ISMS Copilot

The compliance specialist your AI calls.

Your assistant does the work. ISMS Copilot answers when the framework has to be right.

For agents that need a compliance specialist. This is the official ISMS Copilot MCP server. Add it to your AI once, and your AI can ask ISMS Copilot whenever a compliance question comes up. ISMS Copilot (ismscopilot.com) is not Microsoft Copilot or GitHub Copilot.

Connect your AI

Add the URL, sign in, approve. Every plan, including Free.

https://account.ismscopilot.com/v1/account/mcp

Connect in one step

claude.ai and Claude Desktop
Open Connectors, choose Add custom connector, paste the URL and leave the advanced OAuth fields empty. Sign in to ISMS Copilot and click Approve. Open Claude connectors.
Claude Code
Run this once, then type /mcp in a session, pick ismscopilot, sign in and click Approve.
claude mcp add --scope user --transport http ismscopilot https://account.ismscopilot.com/v1/account/mcp
ChatGPT
In developer mode, create a custom MCP app with the URL, choose OAuth and keep the default settings, then sign in and click Approve.
Cursor, Codex and other clients
These use a personal access token. Create one in the app, then paste the config for your client. Token setup.

No account yet? Create one free, no card. The URL to paste: https://account.ismscopilot.com/v1/account/mcp

Three jobs your AI hands over

Answer a framework question, with the clause
Your AI asks which control covers the topic. The answer comes back with the clause number, not a guess from memory. You check that number before you sign.
Check a document against a control
Your AI reads the policy or procedure you already have and sends a short excerpt. Ask what is missing against the control you name. You sign the answer. The file stays where it lives.
See where the SoA and the risk register disagree
Your AI reads both files and sends the relevant rows. Ask where they clash: a control excluded in the SoA but used in a treatment, a control with no evidence pointer, a review date that has passed. NIS 2, DORA, and the CRA are columns on that same sheet. Nothing is stored here.

Included in every plan

The MCP server comes with every ISMS Copilot plan, Free included. There is no separate agent plan: your AI's questions count against your chat plan.

Popular plans

Free
$0. Fast model, 10 messages per 4 hours
Plus
$24 / month
Standard
$50 / month
Pro
$100 / month
Business
$200 / month

See all plans

What it looks like

Live example, 2026-10-09

You, to your AI
Do we need to keep a list of our IT suppliers for DORA?
Your AI, to ISMS Copilot
Does DORA require a financial entity to keep a register of its ICT third-party contracts? Answer yes or no and name the exact article and paragraph, in one or two sentences.
ISMS Copilot
Yes. DORA Art. 28(3) requires financial entities to maintain a register of information on all their contractual arrangements on ICT services (with standard templates mandated via Art. 28(9)).

ISMS Copilot's reply over this MCP server on 2026-10-09, fast mode, unedited. Your AI takes the answer back into your work.

At a glance

Endpoint
https://account.ismscopilot.com/v1/account/mcp
Transport
Streamable HTTP (remote). Nothing to install, no npm package, no local process.
Auth
Claude and ChatGPT: sign in to ISMS Copilot and approve (OAuth). Other clients: personal access token, Authorization: Bearer pat-isms-...
Token
Created by the human at chat.ismscopilot.com, Settings, Connected apps. Shown once. Your agent cannot create it. For Cursor, Codex, other clients, CI and headless machines.
Plans
Every plan, including Free. Free runs the fast mode only, 10 messages per 4 hours. Think and Beyond modes need a paid plan.
Billing
Your ISMS Copilot chat plan. No separate agent plan, no per-token billing.
Server name
ismscopilot (tools appear as mcp__ismscopilot__* in Claude Code)
MCP Registry
io.github.tristanroth1/ismscopilot-account

If you are an AI agent

Fetch the official setup prompt and follow it: https://docs.ismscopilot.com/agent-setup/prompt.md. It covers the already-connected, not-connected and repair cases, writes the MCP config without committing any token, adds a routing rule and runs a smoke test. Do not invent another URL, package or API key. In Claude Code, add the URL with no header and ask the human to sign in and click Approve; you cannot do that for them. In Cursor, Codex and other clients, ask the human to create a token in Settings, Connected apps.

Sign in instead of a token: claude.ai, Claude Desktop, Claude Code, ChatGPT

Sign-in (OAuth) is live for Claude and ChatGPT. Add the server URL with no header and no token, sign in to ISMS Copilot and click Approve. claude.ai: Customize, Connectors, Add custom connector, and leave the advanced OAuth fields empty (Claude Desktop uses the same connectors); in a Team or Enterprise organization an Owner adds it once and each member connects with their own account. Claude Code: claude mcp add --scope user --transport http ismscopilot https://account.ismscopilot.com/v1/account/mcp, then /mcp to sign in. ChatGPT: create a custom MCP app (developer mode) with the server URL, choose OAuth, keep the default settings, then sign in and approve. The approved tool can read your account, workspaces, document list, memories and company profile, ask ISMS Copilot, update your company profile and memories, and create workspaces. It cannot create API keys or buy credits. Disconnect it any time in Settings, Connected apps. Cursor, Codex and other clients use the token setup below.

