Server definition
- Hash
- sha256:15e8c0d42adcbf9cdd3303e06444c859c5a42086f812e1f5a5036ee372a10da4
- What it is
- What a remote MCP server returned when asked what it offers: 9 tools
The blob, as servednamed by its sha256
{
"instructions": "Incident-reporting deadlines over MCP (CRA, NIS2, DORA, GDPR, HIPAA, SEC 8-K). Free: list_regimes, explain_rule, classify_event, compute_deadlines, deadline_status, holiday_calendar. Premium (license): compute_deadlines_multi, validate_report, timeline_export. Cited arithmetic; not legal advice.",
"tools": [
{
"description": "Apply a regime's statutory criteria to yes/no facts and name the event type. FREE.\n\nTypical input {\"regime\": \"eu_dora\", \"facts\": {\"critical_services_affected\":\ntrue, \"duration_or_downtime\": true, \"geographic_spread\": true}} returns\n{\"reportable\": true, \"event_type\": \"major_ict_incident\", \"reasoning\":\n[...], \"criteria\": {...}}. Unanswered questions are listed under \"missing\"\nso the caller can go and find out. Use when deciding whether an incident\ntriggers a regime at all. Not for judging severity in the abstract: it\nonly applies the written criteria to the facts given. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"} (for example {\"error\": \"facts must be an object of question id -> answer\"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"facts": {
"additionalProperties": true,
"description": "answers keyed by the question ids returned for the regime (booleans; integers for counts).",
"type": "object"
},
"regime": {
"description": "regime id from list_regimes.",
"type": "string"
}
},
"required": [
"regime",
"facts"
],
"type": "object"
},
"name": "classify_event",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "Compute every reporting deadline of one regime from the moment of awareness. FREE.\n\nTypical input {\"regime\": \"eu_nis2\", \"event_type\": \"significant_incident\",\n\"awareness_at\": \"2026-09-14T09:30:00+02:00\"} returns {\"deadlines\":\n[{\"obligation\": \"early_warning\", \"due_at\": \"2026-09-15T09:30+02:00\",\n\"citation\": \"Art. 23(4)(a)\", ...}, ...]}. Later clocks that run from an\nearlier submission are estimated from that report's due time until you\npass the actual time in submitted. DORA needs classification_at and a\ncountry for the bank-holiday rule; the SEC needs\nmateriality_determined_at; HIPAA takes discovery_date and\nflags.individuals_affected. Use when an incident has just been\nidentified and the agent needs the instants. Not for several regimes at\nonce: use compute_deadlines_multi. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"} (for example {\"error\": \"flags must be an object\"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"awareness_at": {
"description": "when the entity became aware, ISO 8601 with a UTC offset.",
"type": "string"
},
"classification_at": {
"default": "",
"description": "DORA - when the incident was classified as major.",
"type": "string"
},
"country": {
"default": "",
"description": "ISO 3166-1 alpha-2 code for the public-holiday calendar (DORA weekend rule; SEC uses US).",
"type": "string"
},
"discovery_date": {
"default": "",
"description": "HIPAA - the date the breach is treated as discovered (defaults to awareness date).",
"type": "string"
},
"entity_class": {
"default": "",
"description": "e.g. trust_service_provider (NIS2), credit_institution / central_counterparty / trading_venue_operator / nis2_essential_or_important (DORA), business_associate (HIPAA).",
"type": "string"
},
"event_type": {
"default": "",
"description": "event type within the regime; optional when the regime has one.",
"type": "string"
},
"flags": {
"additionalProperties": true,
"default": {},
"description": "condition answers: high_risk, processor, ongoing, handled_at, individuals_affected, max_residents_of_one_state, business_associate.",
"type": "object"
},
"materiality_determined_at": {
"default": "",
"description": "SEC - when the incident was determined to be material.",
"type": "string"
},
"measure_available_at": {
"default": "",
"description": "CRA - when a corrective or mitigating measure became available.",
"type": "string"
},
"regime": {
"description": "regime id from list_regimes.",
"type": "string"
},
"subdiv": {
"default": "",
"description": "optional subdivision code for the holiday calendar (e.g. BY for Bavaria).",
"type": "string"
},
"submitted": {
"additionalProperties": true,
"default": {},
"description": "actual submission times of earlier reports, e.g. {\"initial_notification\": \"...\"}.",
"type": "object"
}
},
"required": [
"regime",
"awareness_at"
],
"type": "object"
},
