LawVu MCP server icon

LawVu

by LawVu

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Data & Research51 tools

Search matters, contracts and legal knowledge in a LawVu LegalOS tenancy from an AI agent, and create or delete records in it. Anthropic lists 51 tools: 29 read, 16 write, 5 delete. No OAuth scopes are published, LawVu publishes no privilege-waiver warning, and its AI terms never mention MCP.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect LawVu via MCP

https://mcp.lawvu.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

LawVu Tools & Capabilities (51)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • No OAuth scopes exist to narrow the grant. Neither the resource descriptor nor the authorization server metadata declares scopes_supported, so nothing at consent separates reading a matter from deleting a legal note.
  • LawVu names no individual tool. All 51 names come from Anthropic's directory. LawVu publishes capability groups instead, which is diffable at the capability level but means a renamed tool would be invisible to us.
  • One documented write capability has no matching tool name. LawVu lists "Trigger contract workflows" as something a connected AI tool can do; no name among the 51 carries a trigger, workflow or stage verb, so we cannot say which tool it is or what its arguments allow.
  • We could not read tool schemas or safety annotations. The endpoint returned 401 to an anonymous request, so no parameter detail appears here and no tool's readOnlyHint or destructiveHint could be read. The read/write/delete split is our classification of the names, not the server's declaration.
  • explain_tool is unclassified. Its name suggests a meta helper, but without a schema we cannot rule out that it forwards an argument, so it is excluded from the read count rather than assumed safe.
  • No invoice, spend or approval tool exists — and no accounting one either. The connector can neither authorise spend nor read it, so an agent cannot check a matter's budget or actual spend before creating work against it.
  • Delete tools are irreversible as far as LawVu documents. No undo, restore or trash tool appears among the 51, and LawVu publishes no retention window for a deleted legal note or conversation message.
  • The feature is gated commercially and administratively. Activation requires a Customer Success Manager or support request, then an Organisation Admin enabling the tile. LawVu also describes the tool set as one that "will expand over time", so today's 51 is a snapshot.
  • No rate limits are published. LawVu documents no request cap, no HTTP 429 behaviour and no retry guidance for the MCP server, so throughput is unpredictable.
  • LawVu publishes no privilege-waiver guidance. Recorded here as an absence, not an all-clear — see the section above.
  • No published term covers MCP at all. LawVu's AI Service Terms, AI Acceptable Use Policy and AI FAQ never mention MCP, and its AI Powered Products table lists seven Azure features that do not include it. So the no-training promise and the qualified-professional review requirement are not demonstrably binding on data sent to Claude or ChatGPT through this connector.
  • No term governs which AI account may connect. There is no enterprise-account requirement and no bar on a personal or free-tier AI account. A peer legal connector imposes both contractually.
  • Anthropic is not a LawVu subprocessor, by design. LawVu's subprocessor list, updated 4 August 2026, names Microsoft Azure, Intercom, Twilio, Cloudflare and others. Anthropic does not appear, and the only OpenAI entry is "Microsoft Corporation (Azure OpenAI)" under LawVu's own AI Services. MCP is framed as your relationship with the AI provider rather than LawVu's, so connector use triggers no subprocessor obligation.
  • LawVu publishes no retention statement for MCP data. Its DPA and privacy policy set a 12-month backup window for User Data generally, but nothing addresses what happens to data passing through the MCP server specifically.
  • Compliance evidence is gated. ISO 27001, SOC 1, SOC 2 and an AssuranceLab seal are claimed, but the artefacts sit in a "security pack" behind a request form and a confidentiality click-through rather than a public trust portal. ISO 42001 is described as being pursued, not held.
  • LawVu's robots.txt is truncated mid-directive. The file ends after User-agent: Bytespider with no Allow or Disallow line following it, so that group is empty and falls through to the wildcard. Cosmetic for this connector, but it indicates an edit that was cut off.
  • LawVu places the AI-side security posture on you. It states that it enforces permissions and maintains an audit trail on its side, but that "the security posture of the AI tool itself — and how it is deployed within your organization — is your responsibility."
  • The production host root serves a page titled "LawVu Local MCP". https://mcp.lawvu.com/ returns a one-line HTML page carrying that heading and directing clients to /mcp. The MCP endpoint itself behaves correctly; the stray "Local" in a production title is cosmetic, but it is what the host publishes.
  • Documentation is one article. LawVu's entire MCP documentation is a single help-centre page. There is no tool reference, no schema documentation, no error-code table and no security page specific to the connector.

Frequently asked questions

No tool can. None of the 51 names carries an approve, decline, void, invoice, spend, budget or payment verb, and LawVu's MCP article omits invoices from both its read and write lists. That matters because approving an invoice batch in LawVu forwards it to Finance for payment, so an approval tool would have been a payment authorisation.

Twenty-one. Our reading of the names gives 29 read, 16 write, 5 delete and one meta tool. The five deletes remove status messages, legal notes, conversations and conversation messages. A narrow risky-verb scan finds only those five and misses all 16 writes, so the delete count alone understates the surface by three times.

No. We searched LawVu's entire public corpus — every help-centre article, every sitemap page and all eight published terms documents — and found no privilege, attorney-client or work-product language anywhere. Consilio's Aurora connector, in the same directory category, does warn. The absence of a warning is not a statement that no risk exists.

None are published. The server's RFC 9728 resource descriptor and its authorization server metadata both omit scopes_supported entirely, checked live on 2026-08-23. So no consent screen can offer reading a matter without also granting the five delete tools. The only boundary is the signed-in user's existing LawVu permissions.

Whatever the signed-in user can already open, which for an in-house lawyer is legal advice. The read tools reach matter legal notes, private conversation messages, contract and matter file contents, and the internal knowledge base. LawVu states the server grants no elevated permissions and cannot see a record the user cannot.

Two gates, one commercial and one administrative. LawVu states you must first contact your Customer Success Manager or support team to have the MCP Server feature activated on your account. A LawVu Organisation Admin then opens the Integrations screen, finds the MCP Server tile and enables it for users before anyone can connect.

No, and the join tools are narrower than they look. LawVu documents Join as clicking join on a record a user can already access, which adds them as a member for notifications and participation. Restricted matters block self-joining entirely, so join_matter cannot reach a record the user was walled off from.

No, and it says so twice. LawVu's MCP article strongly recommends requiring human review and approval for any AI-initiated action that creates, modifies or deletes records, particularly early in deployment. Its recommendations list repeats the point and advises granting minimum access rather than enabling MCP organisation-wide.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Data & Research
Developer
LawVu
Tools
51
Domain
mcp.lawvu.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.