AI-Powered Risk Intelligence™.
Same data, new insights.
Internally, we call it Titanium. You'll know it as the part of vCISO Lite that connects your risks, vendors, and compliance posture — and runs the next step on your say-so. Close gaps, resolve incidents, decide with the numbers in front of you. On your terms.
vCISO Lite has always surfaced what matters. APRI™ takes the work from there.
For every framework, every vendor, every scan — vCISO Lite has been finding the gaps, surfacing the risks, and showing you what to act on. Interpreting the results, drafting the response, running the next step — that's been your lion's share. APRI™ takes it on. You make the calls. We do the math.
The data was always there.
The work doesn't have to be.
One brain. The right tools. Every time.
APRI™ is the agent inside vCISO Lite. Under the hood: an apri-gateway that owns sessions, authorization, and audit, and an MCP server that owns the 35+ tools APRI™ can call. You ask. It parses your intent, picks the tools that fit your role and your data, runs them in the right order, and streams the result back with full citations.
Ask in plain English. Get a finished deliverable.
A handful of the workflows APRI™ runs today. Every one of these used to be a half-day of clicking. Now they're an ask.
A 200-question vendor questionnaire from a Fortune 500 prospect lands in your inbox. Due Friday.
You're the connector: draft in vCISO Lite, attach the evidence, package the export, write the email, send it, track the follow-ups.
“Respond to this.” APRI™ imports the questionnaire, drafts the answers, attaches the cited evidence, re-checks each answer against its citations, and packages the export. You approve. APRI™ sends it. The deal stays on the calendar.
Agents that respect the rules you already set.
APRI™ inherits every guardrail vCISO Lite enforces. No shadow accounts, no broad service tokens, no silent writes.
Scoped to what you can see
APRI™ uses your entitlements, not a service account. If a user can't see a record, neither can the agent acting on their behalf.
Every action recorded
Each tool call, parameter, and result lands in the audit trail. Replayable, exportable, and addressable for your auditor.
Observe-first by default
Read-only by design. Writes and irreversible actions go through a confirmation gate — agents never publish, send, or change without a human.
APRI™ is a public MCP, too. Wire it into your own stack.
Same agent, same authorization model, same audit trail — exposed as a Model Context Protocol server. Connect APRI™ to Claude, Cursor, your own agent, or any client that speaks MCP. Same Enterprise plan, no new contract.
$# Add APRI™ to Claude Code
claude mcp add --transport http apri https://mcp.vcisolite.com/mcp
# …or install the plugin — adds /vciso-lite:risk-readiness + /vciso-lite:posture
claude plugin marketplace add vciso-lite/claude-plugin
claude plugin install vciso-lite@vciso-lite
# Claude.ai — Settings → Connectors → Add custom → https://mcp.vcisolite.com
# Cursor — Settings → MCP Servers → Add → https://mcp.vcisolite.com/mcpAn engagement layer, not a rebuild.
APRI™ sits on top of the vCISO Lite capabilities you already have. Same data sources, same controls, same evidence trail — orchestrated.