SCRUt MCP Server

Scrut MCP: Get compliance work done without leaving your AI app

Give an MCP-compatible AI app like Claude, ChatGPT, and Cursor trusted access to your Scrut Platform. Get sourced answers, check readiness, and file evidence in the same workspace.

Connect Scrut with the AI apps your team already uses

Claude Code
ChatGPT Codex
Perplexity
Co-pilot
Cursor
Gemini
AI apps

Keep compliance work moving without switching tabs

Get compliance answers without hunting for them

Ask about frameworks, controls, policies, evidence, audit dates, owners, or continuous tests in plain language and get answers grounded in Scrut.

Check your compliance program’s readiness

Surface policies still in draft, stale or missing evidence, controls without evidence, and failing tests before they slow down an audit or customer request.

File evidence without leaving your AI app

Upload a file or attach a link to the right evidence item, with a note and date, without leaving the AI app where the work is happening.

Answer questionnaires with Scrut-supported context

Draft responses using published policies, Trust Vault, and Vault documents, with supporting sources and unanswered gaps flagged for review.

Remediate failing cloud tests where code lives

Bring failing test details and remediation guidance into the workspace where your infrastructure code lives, so you can move from finding to fixing.

Complete multi-step work in one request

Use ready-to-run skills in Claude for compliance digests, questionnaire responses, and evidence filing without mapping every step yourself.

Set up Scrut MCP in four steps

Choose a compatible AI app

Use Claude, Cursor, Codex, or any MCP-compatible AI app your team already works in.

Add the Scrut MCP server

Copy the region’s server config and add it to the AI app’s MCP or connector settings.

Sign in with Scrut

Authenticate with your Scrut account. Scrut MCP works at your existing Scrut permission level.

Try your first prompt

Start with one simple question, such as: “Which SOC 2 policies are still in draft?”

Bring Scrut context into your AI app, with guardrails

Works within your Scrut access

When you sign in, your AI app can only access the information your existing Scrut role already allows you to see. Nothing more.

Your compliance records stay protected

Scrut MCP can upload and attach evidence, but it cannot delete, overwrite, or edit any of your existing compliance records.

Every evidence action has an audit trail

Evidence uploads and attachments are tied to the authenticated user and recorded in Scrut’s audit log.

Frequently Asked Questions
What is Scrut MCP?

Scrut MCP is a Model Context Protocol server that connects Scrut to MCP-compatible AI apps such as Claude, ChatGPT, Cursor, and more. It gives your AI app permission-bound access to the compliance context maintained in Scrut, so you can ask questions, read documents, check readiness, and file evidence from your existing workspace. Scrut remains the source of truth for your compliance program.

How does Scrut MCP work?

Connect the Scrut MCP server to your AI app and sign in using your Scrut account. When you make a request, the AI app selects the relevant predefined Scrut MCP actions, retrieves the permitted context from Scrut, and returns the answer or result in the same workspace.

What can you do with Scrut MCP?

You can use Scrut MCP to:

  • Ask questions about frameworks, controls, policies, evidence, audit dates, owners, and continuous tests
  • Run readiness checks across your compliance program
  • Search for and read policy or evidence documents
  • Draft sourced security questionnaire answers
  • Create compliance digests
  • Upload files or attach links to evidence

Scrut MCP supports 14 tools across these workflows.

Which AI apps work with Scrut MCP?

Scrut MCP works with supported AI apps that can connect to remote MCP servers, including Claude Code, Cursor, Codex, and GitHub Copilot. The setup process may vary slightly depending on the AI app you use.

How does Scrut MCP answer security questionnaires?

Scrut MCP uses the compliance knowledge maintained in Scrut to draft answers to security questionnaire questions. It returns the sources used for each answer and flags questions it cannot answer confidently instead of filling the gap with an unsupported response.

Your team should still review and approve the final answers before submitting them.

Can Scrut MCP search and read policies, evidence, and other documents?

Yes. Scrut MCP can search for documents across policies, evidence, and the Trust Vault. It can also read the full text of a specific policy or evidence document, provided the signed-in user has permission to access it in Scrut.

What are Scrut MCP skills, and how do they work?

Scrut MCP skills are packaged workflows that combine multiple predefined actions into one repeatable job. Instead of explaining every step, you start with the outcome you need.

Current skills include:

  • Compliance digest for summarizing audit dates and areas requiring attention
  • Answer questionnaires by drafting questionnaire responses from Scrut context
  • Upload evidence for attaching a file or link to the relevant evidence item

Packaged skills are currently available in Claude.

What information can Scrut MCP read and write?

Depending on the signed-in user’s permissions, Scrut MCP can read information about frameworks, controls, policies, evidence, documents, and continuous tests.

Its write access is limited to evidence filing. It can upload a file, attach a file, or external link to an existing evidence item. It cannot delete, overwrite, or freely edit existing compliance records.

How does Scrut MCP keep compliance data secure?

Scrut MCP acts as the person who signs in, so it can only access information that user is already permitted to access in Scrut. It does not receive blanket access to the organization.

Evidence uploads and attachments are tied to the authenticated user and recorded in Scrut, helping supported actions remain traceable. Regional connections are available for US, EU, and India deployments

How do I connect Scrut MCP to my AI app?

Add the Scrut MCP server URL for your Scrut region in the MCP or connector settings of your AI app. Then sign in using your Scrut account and approve the connection.

Once connected, you can start with a plain-language request such as:

“Give me a SOC 2 readiness summary and show me what needs attention.”

The exact setup steps depend on the AI app you use.

Experience security-first GRC powered by Scrut Teammates.

Scrut Automation’s AI-powered platform helps you move fast, stay compliant, and build with confidence from day one.

Book a Demo
Book a Demo