
VendorWatch
io.github.sergiomaldov1.0.0Updated Oct 6, 2026
Check a vendor before you sign: DPA coverage, subprocessors, certifications, data locations, AI use.
Overview
AI-generated overview
Lets an assistant look up vendor due-diligence details such as DPA coverage, subprocessors, certifications, data locations and AI use before signing.
- What it does
- VendorWatch is a remote MCP server that gives an assistant a way to check a vendor before committing to a contract. According to its registry description, it covers DPA coverage, subprocessors, certifications, data locations and AI use. No individual tools are listed in the manifest, so the exact operations are not documented here.
- When to use it
- Worth adding when you regularly evaluate software or service vendors and want an assistant to pull due-diligence facts into a review, procurement or compliance conversation. Less useful if you never assess third-party vendors.
- Requirements
- A remote streamable HTTP endpoint at vendor.watch; no local package or runtime is needed. It requires an Authorization header containing a Bearer token with a VendorWatch agent key (vwa_...). Network access to the endpoint is required.
Before you install
The Authorization header carries a VendorWatch agent key (vwa_...), so treat it as a secret and avoid exposing it in logs or shared configuration. The manifest declares no other authentication and no write tools, but the tool list is not published, so confirm what the server can do before relying on it.
Installation
In SourceWeft
- Open VendorWatch in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"vendorwatch": {
"type": "http",
"url": "https://vendor.watch/api/v1/mcp"
}
}
}Tools
0Tool metadata has not been indexed yet.
Version history
1- v1.0.0LatestOct 6, 2026