"name": "compute_deadlines",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "One merged timeline across several regimes for the same incident. PREMIUM (license).\n\nTypical input {\"regimes\": [{\"regime\": \"eu_nis2\"}, {\"regime\": \"eu_gdpr\"},\n{\"regime\": \"eu_dora\", \"entity_class\": \"credit_institution\"}],\n\"awareness_at\": \"2026-09-14T09:30:00+02:00\", \"country\": \"DE\"} returns\n{\"timeline\": [rows sorted by due_at, each tagged with regime], \"first_due\":\n{...}, \"per_regime\": {...}}. Each entry may carry its own event_type and\nentity_class; the anchors and flags are shared. Use when one incident\ntriggers several regimes and the agent needs a single ordered list. Not\nfor one regime: compute_deadlines is free. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"} (for example {\"error\": \"regimes must be a non-empty list of <value>\"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"awareness_at": {
"description": "when the entity became aware, ISO 8601 with a UTC offset.",
"type": "string"
},
"classification_at": {
"default": "",
"description": "DORA classification instant.",
"type": "string"
},
"country": {
"default": "",
"description": "ISO 3166-1 alpha-2 code for the public-holiday calendar.",
"type": "string"
},
"discovery_date": {
"default": "",
"description": "HIPAA discovery date (defaults to the awareness date).",
"type": "string"
},
"entity_class": {
"default": "",
"description": "default entity class for entries that do not set their own.",
"type": "string"
},
"flags": {
"additionalProperties": true,
"default": {},
"description": "condition answers shared by all regimes (see compute_deadlines).",
"type": "object"
},
"materiality_determined_at": {
"default": "",
"description": "SEC materiality determination instant.",
"type": "string"
},
"measure_available_at": {
"default": "",
"description": "CRA corrective-measure instant.",
"type": "string"
},
"regimes": {
"description": "list of {\"regime\": id, \"event_type\"?: ..., \"entity_class\"?: ...} (1-10 entries).",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"subdiv": {
"default": "",
"description": "optional subdivision code for the holiday calendar.",
"type": "string"
},
"submitted": {
"additionalProperties": true,
"default": {},
"description": "actual submission times keyed by \"regime/obligation\" or obligation id.",
"type": "object"
}
},
"required": [
"regimes",
"awareness_at"
],
"type": "object"
},
"name": "compute_deadlines_multi",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "Mark each computed deadline open, due soon, overdue or submitted as of now. FREE.\n\nTypical input {\"deadlines\": <rows from compute_deadlines>, \"now\":\n\"2026-09-15T08:00:00+02:00\"} returns {\"items\": [{\"obligation\":\n\"early_warning\", \"status\": \"due_soon\", \"hours_remaining\": 1.5, ...}],\n\"overdue\": 0, \"next_due\": {...}}. Use when polling an incident timeline\nor deciding what to escalate next. Not for computing the deadlines\nthemselves. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"} (for example {\"error\": \"deadlines must be a non-empty list of rows from compute_deadlines\"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"deadlines": {
"description": "rows from compute_deadlines / compute_deadlines_multi (each with obligation and due_at).",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"now": {
"description": "the current instant, ISO 8601 with a UTC offset.",
"type": "string"
},
"submitted": {
"additionalProperties": true,
"default": {},
"description": "actual submission times keyed by obligation id (or \"regime/obligation\").",
"type": "object"
}
},
"required": [
"deadlines",
"now"
],
"type": "object"
},
"name": "deadline_status",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "Quote the time limit, citation and required content for an obligation. FREE.\n\nTypical input {\"regime\": \"eu_cra\", \"event_type\": \"severe_incident\",\n\"obligation\": \"final_report\"} returns {\"citation\": \"Art. 14(4)(c)\",\n\"rule\": \"within one month after ...\", \"required_content\": [...]}. Leave\nobligation empty to get every obligation of the event type; leave\nevent_type empty on single-event regimes. Use when a caller needs the\nrule's own words next to a computed date. Not for computing dates: use\ncompute_deadlines. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"} (for example {\"error\": \"unknown obligation '<value>' for <value>/<value>; one of <value>\"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"event_type": {
"default": "",
"description": "event type within the regime (see list_regimes); optional when the regime has one.",
"type": "string"
},
"obligation": {
"default": "",
"description": "obligation id (for example early_warning); empty for all.",
"type": "string"
},
"regime": {
"description": "regime id from list_regimes (eu_cra, eu_nis2, eu_dora, eu_gdpr, uk_gdpr, us_hipaa, us_sec_8k).",
"type": "string"
}
},
"required": [
"regime"
],
"type": "object"
},
