Skip to content
fullCircle GRC

fullCircle MCP Server

Your GRC program, inside your AI assistant.

The fullCircle MCP Server connects Claude and other MCP-compatible AI clients to your live program — 80 tools to search, read and update controls, evidence, audits, risks, vendors and projects, all under each user's own permissions.

The team behind fullCircle is trusted by security leaders at

WorkdayVMwareGE VernovaDISHSalesloftMapLargeembecta

Why MCP Server

Bring fullCircle to the AI your team already uses

Works where your team works

Connect Claude, Claude Code and other MCP-compatible clients with a fullCircle sign-in — no copy-paste between tools.

Grounded in your real program

Search and cross-reference live controls, evidence, findings, risks and vendors, plus fullCircle's framework knowledge base.

Governed like everything else

Every call runs as the signed-in user, with their role and module permissions. Nothing more.

MCP Server

Everything your AI assistant needs to do real GRC work

Ask

Answers from live program data

Ask your assistant which evidence is expiring, which vendors have open findings or how a control maps across frameworks — it calls fullCircle's tools and answers from your actual program.

Keyword, semantic and relationship search across your program
Framework knowledge base and Platform Intelligence content
Dashboards for controls, assessments and risk

Act

Do the work, not just the lookup

Write tools let your assistant help with real tasks: record control testing, create and update formal findings, link files to evidence and audit requests, and review vendor questionnaires.

Record assessment control testing and formal findings
Upload files and link them to evidence or requests
Suggest risks and tasks, and manage vendors and tags

Trust

Secure by design

Clients connect over OAuth 2.0 with PKCE, and admins control your organization's MCP credentials. Every tool declares whether it reads or writes, so your AI client can ask before it changes anything.

OAuth 2.0 sign-in with PKCE, or API keys for automation
Admin-managed credentials you can rotate or delete instantly
Honest read/write annotations on every tool

How it works

Up and running in three steps

1

Enable access

An organization admin generates MCP credentials and grants MCP access to the people who need it.

2

Connect your client

Add the fullCircle MCP Server to Claude or another MCP-compatible client and sign in with fullCircle.

3

Start asking

Your assistant can now search, read and update your program — within your permissions.

80

tools across controls, evidence, audits, risk, vendors and projects

“It provides the ability to customize as much as you'd like, but the out of the box solution has very much all you'll need. Having used a variety of other GRC tools, fullCircle is surely the easiest to implement.”

Michael G., Senior Director, Information Security (G2 review)

FAQ

Frequently asked questions

Still have questions? Talk to our team.

Clients that support remote MCP servers with OAuth, such as Claude and Claude Code. API-key access is also available for scripts and custom agents.

Only through write tools, and only within the signed-in user's permissions. Every tool is annotated as read or write so MCP clients can ask for approval before a change.

Exactly what the signed-in user can access in fullCircle — their organizations, modules and permitted records. Users who belong to several organizations can switch between them.

An organization admin generates MCP credentials in fullCircle settings and grants MCP access to the users who need it. Admins can rotate or delete credentials at any time. The MCP Server is included with Optimize.

See MCP Server in action.

Book a personalized demo and we'll show you exactly how fullCircle fits your frameworks, team and audit calendar.

Or see how audit-ready you are