GRC Platforms

Machine access

For AI agents

Machine-readable access to GRC Platforms. Prefer HTTP search when you do not need stdio MCP.

This page is the developer portal. /docs and /developers alias it.

OpenAPI

Machine-readable spec for the public catalog, including /api/v1/search: /openapi.json. Search and dump only. No auth.

Catalog search API

GET https://grcplatforms.com/api/v1/search?category=compliance-automation&q=soc2
GET https://grcplatforms.com/api/v1/search?size=enterprise,public&limit=20
GET https://grcplatforms.com/api/search?deployment=SaaS&limit=100

Prefer /api/v1/search. Unversioned /api/search is the same handler.

Params: category, size (company size: startup, mid-market, enterprise, public; repeatable, comma-separable), deployment (SaaS, On-prem, Hybrid), q, limit (default 50; if present, must be an integer from 1 to 100, else HTTP 400 JSON). Category values are listed in /api/platforms.json.

Response fields: total (matches before limit), count (results returned this page), limit (applied cap), normalized, results. Prefer total for catalog size under a filter; unfiltered full size is also on the dump below.

Full dump

GET https://grcplatforms.com/api/v1/platforms.json
GET https://grcplatforms.com/api/platforms.json

Shape: count, categoryCount, categories, platforms (full public fields, alphabetical by name), dataAsOf (latest catalog date_added), lastUpdated (response date).

llms.txt

/llms.txt (index: categories, shortlists, machine endpoints, counts) and /llms-full.txt (full catalog text, same platform count as the JSON dump).

Human shortlists (alphabetical within category, not ranked): /best.

MCP server (stdio)

Zero-install is HTTP (above and below). The stdio MCP server is optional and runs from a clone today:

# from a clone of the repo:
node mcp-server/dist/index.js
# tools: search_platforms, get_platform, check_if_listed, list_categories, submit_listing

Source: mcp-server/ in the repo. The npm package @grcplatforms/mcp-server is not published yet, so npx -y @grcplatforms/mcp-server does not work. Until it is published, run from a clone as above, or just use HTTP POST /api/submit below (no install).

Submit a listing

Humans: /submit. Agents (free review queue only):

POST https://grcplatforms.com/api/submit
Content-Type: application/json

{
  "name": "My GRC Platform",
  "url": "https://example.com",
  "brief_summary": "What the platform does (20+ chars).",
  "email": "you@example.com",
  "category": "compliance-automation"
}

Free tier queues up to ~90 days for review. MCP tool submit_listing calls the same API.