Skip to content

Security

SecurityScorecard MCP connector

The SecurityScorecard connector brings your vendor portfolios, the companies in them, their expanded risk findings, and scorecard tags into Claude, ChatGPT, Cursor, or any MCP client, with every action tied to the person who signed in.

  • How it connects. Connects with an API key. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect SecurityScorecard to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect SecurityScorecard once

  1. Open Connections, choose Add connection, and pick SecurityScorecard.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste a SecurityScorecard API key. One person generates a token in SecurityScorecard and pastes it once. Everyone else works through Share with, and never sees it.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

securityscorecard
SecurityScorecard
Censys
Herd Security
Infisical
Orca Security
Semgrep
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Connect SecurityScorecard to Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Connect SecurityScorecard to ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Connect SecurityScorecard to Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect SecurityScorecard to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with SecurityScorecard through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Third-party risk

    Review a vendor portfolio before the quarterly meeting

    Ask for every company in a SecurityScorecard portfolio along with its open risk findings, then get a plain summary of which vendors need a conversation this quarter.

  • Security

    Add new vendors to the right portfolio

    After a contract is signed, add the vendor to the correct SecurityScorecard portfolio, tag it by business unit and criticality, and move on without opening a spreadsheet.

  • Procurement

    Tag vendors by contract owner and renewal date

    Create scorecard tags for contract owners and renewal windows, attach them to the right companies, and pull the list of vendors coming up for renewal when it is time to negotiate.

  • Compliance

    Pull risk findings for the audit binder

    List the expanded risk findings across a portfolio of in-scope vendors and turn them into the evidence an auditor asks for, in the wording the auditor expects.

  • Security

    Clean up portfolios after a reorganization

    Move companies between SecurityScorecard portfolios in bulk, rename portfolios to match the new team structure, and retire the ones nobody owns anymore.

  • IT

    Keep tag groups tidy across the organization

    Group related scorecard tags, rename or merge the ones that drifted, and remove tags that are no longer used so every team is describing vendors the same way.

Try asking

  • “List the lowest scoring companies in our vendor portfolio.”
  • “Show new expanded risks added this week.”
  • “Which scorecard tags have the most flagged companies.”

See all 405 SecurityScorecard tools below

AI tools

SecurityScorecard tools for your AI agents

405 tools are ready to call through Elaichi's MCP endpoint the moment you connect SecurityScorecard, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting SecurityScorecard gets you

6 screens from the product, each doing one job for your SecurityScorecard account.

The agent

Ask for scores, get straight answers.

Type a plain question and pull live ratings and risk factors from SecurityScorecard portfolios.

  • portfolios
  • companies
  • scorecard tags
  • expanded risks

Ask Elaichi to work across your apps.

List the lowest scoring companies in our vendor portfolio.

Show new expanded risks added this week.

Which scorecard tags have the most flagged companies.

Also runs in Claude, ChatGPT or Cursor

MCP clients

One endpoint, every client, no api keys.

Claude, chatgpt and cursor all reach SecurityScorecard through a single governed org endpoint.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emma Laurent

• Connected 4 minutes ago
Cursor
S

Sofia Ricci

• Connected 2 hours ago
ChatGPT
C

Clara Nowak

• Connected Yesterday

Tool catalog

405 SecurityScorecard tools, zero custom code.

Portfolios, tags, companies and bulk actions, all cataloged and ready to call.

  • List all SecurityScorecard portfolios
  • Create a SecurityScorecard portfolio
  • Update a SecurityScorecard portfolio by ID
  • Delete a SecurityScorecard portfolio by ID
ElaichiTools
Tool Action Description
List all SecurityScorecard portfolios List List SecurityScorecard portfolios. Returns: id, name, description, privacy, team_id.
Create a SecurityScorecard portfolio Create Create a SecurityScorecard portfolio with a name, description, and privacy level. Returns: id, name, description, privacy, team_id. Required: name.
Update a SecurityScorecard portfolio by ID Update Update a SecurityScorecard portfolio by id. Returns: id, name, description, privacy, team_id. Required: id, name.
Delete a SecurityScorecard portfolio by ID Delete Delete a SecurityScorecard portfolio by id. Returns an empty 204 response on success. Required: id.
SecurityScorecard companies bulk uploads bulk update Update Bulk upload companies to SecurityScorecard portfolios via a PUT request. Returns a list of the uploaded companies following processing. Provide a JSON request body containing the companies to add.

Toolboxes

Every team gets its own toolbox.

Security, IT and vendor risk each work from a toolbox scoped to their team.

