Integrations

Connect approved AI tools to FIRCY intelligence

The FIRCY Sense MCP integration provides a way for approved AI tools to access configured threat-intelligence context for investigation. It is separate from the use of decoy MCP surfaces to observe suspicious activity.
Discuss an integration All integrations

Put intelligence into an approved investigation workflow

Where the integration is configured, approved tools can query relevant FIRCY context to support analyst-led investigation. Examples include source IP, network and targeted-activity context. What’s available depends on your service and deployment configuration.

An analyst might use an approved tool to examine context around a finding, compare relevant activity or prepare follow-up investigation questions. The underlying evidence remains the basis for a decision; a generated explanation is not a replacement for it.

Explore the threat-intelligence workflow.

Two different uses of MCP

Use Purpose What not to confuse it with
FIRCY Sense production MCP integration Let approved tools access configured FIRCY intelligence for investigation It is not a decoy, and legitimate use is not evidence of rogue activity.
Decoy MCP surface Observe selected interactions with a controlled detection surface It is not the production route for customers to retrieve intelligence.

For protocol background, see the Model Context Protocol architecture overview. For the detection use case, read detecting rogue AI agents with cyber deception.

Agree the operating boundaries before enabling access

An integration review should establish which tools and users are approved, how access is authenticated, what information is available, and whether any actions beyond retrieval are supported. It should also establish the relevant logging, revocation and review process.

Include the AI provider’s own data handling in that review. Once information reaches a separate tool, that provider’s terms apply.

The answers depend on your deployment, so settle them before access is switched on.

Treat retrieved event content as evidence, not instructions

Security events can contain text supplied by an external actor. An approved AI workflow should treat that text as untrusted data, verify explanations against source evidence, and avoid allowing event content to redefine the analyst’s task. OWASP’s prompt-injection guidance provides background on this risk.

Discuss a supported integration

Tell us the AI tool, the investigation workflow and the information your analysts need. We’ll confirm what’s supported for your tools and environment before anything is enabled.

Discuss an integration or explore other integrations.