Security
Orca Security MCP connector
The Orca Security connector brings your cloud alerts, assets, vulnerabilities, cloud accounts and scans to Claude, ChatGPT, Cursor and the Elaichi Agent, so each person can ask about and act on Orca Security findings inside their own access.
-
How it connects. Connects with an API key. The credential goes into a vault nobody reads back.
-
One address. https://api.elaichi.ai/mcp, the same for every user.
-
Their own access. An agent never gets more than the person it acts for.
How to connect
How to connect Orca Security to Claude, ChatGPT or Cursor
Two steps, about a minute.
In Elaichi
Connect Orca Security once
-
Open Connections, choose Add connection, and pick Orca Security.
-
Optionally set Share with to give a team access, then press Connect.
-
Paste an Orca Security API key. One person generates a token in Orca Security and pastes it once. Everyone else works through Share with, and never sees it.
The credential is vaulted. Nobody reads it back, not even the AI.
Add connection
Choose a connector.
In your AI client
Point it at one endpoint
Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.
Connect Orca Security to Claude
-
1
Open Customize, then Connectors.
-
2
Press Add.
-
3
Name it, paste the MCP server URL, then Continue.
https://api.elaichi.ai/mcp -
4
Sign in and approve.
On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.
Connect Orca Security to ChatGPT
-
1
Open Plugins, then press the + button.
-
2
Name it and paste the endpoint into Server URL.
https://api.elaichi.ai/mcp -
3
Leave Authentication on OAuth, then tick the risk acknowledgement.
-
4
Press Create, then sign in and approve.
Works on the web today. The plugin directory lives at chatgpt.com/plugins.
Connect Orca Security to Cursor
-
1
Open
~/.cursor/mcp.json. -
2
Add the endpoint under
mcpServers.https://api.elaichi.ai/mcp -
3
Reload Cursor, then sign in and approve.
~/.cursor/mcp.json
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
Set up per machine, so repeat it on each computer you work from.
Connect Orca Security to any MCP client
-
1
Add the endpoint as a remote MCP server.
https://api.elaichi.ai/mcp -
2
Sign in and approve.
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
The Elaichi Agent already has these tools, with nothing to set up.
Use cases
What teams do with Orca Security through Elaichi
Every one of these runs inside the access the person already has, and lands in the same audit log.
-
Security operations
Triage this morning's alerts
Ask for the open Orca Security alerts on production accounts, sorted by severity, and get the event log and recommended remediation for the ones that matter.
-
Cloud engineering
Find what a vulnerability actually touches
Ask which assets carry a given CVE and which cloud accounts they sit in, then read the remediation steps before opening a change.
-
Incident response
Pull the full story behind one alert
Get a single Orca Security alert with its event history, malware findings and linked Jira ticket in one place while the call is still going.
-
Compliance
Check coverage across cloud accounts
List every connected AWS and GCP account in Orca Security, see which are scanned, and spot the ones with outstanding remediation before an audit.
-
Platform engineering
Kick off a scan after a deploy
Start an Orca Security scan on a new environment or a vendor's asset and check the result later without leaving the tool you are working in.
-
Security leadership
Summarize risk for the weekly review
Ask for a plain-language rundown of alert counts by severity and account, with the assets driving the most findings, ready to paste into a report.
Try asking
- “Show high severity Orca Security alerts opened this week.”
- “Which cloud accounts have the most open vulnerabilities?”
- “List remediation actions for critical alerts on production assets.”
AI tools
Orca Security tools for your AI agents
40 tools are ready to call through Elaichi's MCP endpoint the moment you connect Orca Security, governed by the same roles, restrictions, and audit log as everything else in Elaichi.
No tools match your search.
See it in Elaichi
What connecting Orca Security gets you
6 screens from the product, each doing one job for your Orca Security account.
The agent
Ask about Orca Security alerts in plain language.
The agent answers from live alerts, assets and cloud accounts, no query syntax.
- alerts
- assets
- cloud accounts
- vulnerabilities
Ask Elaichi to work across your apps.
Show high severity Orca Security alerts opened this week.