  • Security
  • Vendor risk
  • IT
  • Compliance
ElaichiToolboxes
Name Source template Tools Created

Security toolbox

SecurityScorecard · scores and risk factors

SecurityScorecard starter 18 Mar 4, 2026

Vendor risk toolbox

SecurityScorecard · third party portfolios

9 Mar 2, 2026

IT toolbox

SecurityScorecard · remediation tracking

24 Feb 27, 2026

Compliance toolbox

SecurityScorecard · scorecard tags and reporting

SecurityScorecard starter 6 Feb 19, 2026

Procurement toolbox

SecurityScorecard · vendor onboarding checks

31 Jan 30, 2026

Executive toolbox

SecurityScorecard · portfolio summaries

12 Jan 22, 2026

Shared connections

Shared access, no shared credentials.

See who connected each SecurityScorecard account and how many teams and members use it.

  • Vendor Risk
  • Enterprise Security
  • Third Party
  • Compliance
ElaichiConnections
Connection Scope Status Access
SE

SecurityScorecard (Vendor Risk)

Connected by Emma Laurent

Personal • Active 1 team · 6 members
SE

SecurityScorecard (Enterprise Security)

Connected by James Whitfield

Organization • Active 3 teams · 24 members
SE

SecurityScorecard (Third Party)

Connected by Sofia Ricci

Organization • Active 2 teams · 11 members
SE

SecurityScorecard (Compliance)

Connected by Daniel Ortega

Personal • Needs re-auth 1 team · 3 members
SE

SecurityScorecard (IT Ops)

Connected by Clara Nowak

Personal • Active Not shared
SE

SecurityScorecard (Procurement)

Connected by Michael Brennan

Personal • Active 2 teams · 9 members

Audit log

Every call, logged and attributable.

See who touched which portfolio or scorecard tag, and exactly when.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emma Laurent

[email protected]

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

James Whitfield

[email protected]

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

S

Sofia Ricci

[email protected]

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

D

Daniel Ortega

[email protected]

SecurityScorecard Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

C

Clara Nowak

[email protected]

SecurityScorecard Portfolios Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

M

Michael Brennan

[email protected]

SecurityScorecard Portfolios List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule starts the work, a person approves it.

Records fetch, group into a digest, then wait for approval before posting back to SecurityScorecard.

SecurityScorecard digest

Run 418 · started 2 minutes ago · on behalf of Emma Laurent

  1. Schedule

    Every weekday at 08:00

    0.2s
  2. Fetch portfolios

    SecurityScorecard

    1.4s
  3. Group by owner

    Transform

    0.1s
  4. Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    SecurityScorecard

    Queued

Collections and dashboards

Scorecard health, computed, not asked for.

Four metrics and a 14 day trend on records created, broken down by team.

SecurityScorecard health

Refreshed 4 minutes ago · every 15 minutes · from the portfolios collection

Live

Portfolios

1,284 ↓ 12%

Companies

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Portfolios created

Last 14 days

By team

Share of activity

Vendor Risk 34%

Enterprise Security 27%

Third Party 21%

Compliance 18%

FAQ

Frequently asked questions

How do I connect SecurityScorecard to Claude?

Connect SecurityScorecard in Elaichi first: you paste an API key generated in your SecurityScorecard account, and there is no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Claude asks you to sign in to Elaichi as yourself, and from then on your SecurityScorecard portfolios, companies, and tags are available in the conversation.

Does SecurityScorecard work with ChatGPT and Cursor as well as Claude?

Yes. Once SecurityScorecard is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect SecurityScorecard once and every client you use picks it up.

What can an AI agent actually do with my SecurityScorecard data?

With SecurityScorecard connected, an agent can list your portfolios and the companies in each one, pull the expanded risk findings for a portfolio, and create, rename, or remove portfolios. It can also add companies to portfolios in bulk, create and organize scorecard tags and tag groups, and attach tags to companies or remove them. SecurityScorecard exposes a large number of actions, so short concrete asks such as "list the companies in the Critical Vendors portfolio" work better than long paragraphs.

Does connecting SecurityScorecard give the AI every portfolio in my account?

No. An agent working through SecurityScorecard sees only what the API key you connected is allowed to see, and everything it does runs inside that access. Elaichi can narrow that further with restrictions per team or per action, but it can never widen it beyond what SecurityScorecard itself grants.

Can my team share one SecurityScorecard connection?

Yes. One person connects SecurityScorecard in Elaichi and shares the connection with a team, and nobody else ever sees or handles the API key. Each teammate still signs in to Elaichi as themselves, so every portfolio change or tag update in the audit log names the actual person who made it.

Can I stop an agent from deleting or changing things in SecurityScorecard?

Yes. In Elaichi, restrictions on the SecurityScorecard connection work per action, so you can allow listing portfolios and risk findings while blocking deletions or bulk changes to companies and tags. A blocked action is never advertised to Claude, ChatGPT, Cursor, or any other client, so no prompt, accidental or otherwise, can reach it.

What happens to a SecurityScorecard connection when someone leaves?

Offboarding a person in Elaichi ends their access to SecurityScorecard at once, across every client they used. If they had shared a SecurityScorecard connection with a team, it keeps working for everyone else on that team. If you want SecurityScorecard gone entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client at the same time.

Put SecurityScorecard in front of your team

Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.