Where ISMS Copilot plugs into your work
ISMS Copilot integrates in four live ways: coding agents delegate compliance questions to it over MCP, your code calls the OpenAI-compatible Model API, your website runs an embedded assistant, and your team asks it from Slack. You can turn any chat reply into a Word, PDF, Excel or Markdown file.
What connects today
Each of these is live in production and documented. Pick the one that matches where the compliance question starts.
- Coding agents over MCPAccount MCP
Claude Code, Cursor, Codex, OpenCode or Grok hand GRC questions to ISMS Copilot with a personal access token (pat-isms-). Your agent keeps the code; ISMS Copilot writes the compliance answer and sends it back.
- Model APIsk-isms-
OpenAI-compatible chat completions for your own scripts and pipelines. Curated framework knowledge is added when a framework is detected in the request, or pinned by you. Prepaid credits, zero data retention.
- Website assistantEmbed
A compliance assistant on your own site from a console-generated snippet, limited to the domains you allow.
- Slack
Ask ISMS Copilot from your Slack workspace by mention or direct message. Paid plans; an organization owner connects it.
- Document files
Turn a chat reply into a Word, PDF, Excel or Markdown file and take it into your document system.
- Sign-in
Email, Google or Microsoft accounts.
Which integration fits
| Integration | Best for | Credential and billing |
|---|---|---|
| Account MCP | A person working in a coding agent who wants GRC answers without leaving it | Personal access token; rides your ISMS Copilot chat plan |
| Model API | Scripts, pipelines and sub-agent steps that need compliance text | API key; prepaid credits on the developer platform |
| Embed | Visitors to your website asking compliance questions | Public key plus a domain allowlist; separate assistant plans |
| Slack | Teams that ask quick framework questions in channels | Connected by an organization owner; paid chat plans |
Next to your GRC platform
ISMS Copilot does not sync with GRC platforms today. Teams use it as the consulting layer beside them: the platform collects evidence and tracks controls, ISMS Copilot drafts policies, SoA justifications and risk narrative.
- GRC platforms and specialist agents
Which layer does what, and why teams run both
Frequently Asked Questions
Does ISMS Copilot sync with Vanta, Drata or other GRC platforms?
Not today. There is no live sync. Use your GRC platform for evidence collection and control tracking, and ISMS Copilot for drafting and framework questions; move the drafts across as Word, PDF, Excel or Markdown files.
Do you offer webhooks?
No. ISMS Copilot does not send webhook notifications. To automate, call the Model API from your own code, or let your coding agent call ISMS Copilot over MCP.
Do you support SAML SSO?
Not today. You can sign in with email, a Google account or a Microsoft account.
Can I export to Confluence or Notion?
There is no direct export to Confluence or Notion. Generate a Word, PDF, Excel or Markdown file from a chat reply and import it into your wiki.
Can I connect claude.ai, Claude Desktop connectors or ChatGPT?
Not yet. Those connectors need OAuth, and the ISMS Copilot MCP endpoint accepts personal access tokens today. Claude Code, Cursor, Codex, OpenCode and Grok connect with a token.
Connect your coding agent
One token, one MCP entry. Your agent keeps the code; the compliance work goes to the specialist.
