Security
SecurityScorecard MCP connector
The SecurityScorecard connector brings your vendor portfolios, the companies in them, their expanded risk findings, and scorecard tags into Claude, ChatGPT, Cursor, or any MCP client, with every action tied to the person who signed in.
-
How it connects. Connects with an API key. The credential goes into a vault nobody reads back.
-
One address. https://api.elaichi.ai/mcp, the same for every user.
-
Their own access. An agent never gets more than the person it acts for.
How to connect
How to connect SecurityScorecard to Claude, ChatGPT or Cursor
Two steps, about a minute.
In Elaichi
Connect SecurityScorecard once
-
Open Connections, choose Add connection, and pick SecurityScorecard.
-
Optionally set Share with to give a team access, then press Connect.
-
Paste a SecurityScorecard API key. One person generates a token in SecurityScorecard and pastes it once. Everyone else works through Share with, and never sees it.
The credential is vaulted. Nobody reads it back, not even the AI.
Add connection
Choose a connector.
In your AI client
Point it at one endpoint
Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.
Connect SecurityScorecard to Claude
-
1
Open Customize, then Connectors.
-
2
Press Add.
-
3
Name it, paste the MCP server URL, then Continue.
https://api.elaichi.ai/mcp -
4
Sign in and approve.
On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.
Connect SecurityScorecard to ChatGPT
-
1
Open Plugins, then press the + button.
-
2
Name it and paste the endpoint into Server URL.
https://api.elaichi.ai/mcp -
3
Leave Authentication on OAuth, then tick the risk acknowledgement.
-
4
Press Create, then sign in and approve.
Works on the web today. The plugin directory lives at chatgpt.com/plugins.
Connect SecurityScorecard to Cursor
-
1
Open
~/.cursor/mcp.json. -
2
Add the endpoint under
mcpServers.https://api.elaichi.ai/mcp -
3
Reload Cursor, then sign in and approve.
~/.cursor/mcp.json
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
Set up per machine, so repeat it on each computer you work from.
Connect SecurityScorecard to any MCP client
-
1
Add the endpoint as a remote MCP server.
https://api.elaichi.ai/mcp -
2
Sign in and approve.
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
The Elaichi Agent already has these tools, with nothing to set up.
Use cases
What teams do with SecurityScorecard through Elaichi
Every one of these runs inside the access the person already has, and lands in the same audit log.
-
Third-party risk
Review a vendor portfolio before the quarterly meeting
Ask for every company in a SecurityScorecard portfolio along with its open risk findings, then get a plain summary of which vendors need a conversation this quarter.
-
Security
Add new vendors to the right portfolio
After a contract is signed, add the vendor to the correct SecurityScorecard portfolio, tag it by business unit and criticality, and move on without opening a spreadsheet.
-
Procurement
Tag vendors by contract owner and renewal date
Create scorecard tags for contract owners and renewal windows, attach them to the right companies, and pull the list of vendors coming up for renewal when it is time to negotiate.
-
Compliance
Pull risk findings for the audit binder
List the expanded risk findings across a portfolio of in-scope vendors and turn them into the evidence an auditor asks for, in the wording the auditor expects.
-
Security
Clean up portfolios after a reorganization
Move companies between SecurityScorecard portfolios in bulk, rename portfolios to match the new team structure, and retire the ones nobody owns anymore.
-
IT
Keep tag groups tidy across the organization
Group related scorecard tags, rename or merge the ones that drifted, and remove tags that are no longer used so every team is describing vendors the same way.
Try asking
- “List the lowest scoring companies in our vendor portfolio.”
- “Show new expanded risks added this week.”
- “Which scorecard tags have the most flagged companies.”
AI tools
SecurityScorecard tools for your AI agents
405 tools are ready to call through Elaichi's MCP endpoint the moment you connect SecurityScorecard, governed by the same roles, restrictions, and audit log as everything else in Elaichi.
No tools match your search.
See it in Elaichi
What connecting SecurityScorecard gets you
6 screens from the product, each doing one job for your SecurityScorecard account.
The agent
Ask for scores, get straight answers.
Type a plain question and pull live ratings and risk factors from SecurityScorecard portfolios.
- portfolios
- companies
- scorecard tags
- expanded risks
Ask Elaichi to work across your apps.
List the lowest scoring companies in our vendor portfolio.
Show new expanded risks added this week.
