MCP Server

Ask your AI assistant about your compliance posture. Get an answer your examiner would accept.

Connect Claude, ChatGPT, Cursor, or any Model Context Protocol client to ThirdSentry. Posture, risks, policies, evidence, and vendor Dual-Signal status, on demand, from the tool your team already has open. Read-only. Tenant-scoped. Every question audit-logged.

An AI assistant asking ThirdSentry over MCP which critical vendors are flagged for posture divergence, with the matching audit log entries beside the answer
What your team can ask

The questions that used to take a login, three tabs, and an export.

Your GRC data does not move. The assistant asks ThirdSentry, ThirdSentry answers from the live record, and the answer carries the tool it came from.

Which vendors have a claimed posture that disagrees with their live exposure right now?

list_posture_divergences

What is our SOC 2 audit readiness this week, and how many documents are still outstanding?

posture_summary

Give me every open critical risk with its residual score and treatment.

list_risks

Pull the published access control policy so I can quote it in this customer questionnaire.

get_policy

Show the drift history for our payments processor before the board meeting.

get_vendor_posture

Which controls failed an automated test in the last sync?

list_issues

Built for the security review

An AI channel your CISO can sign off on.

Most AI integrations bolt onto a permission config. Ours is enforced where the data lives, with the same architecture that keeps auditors read-only and policy versions immutable.

Read-only by construction

MCP keys carry one fixed scope. There is no tool that creates, edits, approves, or deletes. An assistant cannot be talked into a write because the write does not exist.

Tenant-scoped on the server

Every query is pinned to your organization before the assistant's request is read. No tool accepts an organization id, so there is nothing to spoof.

Every question in your audit log

Each tool call is written to the same immutable audit log your examiner reads: which key, which tool, which arguments, how long, what outcome.

Off until an admin turns it on

Disabled by default for every organization. An administrator enables access, issues per-person keys, and revokes them on offboarding.

Why this is different

The assistant can ask about divergence because both signals live on one data model.

A compliance automation tool can tell your assistant what a vendor claimed. A ratings platform can tell it what the internet sees. Neither can answer “where do those two disagree?” because they never hold both. ThirdSentry does, so list_posture_divergences is a one-line question instead of a two-tool reconciliation.

  • Vendor Dual-Signal: assessed posture and live external exposure on every vendor record
  • Internal control divergence: attested status against automated test signal
  • Frameworks, controls, risks, policies, evidence, and vendors on one tenant-isolated model
tools/list
  • posture_summary
    Per-framework Assurance and Audit Readiness, control counts, outstanding documents.
  • list_posture_divergences
    Vendors and controls whose claimed posture disagrees with live signal.
  • get_vendor_posture
    One vendor's Dual-Signal view: criticality, assessed posture, live exposure, drift, verdict.
  • list_vendors
    Vendor inventory with drift severity and the Posture Divergence flag.
  • list_drift_events
    External exposure drift events with severity and analyst status.
  • list_risks / get_risk
    Risk register with inherent and residual scores.
  • list_policies / get_policy
    Policy lifecycle and the text of the latest published, immutable version.
  • search_controls
    Control library search across your controls and the shared framework library.
  • list_evidence
    Evidence vault metadata. Never file contents, never download links.
  • list_issues
    Open findings, including automated control test failures.
Setup

Connected in about five minutes.

One endpoint, one key, any MCP client. Standard Streamable HTTP transport, no agent to install, nothing to host.

01

Enable access

An administrator turns on MCP access under Settings. It is off for every organization until then.

02

Issue a key

Per person, per client. Optional expiry. Shown once, revocable any time, listed in the audit log.

03

Paste into your client

Claude Desktop, Claude Code, Cursor, ChatGPT, or anything that speaks MCP over HTTP. Copy-ready snippets in Settings.

ThirdSentry MCP server settings with access enabled, three issued read-only keys, and the client connect snippet

Setup time is an illustrative target. Some assistant plans require OAuth for custom connectors; OAuth for the MCP server is on the roadmap and bearer keys work today with every client that accepts a header.

What it means for your team

Answers in the tool you already have open, with the audit trail you already need.

No login, no export, no copy-paste into a deck. And nothing your CISO has to explain away.

Minutes
instead of a login and an export
Ask for posture, risks, a policy, or a vendor's drift while you are already writing the memo.
0
writes, by construction
Every tool reads. There is no write to prompt-inject, misuse, or explain in a security review.
100%
of questions audit-logged
Each tool call is written to your audit log with the key, the arguments, and the outcome.
5 min
to connect a client
One endpoint, one key, any MCP client. Nothing to install, nothing to host.
  • Board prep from the live record
    Pull this quarter's audit readiness and the flagged vendors into the deck from the assistant, with numbers as of right now.
  • Questionnaires answered from published policy
    get_policy returns only the latest published, immutable version, so quoted text is always the approved text.
  • A divergence check in one question
    Ask which vendors' claimed posture disagrees with live exposure. One tool, because both signals live on one data model.
  • Offboard a person, not a platform
    Keys are per person, revocable in a click, and every issue and revoke is itself an audit event.

Illustrative outcomes, stated as built-to-deliver targets. ThirdSentry is pre-GA and these are not realized customer results. The audit-logging figure describes how the server is built, not a measured customer average.

Put your posture where your team already asks questions.

The MCP server ships with every plan. AI is platform-native at ThirdSentry, never a tier.