Integrations

The 22 policy templates are open source (Apache-2.0), and the same renderer that runs on this site runs in three other places: your AI assistant, your CI and your terminal.

In your AI assistant (MCP)

Policyseed ships a Model Context Protocol server. Add it to Claude, Cursor or another MCP client, then ask something like “draft our SOC 2 access control policy”. The assistant asks the intake questions, renders the policy from the templates and can explain which criteria it addresses.

Claude Code:

claude mcp add policyseed -- npx -y github:odedmoshe/policyseed mcp

Claude Desktop (claude_desktop_config.json) or Cursor (.cursor/mcp.json):

{
  "mcpServers": {
    "policyseed": {
      "command": "npx",
      "args": ["-y", "github:odedmoshe/policyseed", "mcp"]
    }
  }
}
ToolWhat it does
list_policiesThe 22 policies with owner role and the SOC 2 criteria each one addresses
intake_questionsThe intake fields, allowed values and an example, so the assistant can interview you
render_policyOne policy rendered as Markdown for your company
render_allAll 22 policies, one item per file
check_reviewsWhich policies in a folder are overdue for review

Full setup and an example conversation: docs/mcp.md.

In CI (GitHub Action)

Keep your policies in a repository and let CI tell you when one is overdue for review. Auditors ask for evidence that policies are reviewed on the cadence they state; a weekly check that fails loudly is the cheapest way to never miss one.

name: Policy review check
on:
  schedule:
    - cron: "0 9 * * 1"
  workflow_dispatch: {}
jobs:
  check:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: odedmoshe/policyseed@v1
        with:
          command: check

Inputs and outputs: docs/github-action.md.

In your terminal (CLI)

No install step and no account; it needs Node.js 18 or later.

npx github:odedmoshe/policyseed init    # writes intake.yaml
npx github:odedmoshe/policyseed build   # renders the 22 policies into policies/
npx github:odedmoshe/policyseed check   # exits 1 when a review is overdue

Source, template syntax and the full policy list are on GitHub. Prefer a form? The generator does the same in your browser.

Frequently asked questions

Does the MCP server send my answers anywhere?
The server runs on your machine and renders the templates locally; it makes no network calls of its own. What you type to the assistant goes to whichever AI provider your assistant uses, as with any conversation.
Is the AI writing the policies?
No. The policy text comes from the same deterministic, open-source templates as the website. The assistant asks the intake questions and calls the renderer; you can still ask it to edit the result afterwards, and you should review the text before adopting it.
Which MCP clients work?
Any client that supports stdio MCP servers, including Claude Desktop, Claude Code and Cursor. It needs Node.js 18 or later on the machine.
What does the GitHub Action check?
It runs policyseed check against your rendered policies and fails the job when any policy's last review date is older than the review cadence in your intake, so an overdue review shows up as a red check. It can also run build to re-render the policies.
How is this different from the Audit Kit?
The CLI, Action and MCP server use the free templates. The $39 Audit Kit on this site adds AI tailoring of each policy to your named tools, Word files, the criteria crosswalk, registers, acknowledgment forms and a review calendar.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.