Setup guide
Connect Claude or ChatGPT
to your own compliance data.
Scarlet Risk runs a live MCP server. Add one URL to your AI tool, sign in with your Scarlet Risk account, and your assistant can answer questions from your real risk register, policies, vendors and checklist — and, if you allow it, take action.
The server
Your MCP endpoint
https://scarletrisk.com/mcpIt speaks MCP over streamable HTTP and is protected by OAuth 2.1 — there is no API key to copy, paste or leak. Your AI tool registers itself, you sign in as you normally would, and the connection is bound to your user account only.
Step by step
Setting it up
- 1
Turn on AI tool access in Scarlet Risk
Sign in and go to Settings → AI tool access (MCP). Access is off by default and is authorized per person — enabling it for yourself never enables it for anyone else on the account. Click Authorize under Read access. - 2
Decide on write / action access
Write access is a separate, explicit switch. Leave it off and your assistant can only describe your program. Turn it on and it can regenerate registers, run vendor assessments, generate policies and update self-attested checklist items. Checklist items confirmed from real artifacts stay locked either way. - 3
Add the server in Claude
In Claude, open Settings → Connectors → Add custom connector, pastehttps://scarletrisk.com/mcpand save. Claude opens a browser window for OAuth. - 4
Add the server in ChatGPT
In ChatGPT, open Settings → Connectors → Create (or add an MCP server in a custom GPT / Deep Research connector), paste the same URL, and choose OAuth as the authentication method. - 5
Complete the OAuth sign-in
You'll be sent to Scarlet Risk to sign in, then shown a consent screen naming the client asking for access. Approve it once. Tokens are short-lived and refresh automatically; you never handle a secret. - 6
Ask your first question
Try "What are my open critical risks?", "Summarize my SOC 2 gap analysis" or "Which vendors are rated yellow or red and why?". For actions, be explicit: "Regenerate my risk register". - 7
Check the connection any time
Settings → AI tool access → Connection diagnostics & activity log shows connection health, the last call, which tools are exposed, and a timestamped log of every read and write — including which client made the call and what changed.
What your assistant can do
The tools
Read tools
list_risks / get_riskYour risk register — every risk, severity, owner and status.get_compliance_scoreCurrent compliance score plus the gap analysis behind it.list_vendors / get_vendorVendor assessments, ratings and the reasoning behind each.list_policies / get_policyYour policy library and the full text of any generated policy.get_incident_response_planThe IR plan generated for your account.get_security_quiz_statusSecurity awareness quiz completion across your team.get_cyber_checklistChecklist progress, with confirmed vs. self-attested clearly marked.get_credential_exposureBreach / credential exposure findings for your domains.
Write / action tools
Only available once write access is explicitly authorized. Every call is logged.
refresh_risk_registerRegenerates your risk register from current account data.assess_vendorRuns a new assessment for a vendor you name.generate_policiesGenerates or regenerates a policy document.update_checklist_itemUpdates a self-attested checklist item. Items confirmed from real artifacts stay locked.
Good to know
Boundaries and troubleshooting
- Your data only. Every tool runs as you, under the same row-level security as the app. One account can never read another's data.
- Confirmed stays confirmed. Anything labelled AI-inferred or self-attested in your dashboard is labelled the same way to your AI tool. Nothing gets upgraded to certainty in translation.
- Getting "access has not been authorized"? Read access is off — enable it in Settings → AI tool access.
- Tools not showing up? Remove and re-add the connector so it re-runs discovery, then check the diagnostics page for the last call.
- Revoking is instant. Hit Revoke in Settings and connected tools are refused on their next call — no need to delete the connector first.
Need deeper permissions, a specific workflow or a unique integration? Get in touch.
Stop guessing.
Start knowing.
AI-powered risk intelligence that shows you exactly where you're exposed — and what to do about it. Live in minutes.
Get started