What does it do?
It puts a Terraform security engine inside the assistant that is writing your Terraform. Instead of generating code and finding out in a pull request that it was wrong, the assistant asks what the rules are, writes code that satisfies them, then checks its own output.
Eight tools are exposed. You never call them — the assistant does:
| Tool | Purpose |
|---|---|
scan_terraform | Scan HCL from disk or an unsaved buffer; findings by severity with file and line |
explain_finding | The full remediation for one finding and the exact Terraform that fixes it |
apply_fixes | Apply the mechanically-safe fixes and return patched HCL |
secure_template | A hardened starting point, so the insecure version is never written |
check_compliance | Map findings to SOC 2, ISO 27001, NIST 800-53, PCI-DSS, DORA, NIS2, NCA, NESA |
framework_coverage | Which articles of a regulation automated scanning can and cannot evidence |
org_requirements | Your organisation’s own rules for a resource type, before the code is written |
org_status | Whether organisation policy is in force, or built-in rules only |
How do I install it?
It ships as a Python package on PyPI and runs over stdio. uv handles the install, so there is nothing to set up first.
Claude Code
claude mcp add sovereign -- uvx sovereign-observerCursor
In ~/.cursor/mcp.json:
{
"mcpServers": {
"sovereign": {
"command": "uvx",
"args": ["sovereign-observer"]
}
}
}VS Code (GitHub Copilot)
In .vscode/mcp.json:
{
"servers": {
"sovereign": {
"type": "stdio",
"command": "uvx",
"args": ["sovereign-observer"]
}
}
}Windsurf
In ~/.codeium/windsurf/mcp_config.json, same shape as Cursor.
The first run downloads the scanning engine (around 100 MB) and takes a moment. After that it is local and fast.
How do I know it is working?
Open a new conversation and ask for something ordinary, without mentioning security:
add an S3 bucket for user uploads to my TerraformIf it is wired up, the assistant writes the resource, scans it unprompted, and comes back with the findings already fixed. A bare aws_s3_bucket produces seven findings, so there will be something to report.
If it writes the bucket and stops, the server is not connected — check the config path and restart the editor.
Does my code leave my machine?
No. The scan runs in the server process on your own machine, and there is no network call in the default path — it works with networking disabled entirely.
Connecting an organisation token changes what rules are applied, not what leaves. The server fetches your company’s policy with a single GET request and evaluates it locally. Rules come down; code never goes up. That is asserted at the transport layer in the package’s own test suite, not just documented.
What about my company’s own rules?
Built-in rules cover the common misconfiguration classes. Organisation rules cover the things only you know — which regions are approved, what retention your auditor expects, which instance classes finance will sign off on.
export SOVEREIGN_TOKEN=... # Integrations → GitHub in the dashboardWith a token set, org_requirements returns your rules for a resource type before the assistant writes it, and violations appear in scans tagged source: org_policy so a developer can always tell a company requirement from a built-in one. The same rules run in CI and against live cloud accounts, so the editor and the merge gate never disagree.
What does it not do?
Worth stating plainly, because a security tool that overstates its scope is worse than none:
- It scans Terraform. Not container images, not dependencies, not running workloads.
check_compliancereturns control mappings — evidence that shortens an audit, not a compliance assessment. Every framework it maps also carries governance and process obligations no scanner can observe.apply_fixesis deliberately narrow: single-attribute, in-place changes from a hand-verified allowlist, and it never overwrites a value wired to a variable. Everything else stays advisory, because a mechanically-clean fix can still take a running system down.
Frequently asked questions
How do I add a Terraform security MCP server to Claude Code?
Run: claude mcp add sovereign -- uvx sovereign-observer. That registers the server over stdio. Open a new conversation and ask for a Terraform resource; the assistant will scan what it writes without being told to.
Is the Sovereign Observer MCP server free?
Yes. It is free and open source under Apache-2.0, with no account, no API key and no usage limit. Connecting an organisation token to enforce your own company policy is a paid feature of Sovereign Observer, but everything else works unconnected.
Does it work with Cursor and GitHub Copilot?
Yes. It speaks standard MCP over stdio, so it works in any MCP client. Configuration snippets for Cursor, VS Code with Copilot, and Windsurf are in the package README — all three use the same command, uvx sovereign-observer.
What scanning engine does it use?
Checkov, the Apache-2.0 open-source IaC scanner, pinned to the same version the Sovereign Observer backend runs so a finding in your editor matches a finding in CI. Severity is derived from a curated map plus a keyword classifier, since Checkov community edition reports most checks without one.
See your cloud the way an attacker does.
Connect AWS, Azure or GCP with a read-only role you create yourself and get ranked attack paths in minutes. No sales call, and no keys stored on our side.