Smpl Security for Claude.
Bring your security findings into Claude. Review open findings, pull remediation guidance, check SOC 2 readiness, and triage findings without leaving the conversation.
Overview
The Smpl Security connector gives Claude read access to the security findings Smpl produces for your organization, plus the ability to update a finding’s status.
It reflects data Smpl’s backend has already computed from your connected systems. It does not run scans on demand — queries return the results of scans that have already completed.
Before you connect
- A Smpl Security account at smplsecurity.ai, with an organization.
- At least one connector configured in Smpl (GitHub, Vercel, Supabase, Stripe, Cloudflare, or Resend) and at least one completed scan. Until a scan has run, queries return no results.
Any member of your Smpl organization can connect.
Connecting in Claude
- In Claude, open connector settings and add a new connector.
- Enter the Smpl MCP server URL:
https://smplsecurity.ai/api/mcp - Claude opens the Smpl authorization page. Sign in to your Smpl account if prompted.
- Review the permissions on the consent screen, then click Allow.
- The connector is now active.
MCP server URL
https://smplsecurity.ai/api/mcp
Permissions
The connector requests one or both of these scopes. The consent screen shows exactly what is requested before you approve.
mcp:readRead your open security findings and compliance status.
mcp:writeUpdate the status of findings (dismiss, resolve, reopen).
If you grant read-only access, finding-status updates are rejected. Re-authorize and grant write access to enable them. You can revoke a connection at any time in Smpl Settings.
What you can ask
get_findingsreadLists your open findings. Filter by severity to focus on what matters.
get_finding_detailreadFull detail for one finding, plus a remediation playbook with fix steps.
get_compliance_statusreadYour SOC 2 readiness score, broken down by control category.
update_finding_statuswriteDismiss, resolve, or reopen a finding. A reason is required when dismissing or accepting risk (captured as SOC 2 evidence).
Troubleshooting
Queries return nothing+
“Unauthorized” or the connection dropped+
“This connection has read-only access”+
“Finding not found”+
Support
Questions or issues with the connector? Email support@smplsecurity.ai. We typically respond within a business day.
