# Scytale MCP for AI Agents AI Agent Connect

> Scytale MCP lets you manage security compliance and audits directly through your AI agent. It handles evidence collection, framework monitoring for standards like SOC2 and ISO 27001, and user access reviews without you having to jump back and forth between your security dashboard and your workspace.

## Overview
- **Category:** security-compliance
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_oKCV8VNfjg3CxNOFTBLXjx0OTJUuSTOBPQomuHNh/ai-agent-connect
- **Tags:** compliance-automation, soc2, iso27001, security-audit, evidence-collection

## Description

Managing security audits usually feels like a chore involving endless tabs and manual data entry. This Connector changes that by letting your AI agent handle the heavy lifting of compliance tracking. Instead of clicking through a dashboard to see if your SOC2 controls are passing, you can just ask your agent for a status update. You can pull evidence, check user permissions, and upload new documentation directly from your chat interface. It connects your Scytale account to any AI client you already use, making it a core part of your security workflow. Because Vinkius hosts this Connector, you can get it up and running in minutes alongside your other tools. It turns a complex, manual process into a simple conversation where you can stay on top of your security posture without the usual headaches.

## Tools

### get_audit_logs
Retrieve a history of all actions taken within your Scytale platform. This helps you track historical changes and platform activity.

### get_compliance_status
Get the current compliance status across all your active security frameworks. Use this to quickly see where you stand on SOC2 or ISO 27001.

### get_evidence
Fetch detailed information about a specific piece of evidence. This is useful for verifying the details of a policy or link.

### get_user
Get the specific details for a single user in your organization. Use this to verify individual account information.

### list_controls
List all security controls and their current states. This helps you identify specific gaps in your security posture.

### list_evidence
List every piece of evidence collected in your Scytale account. Use this to see a full inventory of your audit materials.

### list_users
List all users within your organization. This lets you see who has access to your systems at a glance.

### upload_evidence
Upload a new evidence file or link to your account. This allows you to submit new documentation without leaving your chat.

## Prompt Examples

**Prompt:** 
```
What's our current status for SOC2 and ISO 27001?
```

**Response:** 
```
I've pulled your current compliance status:

| Framework | Status | Score |
| :--- | :--- | :--- |
| **SOC2** | In Progress | 85% |
| **ISO 27001** | In Progress | 72% |

Would you like to see which specific controls are currently marked as 'Failed'?
```

**Prompt:** 
```
List all the security controls that are currently failing.
```

**Response:** 
```
I found 4 security controls that currently have a 'Failed' status:

*   **Encryption at Rest** (Control ID: SEC-04)
*   **MFA Policy** (Control ID: SEC-12)
*   **Data Retention Policy** (Control ID: SEC-19)
*   **Offboarding Procedure** (Control ID: SEC-22)

Would you like me to pull the evidence for any of these?
```

**Prompt:** 
```
Show me the evidence for the access control policy.
```

**Response:** 
```
I've retrieved the details for the Access Control Policy evidence:

*   **Type**: Policy Document
*   **Title**: Access Control Policy v2
*   **Uploaded By**: Sarah J.
*   **Date**: Oct 12th
*   **Linked Controls**: 3 SOC2 Controls
*   **Status**: Verified

Do you need me to find anything else related to this policy?
```

## Capabilities

### Check framework status
Get real-time compliance scores for SOC2, ISO 27001, and other standards.

### Manage evidence files
List, view, and upload new evidence items like policy docs or links.

### Audit security controls
See which controls are passing or failing across your entire organization.

### Review user access
List all organization users and check their specific permission levels.

### Pull audit history
Access a full log of platform actions to track changes and activity.

## Use Cases

### Audit Readiness
A compliance officer asks for all evidence linked to SOC2 controls to see what's missing before an audit starts.

### Rapid Security Checks
A security engineer asks the agent to list all failed controls to see which ones need immediate attention.

### User Access Review
A manager asks the agent to list all users to ensure only the right people have admin access.

### Evidence Collection
A founder asks the agent to upload a link to the new remote work policy as evidence for a security control.

## Benefits

- Stop manual dashboard hopping by checking SOC2 status directly in your chat.
- Upload evidence files and links using the upload_evidence tool to save time.
- Identify security gaps faster by using list_controls to see failing items.
- Keep user permissions organized by quickly pulling user data with list_users.
- Stay audit-ready by pulling a full history of platform actions with get_audit_logs.

## How It Works

The bottom line is you get a conversational interface for your entire security compliance dashboard.

1. Subscribe to the Scytale MCP on Vinkius.
2. Provide your Scytale API Key in the configuration.
3. Ask your agent to check your compliance status or upload evidence.

## Frequently Asked Questions

**Can the Scytale MCP help me with my SOC2 audit?**
Yes, it helps you track your SOC2 status and manage all the evidence you need for the audit in one place.

**How do I upload evidence using the Scytale MCP?**
You just tell your AI agent to upload a file or a link, and it handles the connection to Scytale for you.

**Can I see who has access to my Scytale account?**
Yes, you can ask your agent to list all users in your organization to see who has access at a glance.

**Does the Scytale MCP support HIPAA compliance?**
Yes, it can monitor your compliance status across various frameworks, including HIPAA, depending on your setup.

**How does this save me time on audits?**
It eliminates the need to constantly switch between your security dashboard and your workspace, making evidence gathering much faster.

**Can I get a history of changes in Scytale?**
Yes, you can use the Connector to pull a full history of actions performed within your Scytale platform for better transparency.

**Can I check my current compliance status across all frameworks?**
Yes! Use the `get_compliance_status` tool. Your agent will retrieve the current status for all active frameworks like SOC2 and ISO 27001, highlighting your overall progress.

**How do I upload new evidence for an audit requirement?**
Simply use the `upload_evidence` action. You can provide a file reference, a link, and optional metadata to attach the evidence directly to your Scytale account.

**Can I see a history of actions performed within the platform?**
Yes, the `get_audit_logs` tool allows you to retrieve a history of actions performed within Scytale, ensuring full transparency for your security audits.