Which cloud accounts have the most open vulnerabilities?
List remediation actions for critical alerts on production assets.
Also runs in Claude, ChatGPT or Cursor
MCP clients
Claude, ChatGPT and Cursor reach Orca Security.
One org MCP endpoint over OAuth, no SDK and no shared API key.
Copy the endpoint
Tool catalog
40 Orca Security tools, ready on connect.
Alerts, vulnerabilities, remediation actions, assets and cloud accounts, with no custom code.
- List all Orca Security alerts
- Get single Orca Security alert by ID
- Orca Security alerts event logs
- Orca Security alerts state
Toolboxes
Each team gets its own Orca Security toolbox.
Curate one toolbox per team so people see the tools their work needs.
- Security operations
- Cloud platform
- Vulnerability management
- Compliance
Shared connections
Share an Orca Security account, never the key.
See who connected each account and how many teams and members use it.
- Security operations
- Cloud platform
- Compliance
- Incident response
Audit log
Every Orca Security call is on the record.
When, who, what happened, type and resource, in an append only log.
- When
- Who
- What happened
- Type
Launching soon
From answering questions to doing the work
A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.
Automations
A schedule turns Orca Security alerts into action.
Fetch alerts, group them, draft a digest, get approval, post back to Orca Security.
Orca Security digest
Run 418 · started 2 minutes ago · on behalf of Emma Laurent
-
✓
Schedule
Every weekday at 08:00
0.2s -
✓
Fetch alerts
Orca Security
1.4s -
✓
Group by owner
Transform
0.1s -
✓
Draft the digest
Agent step
Ran with 4 tools, returned a structured summary
6.2s -
Approve the digest
Needs approval
Assigned to Michael Brennan
Approve Deny -
Post the digest
Orca Security
Queued
Collections and dashboards
Orca Security health, counted on a schedule.
Four metrics, 14 days of alerts created, and a breakdown by team.
Orca Security health
Refreshed 4 minutes ago · every 15 minutes · from the alerts collection
Alerts
1,284 ↓ 12%
Assets
96 ↓ 8%
Needs attention
3 ↑ 2
Updated this week
412 ↑ 9%
Alerts created
Last 14 days
By team
Share of activity
Security operations 34%
Cloud platform 27%
Compliance 21%
Incident response 18%
Related connectors
More from the catalog
FAQ
Frequently asked questions
How do I connect Orca Security to Claude?
Two steps. In Elaichi, choose Orca Security and paste in your Orca Security API key, which is the only sign-in step, with no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Claude signs you in through Elaichi and Orca Security is ready to use.
Does Orca Security work with ChatGPT and Cursor as well as Claude?
Yes. Once Orca Security is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Orca Security once and every client picks it up.
What can an AI agent actually do with my Orca Security data?
An agent can list and read Orca Security alerts, pull an alert's event log, vulnerabilities, malware findings, remediation actions and linked Jira ticket, browse your assets and cloud accounts, and start or check a scan. It cannot do anything the connector does not cover, and it cannot do anything the signed-in person could not do in Orca Security. Because Orca Security has many actions, short concrete asks such as "critical alerts on the payments account" get better results than long paragraphs.
Does connecting Orca Security give the AI every cloud account and alert?
No. Access follows the person who signed in, so the agent sees the Orca Security cloud accounts, assets and alerts that person's own Orca Security account can see, and nothing beyond it. Elaichi can narrow that further, for example to read-only or to a subset of actions, but it can never widen access past what Orca Security already grants.
Can I stop an agent from changing or deleting things in Orca Security?
Yes. Restrictions in Elaichi work per action, so you can allow reading Orca Security alerts and assets while blocking starting scans or changing alert state. A blocked action is never advertised to Claude, ChatGPT, Cursor or any other client, so no prompt, however worded, can reach it.
What happens to an Orca Security connection when someone leaves?
Offboarding a person in Elaichi ends their access to Orca Security through every client at once, with no need to touch Orca Security itself. If they were using a shared Orca Security connection, it keeps working for everyone else on the team. Disconnecting Orca Security once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client at the same time.
Put Orca Security in front of your team
Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.