Set up with a token in four steps

For Cursor, Codex and other clients, CI jobs and headless machines.

  1. 1Sign up at chat.ismscopilot.com (free, no card), then open Settings, Connected apps.
  2. 2Create a token with the Agent delegation preset. It grants account:read, workspaces:read, conversations:create, company_context:read and memories:read, with no write scopes. Copy the pat-isms- value once.
  3. 3Put it in an environment variable, for example export ISMS_COPILOT_TOKEN="pat-isms-..." in your shell profile, so the token never lands in a committed file.
  4. 4Add the server to your client with the config below, restart the client, and ask: list my ISMS Copilot workspaces.

Token config for your client

Claude Code

Terminal, user scope so it works in every folder

claude mcp add --scope user --transport http ismscopilot https://account.ismscopilot.com/v1/account/mcp --header 'Authorization: Bearer ${ISMS_COPILOT_TOKEN}'

Keep the single quotes: Claude Code stores the ${ISMS_COPILOT_TOKEN} placeholder and expands it at start. Restart, then run /mcp to verify.

Cursor

~/.cursor/mcp.json (global, not a committed project file)

{
  "mcpServers": {
    "ismscopilot": {
      "url": "https://account.ismscopilot.com/v1/account/mcp",
      "headers": {
        "Authorization": "Bearer ${env:ISMS_COPILOT_TOKEN}"
      }
    }
  }
}

Merge into existing mcpServers. If Cursor started from the dock does not see the variable, put the literal token in the global file.

Codex

~/.codex/config.toml

[mcp_servers.ismscopilot]
url = "https://account.ismscopilot.com/v1/account/mcp"
bearer_token_env_var = "ISMS_COPILOT_TOKEN"

Older Codex builds without bearer_token_env_var take an [mcp_servers.ismscopilot.http_headers] table with the Authorization header.

Any other MCP client (OpenCode, Grok, Hermes, Windsurf, VS Code)

The client's MCP config

{
  "mcpServers": {
    "ismscopilot": {
      "type": "http",
      "url": "https://account.ismscopilot.com/v1/account/mcp",
      "headers": { "Authorization": "Bearer pat-isms-..." }
    }
  }
}

Same URL, same Bearer header. The exact key names vary by client.

Step-by-step guides: Claude Code, Cursor, and the product docs for every client.

Tools

What a client sees depends on how it connects. Full list with scopes and limits on ISMS Copilot for Agents.

Sign-in connection (Claude, ChatGPT): 12 tools

  • create_conversation, send_message, get_reply: ask the specialist. Fast mode by default; replies are asynchronous, poll get_reply until complete.
  • get_account_info, list_workspaces, create_workspace: who you are and which client workspaces exist.
  • list_documents: generated documents, metadata only.
  • list_memories, create_memory, update_memory: what your agent learns stays with your account.
  • get_company_context, set_company_context: the company profile set under Customize.

No API key, credit or checkout tools, and no upgrade or purchase fields in tool results.

Personal access token only: API keys and credits

The same 12 tools, each gated by the matching scope on the token, plus these when the token has the Model API scopes:

  • list_api_keys, create_api_key, revoke_api_key: manage sk-isms keys for the separate Model API.
  • get_api_credit_balance, create_api_credit_checkout: Model API credit balance and a checkout link a human pays.

Questions

Is there an official ISMS Copilot MCP server?
Yes. It is hosted at https://account.ismscopilot.com/v1/account/mcp, uses Streamable HTTP, and authenticates by OAuth sign-in, or with a pat-isms personal access token as a fallback. It is listed in the official MCP Registry as io.github.tristanroth1/ismscopilot-account.
Is this Microsoft Copilot or GitHub Copilot?
No. ISMS Copilot is an independent compliance AI made by Better ISMS (ismscopilot.com). Microsoft Copilot Studio and GitHub Copilot MCP instructions do not apply to it.
Do I need a paid plan to use the MCP server?
No. The MCP server works on every plan, including Free. Free runs the fast mode only, within the 10 messages per 4 hours limit. Think and Beyond modes need a paid plan.
Can my agent set itself up?
Yes, except for the sign-in. Point the agent at the official setup prompt, https://docs.ismscopilot.com/agent-setup/prompt.md. It adds the server, asks the human to sign in and click Approve, runs a smoke test and offers a routing rule. In Cursor, Codex and other clients, the human creates a token in Settings, Connected apps instead.
Is there an npm package or local server to install?
No. It is a hosted remote server. Add the URL to your MCP client and sign in, or add the URL with the Authorization header.

Registry entry: official MCP Registry. Machine-readable connect protocol: /api/public/connect/v1. Server Card: /.well-known/mcp.json. Agents get a Markdown version of this page by sending Accept: text/markdown. Facts checked on 2026-10-09 against the live endpoint, the official setup prompt and the ISMS Copilot app.

Add the server and sign in

Add the URL to your client, sign in to ISMS Copilot and click Approve in your AI. No account yet? Sign up free first. Cursor, Codex and other clients use a token from Settings, Connected apps.