Skip to content

Security

Orca Security MCP connector

The Orca Security connector brings your cloud alerts, assets, vulnerabilities, cloud accounts and scans to Claude, ChatGPT, Cursor and the Elaichi Agent, so each person can ask about and act on Orca Security findings inside their own access.

  • How it connects. Connects with an API key. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Orca Security to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Orca Security once

  1. Open Connections, choose Add connection, and pick Orca Security.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste an Orca Security API key. One person generates a token in Orca Security and pastes it once. Everyone else works through Share with, and never sees it.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

orca security
Orca Security
Censys
Herd Security
Infisical
SecurityScorecard
Semgrep
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Connect Orca Security to Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Connect Orca Security to ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Connect Orca Security to Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Orca Security to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Orca Security through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Security operations

    Triage this morning's alerts

    Ask for the open Orca Security alerts on production accounts, sorted by severity, and get the event log and recommended remediation for the ones that matter.

  • Cloud engineering

    Find what a vulnerability actually touches

    Ask which assets carry a given CVE and which cloud accounts they sit in, then read the remediation steps before opening a change.

  • Incident response

    Pull the full story behind one alert

    Get a single Orca Security alert with its event history, malware findings and linked Jira ticket in one place while the call is still going.

  • Compliance

    Check coverage across cloud accounts

    List every connected AWS and GCP account in Orca Security, see which are scanned, and spot the ones with outstanding remediation before an audit.

  • Platform engineering

    Kick off a scan after a deploy

    Start an Orca Security scan on a new environment or a vendor's asset and check the result later without leaving the tool you are working in.

  • Security leadership

    Summarize risk for the weekly review

    Ask for a plain-language rundown of alert counts by severity and account, with the assets driving the most findings, ready to paste into a report.

Try asking

  • “Show high severity Orca Security alerts opened this week.”
  • “Which cloud accounts have the most open vulnerabilities?”
  • “List remediation actions for critical alerts on production assets.”

See all 40 Orca Security tools below

AI tools

Orca Security tools for your AI agents

40 tools are ready to call through Elaichi's MCP endpoint the moment you connect Orca Security, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Orca Security gets you

6 screens from the product, each doing one job for your Orca Security account.

The agent

Ask about Orca Security alerts in plain language.

The agent answers from live alerts, assets and cloud accounts, no query syntax.

  • alerts
  • assets
  • cloud accounts
  • vulnerabilities

Ask Elaichi to work across your apps.

Show high severity Orca Security alerts opened this week.

Which cloud accounts have the most open vulnerabilities?

List remediation actions for critical alerts on production assets.

Also runs in Claude, ChatGPT or Cursor

MCP clients

Claude, ChatGPT and Cursor reach Orca Security.

One org MCP endpoint over OAuth, no SDK and no shared API key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emma Laurent

• Connected 4 minutes ago
Cursor
S

Sofia Ricci

• Connected 2 hours ago
ChatGPT
C

Clara Nowak

• Connected Yesterday

Tool catalog

40 Orca Security tools, ready on connect.

Alerts, vulnerabilities, remediation actions, assets and cloud accounts, with no custom code.

  • List all Orca Security alerts
  • Get single Orca Security alert by ID
  • Orca Security alerts event logs
  • Orca Security alerts state
ElaichiTools
Tool Action Description
List all Orca Security alerts List Retrieve alerts from Orca Security. The response provides detailed information about the retrieved alerts, including their attributes and related data.
Get single Orca Security alert by ID Get Retrieves details of a specific alert identified by its id from Orca Security. The response contains information related to the alert, including remediation details, compliance status, asset details, and more.
Orca Security alerts event logs Action Use this endpoint to retrieve the event log for a specific alert by providing the alert_id. The response includes a list of events related to that alert, along with metadata for each event.
Orca Security alerts state Action Use this endpoint to retrieve the current state of a specific alert identified by its alert_id. The response includes detailed information such as the alert's severity, rule source, timestamps for creation and last update, verification status, risk level, Orca score, current status, and more.
List all Orca Security alerts scheme List Retrieves a list of alerts and their details from Orca Security. The response includes an array of "alerts" with attributes such as type, rule information, compliance status, asset details, severity, cloud provider information, connectivity details, vulnerabilities, etc.

Toolboxes

Each team gets its own Orca Security toolbox.

Curate one toolbox per team so people see the tools their work needs.

