Skip to content

Integration · Developer tools

Connect Claude & ChatGPT to UpGuard

Ask your AI which security risks are open on your own domains and IPs, how a vendor is rated, or which vendors share a given risk. It reads UpGuard CyberRisk data on vendors, risks, vulnerabilities, breaches, threats and questionnaires. It can also start monitoring a vendor, set its tier, add vendor contacts and send security questionnaires, with your approval if you want it.

Connect UpGuard free

Free plan, no credit card. Takes about a minute.

Try asking

  • “What are the critical risks on our domains right now?”

    The AI lists the active risks on your own domains and IPs from the severity you ask for and up.

  • “What is the security rating of acme.com?”

    It looks up the vendor by hostname and reads its details and security rating.

  • “Which of our vendors have this risk?”

    It lists the vendors that have the given risk, and can filter them by tier, label or score.

What your AI can do

Your own assets

Monitored domains and IPs, active risks and risk changes, potential vulnerabilities (CVEs) and look-alike domains.

Vendor risk

Vendor ratings, risks, domains, contacts, assessments and questionnaires, plus monitoring, tiers and new questionnaires.

Breaches and threats

Breached identities, breach details, threat-monitoring findings and recent notifications.

  • “What changed on our own assets since Monday?”

    It lists the risks that were added or resolved on your domains and IPs in that period.

  • “Start monitoring newvendor.com and put it in tier 2.”

    It starts monitoring the vendor by hostname and sets its tier.

  • “Send our standard security questionnaire to Acme's security contact, due in two weeks.”

    It finds the questionnaire type and the vendor contact and sends the questionnaire. The vendor is emailed right away.

29 tools for UpGuard

These tools are switched on when you connect. You can switch any of them off, or require your approval before it runs.

  • create_vendor_contactChanges dataAdd a contact to a vendor by `vendor_id` with a `name` and optional `email_address`, `title` and phone.
  • get_breachGet details of one data breach by `id`.
  • get_domainGet details and risks for one of your domains by `hostname`.
  • get_ipGet details for one of your IP addresses by `ip`.
  • get_organisationGet your UpGuard organisation's details. Use to confirm which account you are working in.
  • get_questionnaireGet one vendor questionnaire by `id`, with its status, due date and score.
  • get_risk_detailsGet the description and remediation advice for one risk type by `risk_id`.
  • get_threatGet one threat-monitoring finding by `uuid`.
  • get_vendorGet a vendor's details and security rating by `id` or `hostname`.
  • list_breached_identitiesList your people's identities found in known data breaches, optionally for one `breach_id`.
  • list_domainsList your own monitored domains, optionally filtered by `labels` or active/inactive.
  • list_ipsList your own monitored IP addresses, optionally filtered by `labels`.
  • list_my_risk_changesList risks that were added or resolved on your own assets between `start_date` and optional `end_date`.
  • list_my_risksList the active security risks found on your own domains and IPs, optionally from `min_severity` up.
  • list_notificationsList recent UpGuard notifications (rating changes, new risks and more).
  • list_questionnaire_typesList the questionnaire types you can send, with their IDs.
  • list_threatsList threat-monitoring findings (leaked data, dark web mentions and more), filtered by severity, type, status or date period.
  • list_typosquat_domainsList the typosquatting (look-alike domain) monitoring results for your domains.
  • list_vendor_assessmentsList risk assessments, optionally for one vendor (`vendor_id` or `vendor_primary_hostname`) or by `status`.
  • list_vendor_contactsList contacts for a vendor by `vendor_id` or `vendor_primary_hostname`.
  • list_vendor_domainsList the domains of a vendor by `vendor_primary_hostname`.
  • list_vendor_questionnairesList security questionnaires sent to vendors, optionally for one vendor.
  • list_vendor_risksList the security risks of a vendor by `primary_hostname`, optionally from `min_severity` up.
  • list_vendorsList the vendors you monitor, with their ratings; set `include_risks` to add their risks. Use to find a vendor's ID or hostname.
  • list_vendors_with_riskList which of your vendors have a given risk (`risk_id`), optionally filtered by tier, label or score.
  • list_vulnerabilitiesList potential vulnerabilities (CVEs) detected on your own assets, optionally filtered by `labels`.
  • monitor_vendorChanges dataStart monitoring a vendor by `hostname` (or `id`), optionally setting its `tier` and `labels`.
  • send_vendor_questionnaireVisible to othersSend a security questionnaire of type `questionnaire_type_id` to a vendor's `recipients`, from `sender_email`, with a `due_date`. Emails the vendor contacts right away.
  • set_vendor_tierVisible to othersSet the tier of a monitored vendor by `vendor_primary_hostname` and `tier`.

Set up in three steps

  1. 1

    Pick the app

    Create a free PipMCP account and choose UpGuard from the app list.

  2. 2

    Paste your key

    Paste an UpGuard API key. In UpGuard CyberRisk open Account Settings and find or generate an API key.

  3. 3

    Add the link to your AI

    You get a personal MCP link. Add it to Claude, ChatGPT or Cursor:

    1. Click your name, then Settings › Connectors › Add custom connector.
    2. Paste your link as the Remote MCP server URL.
    3. Switch it on from the + menu in a chat.

Questions

What can the AI do in UpGuard?

The AI can read your organization, domains, IPs, risks, risk changes, vulnerabilities, typosquatting results, breaches, breached identities, threats, notifications and vendors with their risks, contacts, assessments and questionnaires. It can start monitoring a vendor, set a vendor's tier, add a vendor contact and send a security questionnaire.

Does the AI see my UpGuard API key?

No. Your UpGuard API key is encrypted at rest and never shown to the AI. After you save it, it is not shown again, not even to you. The AI only sees the results of the tools it calls.

Can I control what the AI is allowed to do?

Yes. You choose which tools are switched on, so you can start read-only. Sending a questionnaire emails the vendor's contacts right away and changing a vendor's tier affects how you track it, and both can require your approval before they run. Every tool call is logged.

Does it work with ChatGPT?

Yes. In ChatGPT go to Settings › Apps & Connectors › Advanced and turn on Developer mode, then add your PipMCP link. Developer mode needs a paid ChatGPT plan: Plus, Pro, Business or Enterprise. The same link also works in Claude (Settings › Connectors › Add custom connector), Cursor and other MCP clients.

What does it cost?

PipMCP has a free plan with no credit card required. Paid plans bill per completed task. You also need your own UpGuard account.

Does it cover my own assets or only vendors?

Both. For your own organization the AI reads monitored domains and IPs, active risks, risk changes, potential vulnerabilities, typosquatting results, breached identities and threat findings. For vendors it reads ratings, risks, domains, contacts, assessments and questionnaires.

Let your AI work in UpGuard today.

Start free. Your key stays encrypted, and you decide what the AI may do.

Connect UpGuard free

PipMCP is not affiliated with UpGuard. Product names are trademarks of their owners.