
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
swissco-mcp
Advanced tools
An MCP server for Swiss company data. Nine tools that look a company up by UID, search 790,000 of them by name or by statutory purpose, trace what changed in the commercial register, browse public tenders, check a bank licence, resolve a UID to an LEI and its group parent, and find federally funded research a company took part in.
claude mcp add swissco -- uvx swissco-mcp
All data comes from six open-data sources, none of which needs a credential: Zefix on LINDAS for the commercial register, the Amtsblattportal for the Swiss Official Gazette of Commerce, simap.ch for public procurement, FINMA for authorised banks and securities firms, GLEIF for the Legal Entity Identifier and group structure, and ARAMIS for federally funded research.
Built and maintained by Prospex, a Swiss B2B sales intelligence platform.
The server runs over stdio and needs Python 3.14 or newer.
uvx swissco-mcp # run it without installing
pip install swissco-mcp # or install it
Registering it depends on the host. Claude Code takes one command:
claude mcp add swissco -- uvx swissco-mcp
Anything that reads a JSON config takes the equivalent block:
{
"mcpServers": {
"swissco": {
"command": "uvx",
"args": ["swissco-mcp"]
}
}
}
| Tool | What it answers |
|---|---|
swissco_lookup | Everything the register publishes about one company, optionally with its FINMA licence and its LEI |
swissco_search | Companies whose legal name or statutory purpose contains a term |
swissco_publications | Commercial-register publications from the gazette in a date range |
swissco_events | One company's registry events, each confirmed against the publication's own UID |
swissco_tenders | Public-procurement projects published on simap |
swissco_vendor | Whether a company holds a simap vendor profile, and what it says |
swissco_finma | Institutions on FINMA's list of authorised banks and securities firms |
swissco_lei | A company's LEI, the entity that consolidates it, and the entity at the top of that chain |
swissco_research | Federally funded research projects, Innosuisse and SNSF money included |
Every tool returns the same envelope: rows, a count, and notes.
Each source covers a slice of Swiss economic life, and a company's absence from
one of them usually means it sits outside that slice. notes says which:
notes also reports what a call did with a request it had to trim, and how many
requests a wide date range is about to cost.
Every tool works with no configuration at all. Four environment variables change what it does:
| Variable | Effect |
|---|---|
ZEFIX_USER, ZEFIX_PASSWORD | Zefix PublicREST credentials, issued by zefix@bj.admin.ch. They add capital, status, former names and corporate relations to swissco_lookup, and a name-prefix search to swissco_search |
SWISSCO_STATE | Where gazette bodies and the two FINMA files are cached. Defaults to ~/.swissco |
SWISSCO_INTERVAL | Seconds between requests. It can raise the floor of 0.5s and cannot lower it |
Requests are paced at half a second apart, and each source that asks for
something slower gets it: FINMA is paced at a second. These are small public
services run by federal offices, and SWISSCO_INTERVAL can raise that floor
but never lower it.
The same data is available as a shell command, from the same repository:
uvx swissco lookup CHE-444.420.929
See swissco on PyPI and its documentation.
Full reference for every tool, its arguments and its caveats: swissco-mcp.readthedocs.io.
MIT. The data belongs to its publishers, and each source's own terms apply; the access and terms section lists them.
FAQs
MCP server for Swiss company data: Zefix, SHAB, simap, FINMA, GLEIF and ARAMIS
We found that swissco-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.