Security Assistant MCP Server
Connect your AI assistant to Strike Graph to query your compliance data in plain language
Written By Micah
Your compliance program generates a lot of data — controls, evidence, risks, framework criteria, and Verify AI test results. The Strike Graph Security Assistant MCP server lets you query all of it from the AI assistant you already use, in plain language, without logging into Strike Graph or exporting a report first.
What is the Security Assistant MCP server?
MCP (the Model Context Protocol) is an open standard that lets AI assistants connect securely to external systems. Strike Graph hosts an MCP server that exposes your organization's compliance data as a set of read-only tools your AI assistant can call on your behalf.
Once connected, you can ask questions like "which evidence items are missing attachments?" or "summarize our SOC 2 readiness" and your assistant will pull live data directly from your Strike Graph workspace to answer.
A few things worth knowing up front:
It's read-only. The MCP server can retrieve and summarize your data. It cannot create, edit, or delete controls, evidence, risks, or attachments.
It respects your permissions. You sign in with your own Strike Graph credentials, and the server acts as you. You will only ever see data from your own organization.
It works with the assistant you already use. Any MCP-compatible client works, including Claude and ChatGPT.
What you can ask about
The MCP server provides tools across six areas of your compliance program:
Compliance posture — overall scores across every enabled framework, posture for a single framework, and the satisfaction status of individual criteria
Controls — search and filter by framework, implementation status, operating frequency, or ownership; retrieve full control details; list the evidence attached to a control
Evidence — search for items that need attention, are missing attachments, are unassigned, or have attachments expiring soon; retrieve full evidence details including attachment names
Risks — search your risk register by category, consequence, likelihood, treatment strategy, status, or owner; retrieve full risk details including mapped controls
Reporting — generate control, evidence, and risk summary reports, or a comprehensive compliance report that combines all of them
Verify AI — review test results for an attachment or evidence item, build a queue of attachments flagged as needing review, and dig into individual test runs
Before you begin
You'll need the following:
MCP access enabled for your organization. This is enabled per organization by Strike Graph. If your connection is rejected or tool calls return a permission error, reach out to your Customer Success Manager to request access.
An eligible Strike Graph role. The Manager, Contributor, Trust Manager, and Trust Contributor roles can use the MCP server. Viewers and the Auditor role cannot.
An MCP-compatible AI assistant. Claude and ChatGPT both support custom MCP connectors. Availability and plan requirements are set by those providers, not by Strike Graph.
Connecting your AI assistant
The Strike Graph MCP server lives at a single endpoint:
https://mcp.grc.strikegraph.com/mcpYou do not need an API key or client secret from Strike Graph. Authentication happens through the same secure login you already use for Strike Graph.
Step 1: Add the connector
In your AI assistant, open the settings area for connectors (in Claude, this is Settings > Connectors; in ChatGPT, look for connectors or apps under settings).
Choose the option to add a custom connector.
Enter a recognizable name, such as Strike Graph.
Paste
https://mcp.grc.strikegraph.com/mcpas the server URL.Save the connector.
Step 2: Sign in and authorize
Click Connect on the newly added connector.
You'll be redirected to Strike Graph's login page. Sign in with your usual Strike Graph credentials — including SSO, if your organization uses it.
Review the access being requested and approve it.
You'll be returned to your assistant with the connector now showing as connected.
Step 3: Confirm the connection
Ask your assistant a question that requires live data, such as:
What's our current compliance posture across all of our frameworks?
If the assistant returns real framework names and scores from your workspace, you're all set. Depending on your assistant, you may be asked to approve the first tool call before it runs.
Getting good results
The MCP server is most useful when you point your assistant at a specific question rather than asking it to browse. Some examples that map well to the available tools:
"Which evidence items don't have any attachments yet?"
"Show me every control that isn't in place for ISO 27001."
"Which of my evidence attachments expire in the next 30 days?"
"List our high-consequence risks that haven't been mitigated."
"Which attachments has Verify AI flagged for review?"
"Build me an executive summary of where our SOC 2 program stands."
"Which controls and evidence items don't have an owner assigned?"
A few tips:
Name the framework when you have one in mind. Saying "SOC 2" or "ISO 27001" lets your assistant scope its query instead of pulling everything.
Ask for summaries before details. Starting broad and then drilling in tends to produce better answers than asking for everything at once.
Remember it's a snapshot in time. The assistant reads your data at the moment you ask. If you make changes in Strike Graph, ask again to pick them up.
Verify anything you plan to act on. Like any AI-generated output, responses should be spot-checked against Strike Graph before you use them in an audit conversation or a board report.
Troubleshooting
The connection fails or you're asked to sign in repeatedly
Confirm the URL is exactly https://mcp.grc.strikegraph.com/mcp, including the /mcp path. Leaving it off is the most common cause of a failed connection.
You connect successfully, but tool calls return a permission error
This usually means one of two things: MCP access hasn't been enabled for your organization yet, or your Strike Graph role isn't eligible. Auditor accounts cannot use the MCP server. Reach out to your Customer Success Manager to confirm your organization's access.
The assistant says it can't find a control, evidence item, or risk
Tools that retrieve a single item look it up by its Strike Graph ID. If you're referencing an item by name, ask your assistant to search for it first, then pull the details. Also keep in mind that inactive and archived items are excluded by default — mention that you want them included if you need them.
The assistant returns data that looks out of date
Each question triggers a fresh read, but your assistant may reuse an answer from earlier in the same conversation. Ask it explicitly to check Strike Graph again.
Your assistant doesn't offer custom connectors
Support for custom MCP connectors varies by provider and plan. If you don't see the option, check your assistant's documentation for its current requirements.
Removing the connection
You can disconnect the Strike Graph connector from your AI assistant at any time using that assistant's connector settings. Disconnecting stops all further data access immediately and does not change anything in your Strike Graph workspace.
Need more help?
If you run into trouble connecting, or you're curious whether a particular question is something the MCP server can answer, reach out to our support team through the in-app messenger or contact your Customer Success Manager. We're happy to help you get the most out of your compliance data.