ISMS Copilot
ISMS Copilot

ISO 27001 Copilot integration

There is no separate ISO 27001 endpoint. ISO 27001 work (Annex A gap checks, Statement of Applicability justifications, policy drafts, risk treatment narrative) runs through the same three integrations: MCP for coding agents, the OpenAI-compatible Model API for your code, and the embedded assistant for your website.

What you can wire in

From Claude Code, Cursor, Codex, OpenCode or Grok: your agent asks ISMS Copilot for an Annex A gap check or an SoA justification over MCP and gets the answer back as a tool result

From your own code: any OpenAI SDK can call the Model API; pin ISO 27001 framework knowledge per request instead of relying on auto-detection

Every Model API response discloses which framework modules were injected

On your website: an ISO 27001-aware assistant for your visitors from a console snippet

In the chat app: draft a policy, then generate it as a Word, PDF, Excel or Markdown file

Start here

Frequently Asked Questions

Is there a control-mapping or risk-assessment API?

No dedicated endpoints. Control mapping and risk assessment are requests you send through MCP or the Model API, answered as text in a structured draft. Ask for the format you need, for example a table per Annex A control.

Can I get compliance status webhooks?

No. ISMS Copilot does not track live control status or send webhooks. A GRC platform does that; ISMS Copilot is the drafting and framework layer next to it.

Does ISMS Copilot see my repository?

Over MCP, only what your agent writes into the message. Over the Model API, only what your code sends in the request.

Give your agent an ISO 27001 specialist

Connect Claude Code, Cursor, Codex, OpenCode or Grok with one token.