Free connector · MCP

Ask your AI assistant, and get the regulator’s answer

Connect Claude or ChatGPT to the Indian cyber regulation register. It answers which instruments bind you and when an incident must be filed from text read at source, not from what the web says.

General-purpose assistants answer Indian regulatory questions from whatever they were trained on, and the public web is wrong about several of them — SEBI’s deadline, DPDP’s commencement, the twelve hours LODR gives a listed company. This connector gives the assistant BitScore’s 32-instrument register instead, each entry re-read from the regulator’s own notification (oldest check 18 August 2026), and the same calculations the free tools run.

No account, no key, nothing to install. It is read-only and remembers nothing you ask.

Add it to Claude

  • Claude (web and desktop). Settings → Connectors → Add custom connector. Name it “BitScore regulations” and paste https://www.bitscore.in/mcp. Then enable it in a chat from the tools menu.
  • Claude Code. claude mcp add --transport http bitscore-regulations https://www.bitscore.in/mcp

Add it to ChatGPT

  • As a connector. Where your ChatGPT plan allows custom connectors (developer mode), add https://www.bitscore.in/mcp with no authentication.

Other clients and builders

  • Any MCP client — Cursor, VS Code, Windsurf, your own agent: a Streamable HTTP server at https://www.bitscore.in/mcp, no authentication. It speaks MCP revision 2026-07-28 and the 2025 revisions that open with initialize.
  • The MCP Registry lists it as io.github.nimitt-IN/india-cyber-regulations.
  • OpenAPI. The same tools as plain JSON over HTTPS, described at openapi.json — importable as GPT Actions or any function-calling tool list.
  • The raw data is on the open data page under CC BY 4.0.

What it can answer

  • Search the Indian cyber regulation register (search_instruments) — Search every cyber and data-protection instrument binding Indian regulated entities (RBI, SEBI, IRDAI, IFSCA, CERT-In, MeitY/DPDP): reference number, issue date, status, who it binds and the deadlines it sets. Filter by free text, issuer or status. Returns summaries; use get_instrument for one entry in full.
  • Get one instrument from the register (get_instrument) — Full register entry for one instrument by its id (from search_instruments): formal name, reference, issue date, status, who it binds, every dated deadline it sets, the regulator’s own URL and the date it was last re-read there.
  • Which Indian cyber regulations apply to an entity (find_applicable_regulations) — Given an Indian entity class, whether it is listed and whether it handles personal data, returns the cyber and data-protection instruments that bind it, why each applies, a caution where one is commonly misapplied, and its next dated deadline. RBI classes each map to their own 2026 Directions; RRBs and LABs have none, and the result says so.
  • Indian cyber incident reporting deadlines (india_incident_reporting_deadlines) — Every incident-reporting clock an Indian entity owes — CERT-In six hours, the sectoral regulator (RBI, SEBI, IRDAI, IFSCA), SEBI LODR, NCIIPC, DPDP — each with its trigger, recipient, channel and source clause. Give noticed_at to get wall-clock IST due times. Clocks run in parallel; none discharges another.
  • US and EU cyber incident reporting deadlines (us_eu_incident_reporting_deadlines) — Incident-reporting clocks under SEC Form 8-K/6-K, NYDFS Part 500, the US bank 36-hour rule, HIPAA, the FTC Safeguards Rule, NIS2, DORA, GDPR and the EU Cyber Resilience Act, each from its own trigger. Give aware_at (and decided_at for materiality/classification clocks) for wall-clock due times.
  • Which cyber regulations apply across India, the US and the EU (find_global_cyber_regulations) — For an organisation operating across India, the US and the EU, lists the cyber and data-protection regimes that apply, may apply (check) or are pending, with why and a caution for each. All flags default to false and sizes/sectors to none.
  • SEBI CSCRF category for a regulated entity (sebi_cscrf_category) — Works out a SEBI regulated entity’s CSCRF category (MII, Qualified, Mid-size, Small-size, Self-certification or Exempt) from the current thresholds, and the obligations that category carries. Call with only entity_type to see which figures it needs. Boundary values the circulars leave uncategorised are reported as such, not guessed.
  • India Cyber Threat Scorecard (india_threat_scorecard) — Aggregate counts of publicly observed cyber threat activity affecting Indian organisations, by industry vertical and category, for one edition (latest by default). Aggregate only: no organisation is named. A vertical the source did not cover is unmeasured, not zero.

Questions to try

  • Which cyber regulations bind a listed NBFC that holds customer data?
  • We noticed a ransomware incident at 2:30 pm today. We are a SEBI stock broker. What do we owe, to whom, and by when?
  • Is the DPDP breach-reporting duty in force yet?
  • What CSCRF category is a proprietary broker with ₹40 crore at the clearing corporation?
  • We are an Indian SaaS firm with EU customers and a US listing. Which regimes apply?

Limits, privacy and sources

  • Read-only and stateless. Every tool is a calculation over the published register; nothing is written, and the arguments you send are not stored. Requests are rate-limited per IP address.
  • Indicative, not legal advice. Every answer carries its source reference and the date that source was last read. Confirm applicability with your counsel or compliance function.
  • It does not rate companies. For your organisation’s own Bitsight security rating, request the complimentary report below.
  • Privacy. See the privacy policy. Issues or a wrong answer: contact us and we will re-read the source.

Your obligations are public. So is your rating.

The connector tells you what you owe. Your organisation is also rated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and read your own figures.

Request my rating →