com.saasdossier/evidence-ledger
com.saasdossier/evidence-ledger · 1.1.0
Read-only MCP: free OpenAI security evidence ledger (55 fields) + SaaSDossier release register.
Nobody here has read this server's code, because it publishes none. The description above is the maker's own, from the registry. A connection test shows whether it answers and what tools it says it has; it never calls a tool, so it cannot show what one does with your data.
Where it sits in the directory's order
What can be seen from outside, weighed as the directory publishes.
Observable signals: 45 of 100 points (at most 60 here)
| Input | Points | What was seen |
|---|---|---|
| Source published | held at 0 | No entry here publishes source: that is what puts it in this directory. |
| Licence stated | held at 0 | With no files, there is nothing for a licence to be stated in or held against. |
| Advisory state | held at 0 | Advisory databases index packages, and these entries publish none, so there is nothing to look up. |
| Auth declared | 0 of 15 | The registry entry declares no key. That is what it declares, not a finding that it has no protection. |
| Latest connection test reached it | 20 of 20 |
Where it answers
https://saasdossier.com/mcpstreamable-http
Connection test
The MCP handshake, then a request for the tool list, with no key and no data of yours. Run nightly, and by anyone, at most once every ten minutes per server.
It completed the handshake and listed 4 tools.
- Protocol
- 2025-06-18
- Calls itself
- SaaSDossier 1.1.0
- Handshake time
- 65 ms
- HTTP status
- 200
The tools it lists (4, as of 3 days ago)
The tool-description rules found nothing in these descriptions. They look for instructions aimed at a model and for hidden characters; they cannot see what a tool does when it runs.
get_registerReturns SaaSDossier's release register: dossier numbers, vendors, editions, and licensing information. The register is the released catalogue: four finished evidence records built only from vendor-published sources across a fixed 55-field, 10-domain framework, every field recorded in one of two states — Documented, or Question surfaced. Each entry carries its vendor, dossier number, edition, evidence date, two-state counts and commercial status: Licensed Editions are US$1,500 one-time; the OpenAI Public Edition is free and complete. Separately from that catalogue, the same response carries the
get_openai_ledgerReturns the free public OpenAI security evidence ledger — 55 fixed fields, each either Documented with a vendor-published source or recorded as a Question surfaced. This is the complete Public Edition record, Dossier No. 003: 47 fields Documented and 8 Question surfaced across 10 domains, free, dated to its evidence date. Documented fields carry the vendor's own quoted wording and the source URL it was found on; Question surfaced fields carry the follow-up question a buyer can put to the vendor in writing. Question surfaced means the reviewed vendor-published sources did not establish the fiel
get_methodologyReturns SaaSDossier's two-state evidence framework: Documented and Question surfaced. A Question surfaced is not a finding of absence. SaaSDossier is the vendor's own record, made reviewable: a finished, dated, source-linked, human-reviewed evidence workproduct built only from vendor-published sources, recording 55 fixed fields across 10 domains for each vendor, with a source register listing every vendor page reviewed. Documented means the reviewed vendor-published sources established the field for the evidence date; Question surfaced means they did not, and each one becomes a buyer-ready fol
get_free_dossierReturns the free OpenAI Public Edition: the dossier title, the direct PDF download URL, and the guided page URL. The OpenAI record, Dossier No. 003, is published free and complete as proof of the format: the same 55 fields across 10 domains, the same two states (47 Documented, 8 Question surfaced), the same source register and the same integrity identifier a Licensed Edition carries. It is built from OpenAI's own published pages, reviewed before release; no relationship with, or endorsement by, OpenAI is implied. Use this tool to give a buyer the whole workproduct to read before they license a
How this entry becomes a listing
For the maker. The catalogue lists what it can read, and this server publishes nothing to read yet. There are two routes, and only the first is open today.
Publish the source Open today
- Put the server's source in a public repository on github.com, with a licence.
- Keep a server.json in that repository naming this server,
com.saasdossier/evidence-ledger, and declare the repository in it:"repository": { "url": "https://github.com/owner/repo", "source": "github" }, adding"subfolder"when the server lives in a folder. - Publish that version to the official MCP registry.
- The nightly registry sweep records the declaration. This page stays, dated, and says the source is declared but not yet read.
- The catalogue reads declared repositories at a pinned commit, in batches run by hand, and lists the servers that meet the batch's rules (among them a server.json at that commit naming the server, an https endpoint and a licence). When it lists this server, this page links to the listing. There is no schedule, so no date can be promised.
List it through the maker studio Not open yet
From the official MCP registry, last updated there 85 days ago. The registry entry · saasdossier.com