Allow the mcp and data sources to declare a compliance level. For example SOC 2. the user can select that current session will only connect and use SOC2 or some other rating during the session. This helps with minimizing mixing of data from secure and insecure environments/rag sources/mcps.