From copy-paste to conversation
For a while, the fastest way to get an AI assistant to reason about your security posture was awkward: export your findings, paste the JSON into a chat, and hope it stayed current. That works exactly once — the moment a new scan runs, your assistant is looking at stale data.
Connectors fix that. KollGuard now speaks MCP (Model Context Protocol) — the open standard that AI clients use to reach live tools and data. Add KollGuard once, and your assistant can pull your current findings, posture, and scan history on demand, in plain language, without anything leaving your account that you did not approve.
Three ways to connect
There is no single "API mode" in KollGuard — there are three doors to the same read-only data, and you pick the one that fits where your AI runs.
- API key (
kgr_) — a read-only token you drop into a script, a CI job, or a local config. It can read findings, posture, scans, and stats; it can never change anything. - Local MCP server — the open-source
kollguard-mcppackage. Run it withnpxinside Claude Code, Cursor, VS Code, Windsurf, or Zed, and your findings show up as tools the agent can call — and, because it is right there in your editor, help you apply fixes in your repo. - Remote connector — for web assistants that cannot run a local process, like claude.ai and ChatGPT. You add a URL and authorize with a sign-in. Nothing to install, no key to paste.
All three are read-only and scoped to your organization. Same data your Dashboard shows, mapped to the same SOC 2 and HIPAA controls.
How the remote connector works
When you paste https://api.kollguard.com/v1/mcp into your assistant's connector settings, a standard OAuth 2.1 handshake runs behind the scenes — the same kind of "Sign in and allow access" flow you already trust with other apps.
Once connected, the assistant sees a set of KollGuard tools — get_posture, list_findings, list_scans, stats, and the developer-tracker reads. Ask "What is my current SOC 2 posture?" or "List my open critical findings," and it calls the right tool and answers from your live data. Good clients ask permission before each call, so you always stay in control of what runs.
Read-only by design
Security tooling has to hold itself to the standard it measures. The connector does:
- Read-only scope. The connector is granted
mcp:readand nothing else. It can read your posture; it can never modify your account, your code, or your data. - OAuth 2.1 with PKCE. No long-lived secret is pasted into a third party. You approve access with a sign-in, and the token is short-lived and revocable.
- Tenant-scoped and per-user. A connection only ever sees your own organization's data, and removing the connector in your AI client revokes it immediately — without touching your teammates or your API keys.
That is the same least-privilege posture your auditors test for under SOC 2 CC6 and the HIPAA access-control standard — applied to the AI tools reading your compliance data.
Try it
- In claude.ai, open Settings → Connectors → Add → Add custom connector.
- Paste
https://api.kollguard.com/v1/mcp. Leave the OAuth fields blank — KollGuard registers automatically. - Sign in, click Allow, and ask: "Use KollGuard to show my current security posture."
Your compliance posture is now one question away — in the assistant you already use, always current, and read-only by design.
Get new posts by email
SOC 2, HIPAA, post-quantum readiness, and the engineering behind continuous compliance. No spam, unsubscribe anytime.