Which scorecard tags have the most flagged companies.
Also runs in Claude, ChatGPT or Cursor
MCP clients
One endpoint, every client, no api keys.
Claude, chatgpt and cursor all reach SecurityScorecard through a single governed org endpoint.
Copy the endpoint
Tool catalog
405 SecurityScorecard tools, zero custom code.
Portfolios, tags, companies and bulk actions, all cataloged and ready to call.
- List all SecurityScorecard portfolios
- Create a SecurityScorecard portfolio
- Update a SecurityScorecard portfolio by ID
- Delete a SecurityScorecard portfolio by ID
Toolboxes
Every team gets its own toolbox.
Security, IT and vendor risk each work from a toolbox scoped to their team.
- Security
- Vendor risk
- IT
- Compliance
Shared connections
Shared access, no shared credentials.
See who connected each SecurityScorecard account and how many teams and members use it.
- Vendor Risk
- Enterprise Security
- Third Party
- Compliance
Audit log
Every call, logged and attributable.
See who touched which portfolio or scorecard tag, and exactly when.
- When
- Who
- What happened
- Type
Launching soon
From answering questions to doing the work
A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.
Automations
A schedule starts the work, a person approves it.
Records fetch, group into a digest, then wait for approval before posting back to SecurityScorecard.
SecurityScorecard digest
Run 418 · started 2 minutes ago · on behalf of Emma Laurent
-
✓
Schedule
Every weekday at 08:00
0.2s -
✓
Fetch portfolios
SecurityScorecard
1.4s -
✓
Group by owner
Transform
0.1s -
✓
Draft the digest
Agent step
Ran with 4 tools, returned a structured summary
6.2s -
Approve the digest
Needs approval
Assigned to Michael Brennan
Approve Deny -
Post the digest
SecurityScorecard
Queued
Collections and dashboards
Scorecard health, computed, not asked for.
Four metrics and a 14 day trend on records created, broken down by team.
SecurityScorecard health
Refreshed 4 minutes ago · every 15 minutes · from the portfolios collection
Portfolios
1,284 ↓ 12%
Companies
96 ↓ 8%
Needs attention
3 ↑ 2
Updated this week
412 ↑ 9%
Portfolios created
Last 14 days
By team
Share of activity
Vendor Risk 34%
Enterprise Security 27%
Third Party 21%
Compliance 18%
Related connectors
More from the catalog
FAQ
Frequently asked questions
How do I connect SecurityScorecard to Claude?
Connect SecurityScorecard in Elaichi first: you paste an API key generated in your SecurityScorecard account, and there is no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Claude asks you to sign in to Elaichi as yourself, and from then on your SecurityScorecard portfolios, companies, and tags are available in the conversation.
Does SecurityScorecard work with ChatGPT and Cursor as well as Claude?
Yes. Once SecurityScorecard is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect SecurityScorecard once and every client you use picks it up.
What can an AI agent actually do with my SecurityScorecard data?
With SecurityScorecard connected, an agent can list your portfolios and the companies in each one, pull the expanded risk findings for a portfolio, and create, rename, or remove portfolios. It can also add companies to portfolios in bulk, create and organize scorecard tags and tag groups, and attach tags to companies or remove them. SecurityScorecard exposes a large number of actions, so short concrete asks such as "list the companies in the Critical Vendors portfolio" work better than long paragraphs.
Does connecting SecurityScorecard give the AI every portfolio in my account?
No. An agent working through SecurityScorecard sees only what the API key you connected is allowed to see, and everything it does runs inside that access. Elaichi can narrow that further with restrictions per team or per action, but it can never widen it beyond what SecurityScorecard itself grants.
Can I stop an agent from deleting or changing things in SecurityScorecard?
Yes. In Elaichi, restrictions on the SecurityScorecard connection work per action, so you can allow listing portfolios and risk findings while blocking deletions or bulk changes to companies and tags. A blocked action is never advertised to Claude, ChatGPT, Cursor, or any other client, so no prompt, accidental or otherwise, can reach it.
What happens to a SecurityScorecard connection when someone leaves?
Offboarding a person in Elaichi ends their access to SecurityScorecard at once, across every client they used. If they had shared a SecurityScorecard connection with a team, it keeps working for everyone else on that team. If you want SecurityScorecard gone entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client at the same time.
Put SecurityScorecard in front of your team
Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.