"name": "explain_rule",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "List the public holidays the engine uses for a country and year. FREE.\n\nTypical input {\"country\": \"IE\", \"year\": 2026} returns {\"holidays\":\n[{\"date\": \"2026-01-01\", \"name\": \"New Year's Day\"}, ...]}. Use when\nchecking why a business-day or bank-holiday adjustment landed where it\ndid, or to see whether a country/subdivision is supported. Not a legal\nregister of bank holidays: it is the `holidays` package's public-holiday\ncalendar, which is what compute_deadlines uses. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"} (for example {\"error\": \"country is required\"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"country": {
"description": "ISO 3166-1 alpha-2 code (DE, FR, IE, US, ...).",
"type": "string"
},
"subdiv": {
"default": "",
"description": "optional subdivision code (state, province, region).",
"type": "string"
},
"year": {
"description": "calendar year.",
"maximum": 2100,
"minimum": 1990,
"type": "integer"
}
},
"required": [
"country",
"year"
],
"type": "object"
},
"name": "holiday_calendar",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "List the reporting regimes this server can compute, with citations. FREE.\n\nTypical input {} returns {\"regimes\": [{\"id\": \"eu_nis2\", \"name\": ...,\n\"instrument\": ..., \"applies_from\": ..., \"event_types\": [...]}, ...],\n\"verified_on\": \"2026-09-06\"}. Use when choosing the regime id and\nevent_type for compute_deadlines or classify_event. Not for legal advice:\nit reports what the instruments say and when the entry was last checked. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "list_regimes",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "Export computed deadlines as an iCalendar file and CSV rows. PREMIUM (license).\n\nTypical input {\"deadlines\": <rows from compute_deadlines or the\ntimeline from compute_deadlines_multi>, \"incident_ref\": \"INC-2026-041\"}\nreturns {\"ics\": \"BEGIN:VCALENDAR...\", \"csv\": \"regime,obligation,...\",\n\"events\": 4}. Each dated deadline becomes a VEVENT with the citation in\nthe description and an alarm alarm_hours_before it; rows without a fixed\ntime limit are listed in the CSV only. Use when the timeline needs to\nland in a calendar or a ticket. Not for computing deadlines. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"} (for example {\"error\": \"deadlines must be a non-empty list of rows from compute_deadlines\"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"alarm_hours_before": {
"default": 4,
"description": "hours before each due instant to fire a VALARM (0 disables).",
"maximum": 720,
"minimum": 0,
"type": "number"
},
"calendar_name": {
"default": "Incident reporting deadlines",
"description": "X-WR-CALNAME for the calendar file.",
"type": "string"
},
"deadlines": {
"description": "rows from compute_deadlines / compute_deadlines_multi.",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"incident_ref": {
"default": "",
"description": "your incident reference, prefixed to every event summary.",
"type": "string"
}
},
"required": [
"deadlines"
],
"type": "object"
},
"name": "timeline_export",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "Check a draft report against the statutory content list and its deadline. PREMIUM (license).\n\nTypical input {\"regime\": \"eu_gdpr\", \"obligation\":\n\"supervisory_authority_notification\", \"report\": {\"nature\": \"...\",\n\"contact\": \"...\", \"consequences\": \"...\", \"measures\": \"...\"}} returns\n{\"checklist\": [{\"item\": \"...\", \"found\": true, \"evidence\": [...]}, ...],\n\"missing\": [...], \"coverage\": 0.75, \"timing\": {...}}. The content check is\na keyword heuristic over the report text, reported as such; the timing\ncheck compares submitted_at with due_at and, for GDPR, flags a late\nnotification that gives no reasons for the delay. Use before a report is\nsent. Not a legal review, and it cannot judge quality, only presence. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {\"error\": \"<what is wrong and how to fix it>\"} (for example {\"error\": \"unknown obligation '<value>' for <value>/<value>; one of <value>\"}). Every call is read-only and idempotent, so after correcting the input it is always safe to retry.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"due_at": {
"default": "",
"description": "the computed due instant (from compute_deadlines), optional.",
"type": "string"
},
"event_type": {
"default": "",
"description": "event type within the regime; optional when the regime has one.",
"type": "string"
},
"obligation": {
"description": "obligation id (for example incident_notification).",
"type": "string"
},
"regime": {
"description": "regime id from list_regimes.",
"type": "string"
},
"report": {
"additionalProperties": true,
"description": "the draft, as an object of section name -> text (any keys).",
"type": "object"
},
"submitted_at": {
"default": "",
"description": "when the report was or will be submitted, optional.",
"type": "string"
}
},
"required": [
"regime",
"obligation",
"report"
],
"type": "object"
},
"name": "validate_report",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:15e8c0d42adcbf9cdd3303e06444c859c5a42086f812e1f5a5036ee372a10da4 | sha256sum