ISMS Copilot
ISMS Copilot

Your agent is the harness. ISMS Copilot is the GRC specialist it delegates to.

Talk to a specialist compliance AI from the harness you already use. Your coding agent keeps the code, the repo and the plan. When a task turns into ISO 27001, SOC 2, GDPR, NIS 2 or DORA work, it sends the question to ISMS Copilot over MCP and gets the answer back.

Claude Code, one line

claude mcp add --scope user --transport http ismscopilot https://account.ismscopilot.com/v1/account/mcp --header "Authorization: Bearer pat-isms-..."

How delegation works

  1. 01

    Your agent sends the question

    Mid-task, your harness calls ISMS Copilot through the MCP tools create_conversation and send_message. What travels is the message your agent writes, nothing else from your repository or filesystem.

  2. 02

    The specialist does the GRC work on its side

    Curated framework knowledge, the memories and files of the workspace the conversation runs in, and the drafting itself all happen on ISMS Copilot's side. A policy draft or a gap analysis is generated there, not in your agent's context window.

  3. 03

    Only the answer comes back

    Your agent receives the finished answer as a tool result. The bulk of the GRC context never enters its transcript, so it is never re-sent on every later turn of the session.

  4. 04

    The answer still counts, so ask for short ones

    The returned answer is read by your agent like any other tool result, and it stays in the transcript from then on. When you only need a decision or a list, tell the agent to ask for a brief answer.

What to delegate, what to keep local

WorkWhere it runsWhy
Policy and procedure draftingDelegate to ISMS CopilotLong drafting is generated on the specialist's side; your agent receives the finished draft.
Gap analysis and control mappingDelegate to ISMS CopilotFramework knowledge is injected there, so you do not paste standards into your own context.
Statement of Applicability justifications, risk register entriesDelegate to ISMS CopilotStructured GRC output grounded in curated framework modules.
Audit preparation and framework questionsDelegate to ISMS CopilotISO 27001, ISO 27701, ISO 42001, SOC 2, GDPR, NIS 2, DORA, EU AI Act, HIPAA, PCI DSS and more.
Code, git, tests, configurationKeep in your harnessThat is your agent's job. ISMS Copilot has no access to your repository.
Reading and editing local filesKeep in your harnessThe specialist only sees what your agent puts in the message.
One-word lookups and triviaKeep in your harnessA round trip is not worth it for something your model already knows.

Connect your harness

HarnessStatusHow it connects
Claude CodeSupportedThe one-line claude mcp add above, with the Authorization: Bearer pat-isms- header.
CursorSupportedAn HTTP MCP server entry in mcp.json: the endpoint URL plus the Authorization header.
CodexSupportedAn mcp_servers entry in ~/.codex/config.toml: the endpoint URL plus the Authorization header.
OpenCodeSupportedA remote MCP server entry with the endpoint URL and the Bearer header.
GrokSupportedAn HTTP MCP server entry with the endpoint URL and the Bearer header.
Claude Desktop and claude.ai connectorsNot yetConnectors need OAuth; the endpoint takes personal access tokens today.
ChatGPTNot yetChatGPT connectors need OAuth; the endpoint takes personal access tokens today.

The connection

Endpoint
https://account.ismscopilot.com/v1/account/mcp
Transport
HTTP MCP (Streamable HTTP)
Auth
Authorization: Bearer pat-isms-...
Token
chat.ismscopilot.com, Settings, Connected apps, Create token. Shown once; grant only the scopes the agent needs.
Smoke test
Ask your agent to list your ISMS Copilot workspaces.

Compliance answers you can trust, inside Claude Code, Cursor or Codex, without burning your Claude or ChatGPT plan

Delegated conversations ride your ISMS Copilot chat plan and its 4-hour UTC session window. There is no separate billing, no credits and no per-token meter for the MCP connection. The free plan connects too; Think mode needs a paid plan, and Beyond runs on paid plans under a daily run cap. If you exhaust your chat plan's 4-hour session window, the plan-limit error tells your agent when it resets, and read tools keep working. Your harness model still reads the answer it gets back, so the answer is not free for your Claude or ChatGPT plan: the drafting behind it is what stays on our side.

The cost comparator, with sources and dates →

Sources and product truth

Frequently Asked Questions

Does this replace Claude, Cursor or Codex?

No. Your agent stays the harness: it keeps the code, the repository, the plan and the tool loop. ISMS Copilot is the GRC specialist it hands compliance questions to. Use both.

Does delegating save tokens in my harness?

By mechanism, the framework knowledge, workspace context and long drafting stay on ISMS Copilot's side, so they never enter your agent's transcript and are never re-sent on later turns. The answer that comes back does enter the transcript, so ask for brief answers when that is enough. We publish no savings figure until we have measured one with a reproducible method.

What does it cost?

Nothing on top of your ISMS Copilot chat plan. Delegated conversations count against the same 4-hour UTC session window as the web app, and there is no separate billing for the MCP connection.

Why can't I connect claude.ai, Claude Desktop connectors or ChatGPT?

Those connectors need OAuth. The ISMS Copilot endpoint accepts personal access tokens sent as a Bearer header today, which Claude Code, Cursor, Codex, OpenCode and Grok support.

What does ISMS Copilot see from my project?

From your project, only what your agent writes into the message: ISMS Copilot has no direct access to your repository, your filesystem or your harness's context. On its own side, the answer can also draw on the memories and pinned files of the ISMS Copilot workspace the conversation runs in. The conversation is stored in your ISMS Copilot account like any other chat.

What can the token do?

It acts as you, within the scopes you grant when you create it: for example reading workspaces and memories, or starting conversations. A read-only token cannot start conversations. Revoke it in Settings at any time; revocation takes effect immediately.

Give your agent a GRC specialist

One token, one MCP entry. Your agent keeps the code; the compliance work goes to the specialist.