ISMS Copilot
ISMS Copilot

Your agent is the harness. ISMS Copilot is the GRC specialist it delegates to.

Talk to a specialist compliance AI from the harness you already use. Your coding agent keeps the code, the repo and the plan. When a task turns into ISO 27001, SOC 2, GDPR, NIS 2 or DORA work, it sends the question to ISMS Copilot over MCP and gets the answer back.

Claude Code, one line

claude mcp add --scope user --transport http ismscopilot https://account.ismscopilot.com/v1/account/mcp --header "Authorization: Bearer pat-isms-..."

How delegation works

  1. 01

    Your agent sends the question

    Mid-task, your harness calls ISMS Copilot through the MCP tools create_conversation and send_message. What travels is the message your agent writes, nothing else from your repository or filesystem.

  2. 02

    The specialist does the GRC work on its side

    Curated framework knowledge, the memories and files of the workspace the conversation runs in, and the drafting itself all happen on ISMS Copilot's side. A policy draft or a gap analysis is generated there, not in your agent's context window.

  3. 03

    Only the answer comes back

    Your agent receives the finished answer as a tool result. The bulk of the GRC context never enters its transcript, so it is never re-sent on every later turn of the session.

  4. 04

    The answer still counts, so ask for short ones

    The returned answer is read by your agent like any other tool result, and it stays in the transcript from then on. When you only need a decision or a list, tell the agent to ask for a brief answer.

What delegation saves, and what it does not →

What to delegate, what to keep local

WorkWhere it runsWhy
Exact requirements and identifiers (DORA RTS, NIS2 implementing regulation, ISO 42001, CMMC)Delegate to ISMS CopilotArticle, control and practice numbers come from curated framework modules, not from your model's memory.
Framework interpretation, gap analysis and control mappingDelegate to ISMS CopilotFramework knowledge is injected there, so you do not paste standards into your own context.
Drafting that needs framework grounding or your company context (policies, SoA justifications, risk register entries)Delegate to ISMS CopilotDrafted against curated framework modules plus your workspace memories, files and company context.
Audit preparation that needs framework grounding or your company contextDelegate to ISMS CopilotISO 27001, ISO 27701, ISO 42001, SOC 2, GDPR, NIS 2, DORA, EU AI Act, HIPAA, PCI DSS and more.
Small, well-known edits and quick drafts your model already handlesKeep in your harnessWhen your model knows the answer, needs no lookup and writes straight to a file, delegating adds turns and costs more.
Code, git, tests, configurationKeep in your harnessThat is your agent's job. ISMS Copilot has no access to your repository.
Reading and editing local filesKeep in your harnessThe specialist only sees what your agent puts in the message.

Connect your harness

HarnessStatusHow it connects
Claude CodeSupportedThe one-line claude mcp add above, with the Authorization: Bearer pat-isms- header.
CursorSupportedAn HTTP MCP server entry in mcp.json: the endpoint URL plus the Authorization header.
CodexSupportedAn mcp_servers entry in ~/.codex/config.toml: the endpoint URL plus the Authorization header.
OpenCodeSupportedA remote MCP server entry with the endpoint URL and the Bearer header.
GrokSupportedAn HTTP MCP server entry with the endpoint URL and the Bearer header.
Claude Desktop and claude.ai connectorsNot yetConnectors need OAuth; the endpoint takes personal access tokens today.
ChatGPTNot yetChatGPT connectors need OAuth; the endpoint takes personal access tokens today.

The connection

Endpoint
https://account.ismscopilot.com/v1/account/mcp
Transport
HTTP MCP (Streamable HTTP)
Auth
Authorization: Bearer pat-isms-...
Token
chat.ismscopilot.com, Settings, Connected apps, Create token. Shown once; grant only the scopes the agent needs.
Smoke test
Ask your agent to list your ISMS Copilot workspaces.

Claude Code with ISMS Copilot: same score as Claude Code alone on 20 tested lookups, with fewer Claude tokens

In our pre-registered test (2026-09-28, 3 runs each, Claude Code 2.1.283 with claude-sonnet-5, web tools available to both setups, answer key from official sources), Claude Code delegating to ISMS Copilot scored the same as Claude Code researching alone on 20 identifier lookups across five frameworks (ISO 27001, ISO 42001, CMMC, DORA RTS, NIS2), using fewer Claude tokens per correct answer. ISMS Copilot plan usage is not counted there. Where it does not help: small tasks Claude already knows, such as a short policy draft or a few SoA entries, cost more Claude usage when delegated, so keep those in your agent. Delegated conversations ride your ISMS Copilot chat plan and its 4-hour UTC session window. There is no separate billing, no credits and no per-token meter for the MCP connection. The free plan connects too; Think mode needs a paid plan, and Beyond runs on paid plans under a daily run cap. If you exhaust your chat plan's 4-hour session window, the plan-limit error tells your agent when it resets, and read tools keep working. Your harness model still reads the answer it gets back, so the answer is not free for your Claude or ChatGPT plan: the drafting behind it is what stays on our side.

Method and limits, including where delegation does not help →

Sources and product truth

Frequently Asked Questions

Does this replace Claude, Cursor or Codex?

No. Your agent stays the harness: it keeps the code, the repository, the plan and the tool loop. ISMS Copilot is the GRC specialist it hands compliance questions to. Use both.

Does delegating save tokens in my harness?

It depends on the task. By mechanism, the framework knowledge, workspace context and long drafting stay on ISMS Copilot's side, so they never enter your agent's transcript and are never re-sent on later turns. The answer that comes back does enter the transcript, so ask for brief answers when that is enough. What we measured (2026-09-28, pre-registered, Claude Code with claude-sonnet-5, 3 runs each): the same score as Claude Code alone with fewer Claude tokens per correct answer on 20 identifier lookups, no saving on a long mixed coding and compliance session, and more Claude usage on small ISO 27001 tasks Claude already knows. ISMS Copilot plan usage is not counted in those figures. Method and limits are on the benchmark page in the sources above.

What does it cost?

Nothing on top of your ISMS Copilot chat plan. Delegated conversations count against the same 4-hour UTC session window as the web app, and there is no separate billing for the MCP connection.

Why can't I connect claude.ai, Claude Desktop connectors or ChatGPT?

Those connectors need OAuth. The ISMS Copilot endpoint accepts personal access tokens sent as a Bearer header today, which Claude Code, Cursor, Codex, OpenCode and Grok support.

What does ISMS Copilot see from my project?

From your project, only what your agent writes into the message: ISMS Copilot has no direct access to your repository, your filesystem or your harness's context. On its own side, the answer can also draw on the memories and pinned files of the ISMS Copilot workspace the conversation runs in. The conversation is stored in your ISMS Copilot account like any other chat.

What can the token do?

It acts as you, within the scopes you grant when you create it: for example reading workspaces and memories, or starting conversations. A read-only token cannot start conversations. Revoke it in Settings at any time; revocation takes effect immediately.

Give your agent a GRC specialist

One token, one MCP entry. Your agent keeps the code; the compliance work goes to the specialist.