GRC Platforms

Machine access

For AI agents

Machine-readable access to GRC Platforms. Prefer HTTP search when you do not need stdio MCP.

Catalog search API

GET https://grcplatforms.com/api/search?category=compliance-automation&q=soc2
GET https://grcplatforms.com/api/search?size=enterprise,public&limit=20
GET https://grcplatforms.com/api/search?deployment=SaaS&limit=100

Params: category, size (company size: startup, mid-market, enterprise, public; repeatable, comma-separable), deployment (SaaS, On-prem, Hybrid), q, limit (1-100, default 50). Category values are listed in /api/platforms.json.

Response fields: total (matches before limit), count (results returned this page), limit (applied cap), normalized, results. Prefer total for catalog size under a filter; unfiltered full size is also on the dump below.

Full dump

GET https://grcplatforms.com/api/platforms.json

Shape: count, categoryCount, categories, platforms (full public fields, alphabetical by name), dataAsOf (latest catalog date_added), lastUpdated (response date).

llms.txt

/llms.txt (index: categories, shortlists, machine endpoints, counts) and /llms-full.txt (full catalog text, same platform count as the JSON dump).

Human shortlists (alphabetical within category, not ranked): /best.

MCP server

npx -y @grcplatforms/mcp-server
# tools: search_platforms, get_platform, check_if_listed, list_categories, submit_listing

Source: mcp-server/ in the repo. After npm publish of @grcplatforms/mcp-server, npx works zero-install. Until then: node mcp-server/dist/index.js from a clone, or use HTTP POST /api/submit below.

Submit a listing

Humans: /submit. Agents (free review queue only):

POST https://grcplatforms.com/api/submit
Content-Type: application/json

{
  "name": "My GRC Platform",
  "url": "https://example.com",
  "brief_summary": "What the platform does (20+ chars).",
  "email": "you@example.com",
  "category": "compliance-automation"
}

Free tier queues up to ~90 days for review. MCP tool submit_listing calls the same API.