Pod

Available as Markdown and JSON. Pod is also available over MCP.

MCP Servers with a list_policies tool

Every MCP server Pod knows of that exposes a list_policies tool.

9 servers, ordered by decision readiness and adoption — GitHub stars and npm downloads where available, then reported issue volume. Pod has connected to 9 of them; the rest are publisher-reported and unverified.

Brandefense MCP

Brandefense connects Claude to the Brandefense external threat intelligence platform, so you can investigate and respond to external cyber risks without leaving the conversation.

What you can do:

How access works: Sign in with your existing Brandefense account. Claude can only see and do what your account already can: Brandefense checks your role, team, modules, and licenses on every request. MSSP users keep access to the customer organizations they already manage. Access to AI assistant connections is controlled in your organization's Brandefense settings, and you can disconnect Claude at any time.

Some tools change data or take external action, such as status changes, user management, credit-spending searches and scans, and takedown requests. These tools are annotated as write actions.

Requires an active Brandefense subscription.

128 tools reported — Live, but requires authorization before it will list tools. Publisher lists 128 tools.

Chariot

Manage your nonprofit's gift processing directly from Claude. Connect your Chariot account to look up, create, and reconcile donations, process checks received by mail, and edit donation details. Manage the custom properties and policies that automate your donation pipeline, read deposits, ledger transactions, and invoices, and export your data for reporting. Built for nonprofits and their finance teams, Chariot brings your entire donation workflow—records, deposits, reconciliation, and reporting—into your conversation, with secure OAuth access scoped to exactly the data and actions you authorize.

65 tools reported — Live, but requires authorization before it will list tools. Publisher lists 65 tools.

Firezone

Unleash the full power of the Firezone REST API using Claude!

All REST API operations are available, empowering you to:

  1. Create Actors, Groups, Resources, and Policies to manage secure access
  2. View audit logs to drill down into who accessed what and when
  3. Troubleshoot configuration and access issues quickly

89 tools reported — Live, but requires authorization before it will list tools. Publisher lists 89 tools.

Kastra

Kastra is an AI authorization platform that evaluates your AI agents’ actions against your policies and maintains a tamper-evident audit trail. This connector gives Claude read-only access to your Kastra account, allowing you to ask questions about your governance posture in plain language instead of navigating the console.

After you authorize the connector through a Kastra OAuth consent screen and select an environment, Claude can read—but never modify—the following:

• Decisions and their outcomes (allow, deny, and hold) • Policies, environments, and per-rule statistics • Incidents and HOLD approval checkpoints • Audit-chain verification results and governance audit logs • Activity statistics and trends • Onboarding governance preferences and masked API key metadata

Access is limited to your tenant and the specific environment you select during authorization. The connector cannot write data, modify settings, access other tenants, or expose raw prompt content or plaintext API keys. You can revoke access at any time through your connector settings.

13 tools reported — Live, but requires authorization before it will list tools. Publisher lists 13 tools.

KEY ESG (Private Equity)

KEY ESG gives sustainability teams instant access to their ESG data through natural language queries. Ask questions about your emissions, energy, water, waste, and social metrics without navigating dashboards or running reports manually. Retrieve progress against targets, review action plans, check uploaded policies, and generate board-ready ESG narratives, all from within your workflow. Designed for sustainability managers and their teams, KEY ESG makes ESG data faster to access, easier to interpret, and simpler to act on.

21 tools reported — Live, but requires authorization before it will list tools. Publisher lists 21 tools.

KEY ESG (Standalone)

KEY ESG gives sustainability teams instant access to their ESG data through natural language queries. Ask questions about your emissions, energy, water, waste, and social metrics without navigating dashboards or running reports manually. Retrieve progress against targets, review action plans, check uploaded policies, and generate board-ready ESG narratives, all from within your workflow. Designed for sustainability managers and their teams, KEY ESG makes ESG data faster to access, easier to interpret, and simpler to act on.

14 tools reported — Live, but requires authorization before it will list tools. Publisher lists 14 tools.

mcp.secureframe.com

MCP server for Secureframe

112 tools reported — Live, but requires authorization before it will list tools. Publisher lists 112 tools.

mcp.xfa.tech

XFA is a device-trust platform for BYOD. It verifies each device's security at every login — OS version and patch status, disk encryption, antivirus, firewall, screen lock, and more — so only healthy devices reach your applications, with no MDM and without managing the device.

This connector lets your AI assistant reach your own XFA organization. After you sign in with your XFA account, you can ask in plain language and get answers straight from XFA: - Your organization, and your own user and role - Devices and their security posture (those active in the last 30 days), including which are non-compliant, out of date, or missing a control - A compliance summary: verified vs unverified devices, compliant vs not, users without a verified device, and exposure to ransomware / phishing / data-breach vulnerabilities - Posture trends over time - Your policies - Software version and vulnerability (CVE) data for the titles XFA tracks (browsers, operating systems, PDF readers, Slack, the XFA app, mobile)

Learn more at https://xfa.tech.

0 GitHub stars · 11 tools reported — Live, but requires authorization before it will list tools. Publisher lists 11 tools.

Norrsent - Agentic Risk Management & GRC

Norrsent MCP connects Claude to your enterprise risk management (ERM) and GRC workspace on Norrsent. Query and analyze your risk register, controls and their effectiveness, Key Risk Indicators (KRIs), mitigations, active threats, governance policies, incidents, your organizational hierarchy, and the aggregated risk matrix and update a risk or report an incident that are all bounded by your own role-based permissions and recorded in an access audit log.

16 tools reported — Live, but requires authorization before it will list tools. Publisher lists 16 tools.

For agents

This page has a Markdown and a JSON twin. Pod is also queryable over MCP at https://api.askpod.ai/mcp/read.