APRI™ — AI-Powered Risk Intelligence
The MCP surface for vCISO Lite. Ask your compliance program anything from Claude, GPT, or your own agent — get evidence-backed answers with the citations attached.
APRI™ (AI-Powered Risk Intelligence) is the MCP surface on vCISO Lite. Point Claude, Cursor, Claude Desktop, Claude Code, or a custom agent at mcp.vcisolite.comand the whole platform becomes addressable: controls, findings, vendor risk, evidence, KRIs, the audit chain — and, for engineering teams on Business tier and above, write operations like attest_control, create_remediation, and triage_finding. The same tool graph sits beneath the in-app APRI side-panel on the Enterprise tier.
What’s in the release
- Roughly 82 MCP tools, read and write. Approximately 68 core tools span compliance, findings, vendor, scanner, red-team, policies, reporting, evidence, work management, audit query, maturity, risk-mapping, business-context, vendor-incident, notifications, corrections, and org-switching. Nineteen are mutating.
- The 14-tool
verify-*family. Claim-grade primitives that take a structured claim and return a verified result with the evidence, freshness, and — where the platform cannot confirm the claim — an explicitunverifiable_reasonslist. This is the RFC-042 verified-claim pattern. - Two consumption modes over the same catalog.
mcp.vcisolite.comwith OAuth 2.1, PKCE, and Dynamic Client Registration for engineering teams (Business tier+) and AI marketplaces (Claude, Cursor, Desktop, Code); the in-app APRI side-panel inside the vCISO Lite web shell on Enterprise, with a $25/day per-user Anthropic-spend cap enforced at the gateway. - Layered authorization enforced by construction. Every tool call passes Layer 1 (plan-tier entitlement), Layer 2 (RBAC), and Layer 3 (per-resource OpenFGA). The JWT is scoped to a single organization; the multi-tenant boundary is enforcement, not policy.
Why it matters
APRI is the connective tissue between vCISO Lite and every place you already run agents. The verify-* envelope (provenance, freshness, unverifiable_reasons) is the material an AI client needs to answer a compliance or risk question correctly instead of confidently-wrong. What the client does with that envelope is the client’s discipline; when Trustworthy Autonomy™ is in the loop, honoring it is enforced at the agent layer by cryptographic signature — not at APRI itself. APRI is the substrate; TA is the enforcement.
Read the accompanying deep-dive in the AI Governance cluster, including “How often is your compliance AI actually right?”
Related reading: AI Governance cluster, Trustworthy Autonomy landing page.