SCARLET RISK

Setup guide

Connect Claude or ChatGPT
to your own compliance data.

Scarlet Risk runs a live MCP server. Add one URL to your AI tool, sign in with your Scarlet Risk account, and your assistant can answer questions from your real risk register, policies, vendors and checklist — and, if you allow it, take action.

The server

Your MCP endpoint

https://scarletrisk.com/mcp

It speaks MCP over streamable HTTP and is protected by OAuth 2.1 — there is no API key to copy, paste or leak. Your AI tool registers itself, you sign in as you normally would, and the connection is bound to your user account only.

Step by step

Setting it up

  1. 1

    Turn on AI tool access in Scarlet Risk

    Sign in and go to Settings → AI tool access (MCP). Access is off by default and is authorized per person — enabling it for yourself never enables it for anyone else on the account. Click Authorize under Read access.
  2. 2

    Decide on write / action access

    Write access is a separate, explicit switch. Leave it off and your assistant can only describe your program. Turn it on and it can regenerate registers, run vendor assessments, generate policies and update self-attested checklist items. Checklist items confirmed from real artifacts stay locked either way.
  3. 3

    Add the server in Claude

    In Claude, open Settings → Connectors → Add custom connector, paste https://scarletrisk.com/mcp and save. Claude opens a browser window for OAuth.
  4. 4

    Add the server in ChatGPT

    In ChatGPT, open Settings → Connectors → Create (or add an MCP server in a custom GPT / Deep Research connector), paste the same URL, and choose OAuth as the authentication method.
  5. 5

    Complete the OAuth sign-in

    You'll be sent to Scarlet Risk to sign in, then shown a consent screen naming the client asking for access. Approve it once. Tokens are short-lived and refresh automatically; you never handle a secret.
  6. 6

    Ask your first question

    Try "What are my open critical risks?", "Summarize my SOC 2 gap analysis" or "Which vendors are rated yellow or red and why?". For actions, be explicit: "Regenerate my risk register".
  7. 7

    Check the connection any time

    Settings → AI tool access → Connection diagnostics & activity log shows connection health, the last call, which tools are exposed, and a timestamped log of every read and write — including which client made the call and what changed.

What your assistant can do

The tools

Read tools

  • list_risks / get_riskYour risk register — every risk, severity, owner and status.
  • get_compliance_scoreCurrent compliance score plus the gap analysis behind it.
  • list_vendors / get_vendorVendor assessments, ratings and the reasoning behind each.
  • list_policies / get_policyYour policy library and the full text of any generated policy.
  • get_incident_response_planThe IR plan generated for your account.
  • get_security_quiz_statusSecurity awareness quiz completion across your team.
  • get_cyber_checklistChecklist progress, with confirmed vs. self-attested clearly marked.
  • get_credential_exposureBreach / credential exposure findings for your domains.

Write / action tools

Only available once write access is explicitly authorized. Every call is logged.

  • refresh_risk_registerRegenerates your risk register from current account data.
  • assess_vendorRuns a new assessment for a vendor you name.
  • generate_policiesGenerates or regenerates a policy document.
  • update_checklist_itemUpdates a self-attested checklist item. Items confirmed from real artifacts stay locked.

Good to know

Boundaries and troubleshooting

  • Your data only. Every tool runs as you, under the same row-level security as the app. One account can never read another's data.
  • Confirmed stays confirmed. Anything labelled AI-inferred or self-attested in your dashboard is labelled the same way to your AI tool. Nothing gets upgraded to certainty in translation.
  • Getting "access has not been authorized"? Read access is off — enable it in Settings → AI tool access.
  • Tools not showing up? Remove and re-add the connector so it re-runs discovery, then check the diagnostics page for the last call.
  • Revoking is instant. Hit Revoke in Settings and connected tools are refused on their next call — no need to delete the connector first.

Need deeper permissions, a specific workflow or a unique integration? Get in touch.

Stop guessing.
Start knowing.

AI-powered risk intelligence that shows you exactly where you're exposed — and what to do about it. Live in minutes.

Get started