents):**

```bash
pip install complyedge
pip install trustlint
pip install 'complyedge[mcp]'
npx -y @complyedge/mcp
claude mcp add complyedge -- npx -y @complyedge/mcp
```

Listing: [smithery.ai/servers/complyedge/complyedge](https://smithery.ai/servers/complyedge/complyedge)

Cursor one-click: [Install TrustLint MCP](cursor://anysphere.cursor-deeplink/mcp/install?name=ComplyEdge%20TrustLint%20EU%20AI%20Act&config=eyJ1cmwiOiAiaHR0cHM6Ly9tY3AuY29tcGx5ZWRnZS5pby9tY3AifQ)

OpenAI Agents extra (hosted path; needs `COMPLYEDGE_API_KEY`):

```bash
pip install 'complyedge[agents]'
```

```python
from complyedge.agents import create_compliance_guardrail
```

CI: `uses: complyedge/trustlint-action@v1`

GOPAL is an OPA library in your process. ComplyEdge is per-request deny + citation + AI Trust Center + MCP.

## Live enforcement seals

Not a static badge. These seals reflect live `/v1/check` traffic from open-source projects
embedding ComplyEdge: they change as real enforcement happens.

Both projects below are our own. ComplyEdge runs in production against our own code
before we ask anyone else to run it against theirs. You choose the region
when you create an account: EU (`https://eu.api.complyedge.io`, key prefix `ce_eu_`)
or US (`https://api.complyedge.io`, key prefix `ce_`). The seals below use the US
host because those accounts live in the US. The SDK reads the key and calls that
host. To move an existing account, use Request a region change in the dashboard.
Support moves the account and issues a new key.
Setting an API URL does not move the account.
The region is where your prompts and audit records are processed and stored.
It does not decide which laws are checked: the `jurisdiction` field on each
check does. No general law requires either region. US law does not require US
storage, and GDPR allows transfers outside the EU with safeguards such as
standard contractual clauses (Chapter V). Choose the region your own contracts
or customers ask for.

[![IVD Framework: runtime enforcement](https://api.complyedge.io/v1/public/badge/ivd.svg)](https://trust.complyedge.io/ivd)
[![Horizon: runtime enforcement](https://api.complyedge.io/v1/public/badge/horizon.svg)](https://trust.complyedge.io/horizon)

| Project | Live AI Trust Center |
|---------|-----------------|
| **IVD Framework** | [trust.complyedge.io/ivd](https://trust.complyedge.io/ivd) |
| **Horizon** | [trust.complyedge.io/horizon](https://trust.complyedge.io/horizon) |

Each AI Trust Center is generated from that project's real audit trail: enforcement status, check
volume, and the EU AI Act articles enforced at runtime. (GitHub proxies and caches images, so the
seal above can lag; the AI Trust Center is always current.)

Embed one on your own project: [Enforcement Seal docs](https://complyedge.io/docs/trust-badge.html).

## Quick Start

```bash
pip install complyedge
```

```python
from complyedge import compliance_check

@compliance_check(jurisdiction="EU", agent_id="my-agent")
def my_agent(prompt):
    return llm.generate(prompt)  # every input and output checked
```

Three lines. Every AI input and output evaluated against the EU AI Act rule corpus (Article 5, Article 50, GPAI). Violations blocked before they reach the user: with article citation, rule ID, and timestamp on every decision.

Set `COMPLYEDGE_API_KEY` to your key. The decorator activates by default; to disable without removing the key (e.g., in CI), set `COMPLYEDGE_ENABLED=false`.