  • Security operations
  • Cloud platform
  • Vulnerability management
  • Compliance
ElaichiToolboxes
Name Source template Tools Created

Security operations toolbox

Orca Security · alerts and triage

Orca Security starter 18 Mar 4, 2026

Cloud platform toolbox

Orca Security · cloud accounts and assets

9 Mar 2, 2026

Vulnerability management toolbox

Orca Security · vulnerabilities and remediation actions

24 Feb 27, 2026

Compliance toolbox

Orca Security · asset coverage and evidence

Orca Security starter 6 Feb 19, 2026

Incident response toolbox

Orca Security · alert event logs and states

31 Jan 30, 2026

Engineering leads toolbox

Orca Security · open findings by service

12 Jan 22, 2026

Shared connections

Share an Orca Security account, never the key.

See who connected each account and how many teams and members use it.

  • Security operations
  • Cloud platform
  • Compliance
  • Incident response
ElaichiConnections
Connection Scope Status Access
OR

Orca Security (Security operations)

Connected by Emma Laurent

Personal • Active 1 team · 6 members
OR

Orca Security (Cloud platform)

Connected by James Whitfield

Organization • Active 3 teams · 24 members
OR

Orca Security (Compliance)

Connected by Sofia Ricci

Organization • Active 2 teams · 11 members
OR

Orca Security (Incident response)

Connected by Daniel Ortega

Personal • Needs re-auth 1 team · 3 members
OR

Orca Security (Production accounts)

Connected by Clara Nowak

Personal • Active Not shared
OR

Orca Security (Sandbox accounts)

Connected by Michael Brennan

Personal • Active 2 teams · 9 members

Audit log

Every Orca Security call is on the record.

When, who, what happened, type and resource, in an append only log.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emma Laurent

[email protected]

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

James Whitfield

[email protected]

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

S

Sofia Ricci

[email protected]

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

D

Daniel Ortega

[email protected]

Orca Security Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

C

Clara Nowak

[email protected]

Orca Security Alerts Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

M

Michael Brennan

[email protected]

Orca Security Alerts List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule turns Orca Security alerts into action.

Fetch alerts, group them, draft a digest, get approval, post back to Orca Security.

Orca Security digest

Run 418 · started 2 minutes ago · on behalf of Emma Laurent

  1. Schedule

    Every weekday at 08:00

    0.2s
  2. Fetch alerts

    Orca Security

    1.4s
  3. Group by owner

    Transform

    0.1s
  4. Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Orca Security

    Queued

Collections and dashboards

Orca Security health, counted on a schedule.

Four metrics, 14 days of alerts created, and a breakdown by team.

Orca Security health

Refreshed 4 minutes ago · every 15 minutes · from the alerts collection

Live

Alerts

1,284 ↓ 12%

Assets

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Alerts created

Last 14 days

By team

Share of activity

Security operations 34%

Cloud platform 27%

Compliance 21%

Incident response 18%

FAQ

Frequently asked questions

How do I connect Orca Security to Claude?

Two steps. In Elaichi, choose Orca Security and paste in your Orca Security API key, which is the only sign-in step, with no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Claude signs you in through Elaichi and Orca Security is ready to use.

Does Orca Security work with ChatGPT and Cursor as well as Claude?

Yes. Once Orca Security is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Orca Security once and every client picks it up.

What can an AI agent actually do with my Orca Security data?

An agent can list and read Orca Security alerts, pull an alert's event log, vulnerabilities, malware findings, remediation actions and linked Jira ticket, browse your assets and cloud accounts, and start or check a scan. It cannot do anything the connector does not cover, and it cannot do anything the signed-in person could not do in Orca Security. Because Orca Security has many actions, short concrete asks such as "critical alerts on the payments account" get better results than long paragraphs.

Does connecting Orca Security give the AI every cloud account and alert?

No. Access follows the person who signed in, so the agent sees the Orca Security cloud accounts, assets and alerts that person's own Orca Security account can see, and nothing beyond it. Elaichi can narrow that further, for example to read-only or to a subset of actions, but it can never widen access past what Orca Security already grants.

Can my team share one Orca Security connection?

Yes. One person connects Orca Security in Elaichi and shares the connection with a team, and nobody else ever handles the API key. Each teammate still signs in to Elaichi as themselves, so every Orca Security call in the audit log names the person who made it, not the person who connected it.

Can I stop an agent from changing or deleting things in Orca Security?

Yes. Restrictions in Elaichi work per action, so you can allow reading Orca Security alerts and assets while blocking starting scans or changing alert state. A blocked action is never advertised to Claude, ChatGPT, Cursor or any other client, so no prompt, however worded, can reach it.

What happens to an Orca Security connection when someone leaves?

Offboarding a person in Elaichi ends their access to Orca Security through every client at once, with no need to touch Orca Security itself. If they were using a shared Orca Security connection, it keeps working for everyone else on the team. Disconnecting Orca Security once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client at the same time.

Put Orca Security in front of your team

Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.