# WhitePact [Health: Active]

**Category:** 🔒 Security  
**Repository:** https://github.com/Guruprasath-Annadurai/Whitepact  
**GitHub Stars:** 2  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/whitepact

## Description
AI governance MCP server: trust scoring, guardrails, bias/hallucination detection, compliance.

## Tools
Capabilities this server exposes over MCP:

- **rai_scan** — Detect and redact PII + harmful content before it reaches a log
- **rai_trust_score** — Composite AI Trust Score (0-100) across 6 governance dimensions
- **rai_compliance** — NIST AI RMF / EU AI Act / ISO 42001 compliance evaluation
- **rai_hallucination** — Hallucination risk from hedging, consistency, unsupported claims
- **rai_cost_estimate** — USD cost of a model API call from token counts
- **rai_redteam_payloads** — Adversarial attack payloads (prompt injection, jailbreak, etc.)
- **rai_redteam_analyze** — Security report from model responses to red team payloads
- **rai_compare_models** — Compare two models across all 6 trust dimensions
- **rai_audit_summary** — Governance capability summary (tools, frameworks, attack vectors)
- **rai_health** — Status and module availability of the governance engine
- **rai_bias_evaluate** — Demographic bias across 6 probe dimensions with confidence intervals
- **rai_drift_check** — Trust score drift between a baseline and current evaluation
- **rai_passport_generate** — Verifiable, tamper-evident AI Passport for vendor risk assessment
- **rai_budget_check** — Spend vs. budget, per-team/model breakdown, month-end projection
- **rai_policy_check** — Text/response against a governance policy (blocklists, disclaimers)
- **rai_stream_scan** — PII/harm scan across streaming LLM output chunks
- **rai_benchmark** — Score responses against truthfulqa / bbq / hellaswag suites
- **rai_benchmark_prompts** — Question set for a benchmark suite
- **rai_model_route** — Cheapest model that can handle a task, with cost/quality tradeoff
- **rai_pii_report** — PII audit report by category with GDPR/CCPA remediation guidance
- **rai_incident_log** — Structured governance incident record for audit/SIEM
- **rai_eu_ai_act_classify** — EU AI Act risk tier classification with compliance roadmap
- **rai_iso42001_gap** — ISO/IEC 42001:2023 AI Management System gap analysis
- **rai_executive_summary** — Board-ready governance summary with RAG status indicators
- **rai_org_status** — Governance status snapshot: models, grades, compliance, risk
- **rai_webhook_status** — Webhook delivery health, failure analysis, remediation actions
- **rai_check_trust** — Free public Trust Index lookup for a **third-party** model/tool, before an agent invokes it — unlike every other tool above, which evaluates output the caller itself produced

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `uvx` (confidence: high):

```json
"mcpServers": {
  "whitepact": {
    "command": "uvx",
    "args": ["whitepact"]
  }
}
```

## Documentation

## What WhitePact MCP server does

The WhitePact MCP server provides MCP-accessible checks for AI governance workflows. Its tools evaluate model outputs, model behavior, and governance state rather than performing general-purpose application actions. Results cover trust, privacy, harmful content, hallucination risk, bias, compliance, cost, security testing, drift, incidents, and organizational status.

The server can redact personally identifiable information and harmful content before text reaches a log. It can also inspect streamed output chunks, check responses against policy rules, and create structured incident records for audit or SIEM workflows. For model and vendor review, it supports trust scoring, passport generation, third-party Trust Index lookups, compliance classification, and ISO 42001 gap analysis.

## How it works

MCP clients call named `rai_` tools with the text, model information, scores, token counts, policy details, or evaluation data required by each operation. Trust scoring combines six governance dimensions into a 0–100 result, while comparison and drift tools use multiple evaluations to identify differences or change over time.

Red-team workflows generate adversarial payloads and analyze the resulting model responses. Benchmark tools provide prompts or score responses against TruthfulQA, BBQ, and HellaSwag suites. Cost and routing tools estimate call costs, compare spending with budgets, and identify a lower-cost model that can handle a task according to the supplied cost and quality information.

The WhitePact MCP server does not require an LLM call for the governance decision path described by the project. Its governance platform also supports five decision outcomes—allow, allow with redaction, require approval, deny, and quarantine—but the listed MCP tools primarily expose individual evaluation and reporting functions.

## Setup and configuration

The project targets Python 3.11 or newer. Install the published package using its documented distribution name:

```bash
pip install "rai-governance-platform[dashboard]"
```

Optional extras are available for PostgreSQL, Redis, OpenTelemetry, OpenAI, Anthropic, or the complete feature set. The package distribution is `rai-governance-platform`, while the Python import name is `responsibleai`; installing `whitepact` is not the documented installation method.

The MCP server supports stdio, Streamable HTTP, and legacy HTTP+SSE transport modes. The provided material does not specify required environment variables or a client-specific configuration file. The wider package can also run a dashboard with Uvicorn, but that is separate from choosing and connecting an MCP transport.

## Tools and capabilities

Available capabilities include:

- Scan and redact PII or harmful content, including streamed output.
- Calculate trust scores, compare models, and detect trust-score drift.
- Evaluate NIST AI RMF, EU AI Act, and ISO/IEC 42001 alignment.
- Detect hallucination indicators and demographic bias with confidence intervals.
- Generate red-team payloads and analyze model responses.
- Estimate API-call cost, check budgets, and recommend model routing.
- Create AI Passports, PII reports, audit summaries, incident records, and executive summaries.
- Classify EU AI Act risk, inspect organization status, and check webhook health.
- Benchmark responses and obtain benchmark prompt sets.
- Look up the public Trust Index for a third-party model or tool before invocation.

## Limitations and notes

Most tools evaluate information supplied by the caller; they do not themselves establish that a model is safe or compliant in every deployment context. The third-party Trust Index lookup is distinct from the other tools: it checks an external model or tool before an agent invokes it, while the remaining evaluations concern output or governance data provided by the caller.

The material does not document required credentials, environment variables, exact MCP launch commands, or per-tool input schemas. Compliance and benchmark results should therefore be interpreted according to the inputs and evaluation method used by the surrounding application.

_Full upstream README: https://allmcps.com/mcp/whitepact/readme_