## Without a decorator

```python
from complyedge import is_safe, check
import os

api_key = os.environ["COMPLYEDGE_API_KEY"]

# Boolean check: returns True if no violations
if not is_safe(prompt, api_key=api_key, jurisdiction="EU"):
    raise ValueError("Prompt violates EU AI Act")

# Full result: returns ComplianceResult with the violations that blocked it
result = check(prompt, api_key=api_key, jurisdiction="EU")
if not result.allowed:
    for v in result.violations:
        print(v.rule_id, v.severity, v.rule_description)
```

`rule_id` is the citation key: every rule carries its article reference in the corpus (`rego-art5-1c-001` → Article 5(1)(c)), and the full citation text ships with the rule under [`rules/`](rules).

`jurisdiction` is where the end user is, not where your company is based: the EU AI Act applies when an AI system's output is used in the EU, wherever the provider or deployer is established ([Art. 2(1)(c)](https://eur-lex.europa.eu/eli/reg/2024/1689)). Default: `EU`. On the hosted API's deterministic path, `EU` runs the EU AI Act rules, `US` and `US-*` run the SOX §302 disclosure rule, and every check runs prompt-injection detection. The other US rules (HIPAA, COPPA, TCPA, BIPA, CCPA, NYC LL144, ECPA) and the GDPR rules run offline in TrustLint, not on the hosted `/v1/check` path. The opt-in Layer 2 (`use_semantic_fallback=True`) adds two LLM judges: a prompt-injection classifier that judges by meaning against the same Article 15 categories and cites them, and a general LLM review. Neither runs the other rules.

## TrustLint, Offline Linter

No API key required. Scans text against the YAML rule corpus using regex patterns. Published as a standalone package, versioned independently of the SDK.

```bash
pip install trustlint

trustlint check --text "We use social credit scoring to evaluate applicants"
# → CRITICAL: EU_AI_ACT_ART5_SOCIAL_SCORING_001, Article 5(1)(c)
```

Exit codes: `0` = pass, `1` = violations found. Designed for CI/CD pipelines. Source: [`packages/trustlint/`](packages/trustlint).

## Rule IDs: two namespaces

ComplyEdge resolves the same regulations through two engines, each with its own rule-ID namespace:

- **Runtime API (OPA/Rego):** IDs like `rego-art5-1c-001`: returned by `compliance_check` and the `/v1/check` API. This is the audit trail your production system logs.
- **TrustLint (offline, YAML corpus):** IDs like `EU_AI_ACT_ART5_SOCIAL_SCORING_001`: emitted by the offline linter.

Both cite the same legal article and differ only in engine. Map between them via the article reference carried in every rule.

## What's In This Repo

```
sdks/python/          Python SDK (@compliance_check decorator, CLI)
  └ comply
ai-governancecomplianceeu-ai-actgdprmcpmcp-servermodel-context-protocolpythonregtechtrustlint

Lo que la gente pregunta sobre complyedge

¿Qué es ComplyEdge/complyedge?

+

ComplyEdge/complyedge es mcp servers para el ecosistema de Claude AI. EU AI Act runtime deny for AI agents. Python SDK, TrustLint, MCP. Tiene 4 estrellas en GitHub y su última actualización registrada es del 2026-10-02.

¿Cómo se instala complyedge?

+

Puedes instalar complyedge clonando el repositorio (https://github.com/ComplyEdge/complyedge) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar ComplyEdge/complyedge?

+

Nuestro agente de seguridad ha analizado ComplyEdge/complyedge y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene ComplyEdge/complyedge?

+

ComplyEdge/complyedge es mantenido por ComplyEdge. La última actividad registrada en GitHub es del 2026-10-02, con 0 issues abiertos.

¿Hay alternativas a complyedge?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega complyedge en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: ComplyEdge/complyedge
[![Featured on ClaudeWave](https://claudewave.com/api/badge/complyedge-complyedge)](https://claudewave.com/repo/complyedge-complyedge)
<a href="https://claudewave.com/repo/complyedge-complyedge"><img src="https://claudewave.com/api/badge/complyedge-complyedge" alt="Featured on ClaudeWave: ComplyEdge/complyedge" width="320" height="64" /></a>

Más MCP Servers

Alternativas a complyedge