May 19, 2026 · APRI · AI-Powered Risk Intelligence

APRI™ — AI-Powered Risk Intelligence

The MCP surface for vCISO Lite. Ask your compliance program anything from Claude, GPT, or your own agent — get evidence-backed answers with the citations attached.

What changed

APRI™ (AI-Powered Risk Intelligence) is the MCP surface on vCISO Lite. Point Claude, Cursor, Claude Desktop, Claude Code, or a custom agent at mcp.vcisolite.com and the whole platform becomes addressable: controls, findings, vendor risk, evidence, KRIs, the audit chain, and, for engineering teams on Business tier and above, write operations like attest_control, create_remediation, and triage_finding. The same tool graph sits beneath the in-app APRI side-panel on the Enterprise tier.

Catalog
Roughly 82 MCP tools spanning compliance, findings, vendor risk, evidence, KRIs, scanner, red-team, policies, reporting, work management, audit query, maturity, risk-mapping, business-context, vendor-incident, notifications, corrections, and org-switching. About 68 are core and 19 are mutating.
Verify family
14 claim-grade primitives that take a structured claim and return a verified result with the evidence, the freshness, and an explicit unverifiable_reasons list when the platform cannot confirm. This is the RFC-042 verified-claim pattern.
Access
mcp.vcisolite.com with OAuth 2.1, PKCE, and Dynamic Client Registration for engineering teams on Business tier and above, usable from Claude, Cursor, Claude Desktop, Claude Code, and custom agents. The same tool graph sits beneath the in-app APRI side-panel inside the vCISO Lite web shell on Enterprise.
Authorization
Every tool call clears Layer 1 (plan-tier entitlement), Layer 2 (RBAC), and Layer 3 (per-resource OpenFGA). The JWT is scoped to a single organization; the multi-tenant boundary is enforcement, not policy.

Why it matters

APRI is the connective tissue between vCISO Lite and every place you already run agents. The verify-* result (provenance, freshness, unverifiable_reasons) is the material an AI client needs to answer a compliance or risk question correctly instead of confidently-wrong. What the client does with that result is the client’s discipline; when Trustworthy Autonomy™ is in the loop, honoring it is enforced at the agent layer by cryptographic signature, not at APRI itself. APRI exposes the data; Trustworthy Autonomy enforces honest use.

Read the accompanying deep-dive in the AI Governance cluster, including “How often is your compliance AI actually right?”

Availability

Shipping today. mcp.vcisolite.com is live for Business tier and above; the in-app APRI side-panel is live on Enterprise.

Business tier and above authenticate against mcp.vcisolite.com with OAuth 2.1, PKCE, and Dynamic Client Registration, usable from any compliant MCP client including Claude, Cursor, Claude Desktop, Claude Code, and custom agents. Enterprise adds the in-app side-panel inside the vCISO Lite web shell, with a $25/day per-user Anthropic-spend cap enforced at the gateway. Starter and Growth tiers get the read-side catalog.

Known limitations

Write operations like attest_control, create_remediation, and triage_finding require Business tier or above. Starter and Growth tiers get the read-side catalog without the mutating tools.

The in-app side-panel is Enterprise-only. Business tier teams point their own MCP clients at mcp.vcisolite.com, where the Anthropic token spend is theirs rather than the platform's.

The in-app side-panel enforces a $25/day per-user Anthropic-spend cap at the gateway. Heavy users should prefer their own client against mcp.vcisolite.com.