Put AI to work in your
security assessments.
Security Reporter gives AI agents secure, permission-scoped access to assessments, findings, evidence, assets and reporting workflows.
This isn't a chatbot.
Watch an AI agent create an assessment, add targets, generate findings and build a report inside Security Reporter.
The agent does not work around Security Reporter. It works inside Security Reporter, using the same permissions, workflows and audit controls as your team.
Read the transcript
In this demo, an AI assistant first creates a new client and security assessment in Reporter using a single prompt. The client information is automatically fetched from the company website and the assessment is scheduled as instructed. The assessment is now created, including the report structure and configured targets.
Because the assistant now has direct access to Reporter, it can also support researchers with the assessment itself. Here the AI reviews the web application's source code, identify security issues, and automatically creates potential findings in draft mode.
By viewing the report, we can see what the findings look like. In the results section, we can see the findings have been added to the appropriate sections of the report. They are grouped by category such as injection and ordered by their risk classification. Each finding includes severity, description, risk explanation, remediation advice, and supporting evidence such as affected code references and screenshots. If an issue could be reproduced in the running application, the AI even captured a screenshot as proof using a real browser session. Everything is prepared for the researcher to review and verify.
Using the MCP server, the AI assistant has access to more than 100 Reporter tools that support the full assessment lifecycle, bringing AI directly into the security assessment workflow.
AI agents can do more than generate text. They can interact with assessments, findings, evidence and workflows.
How the connection works
The Security Reporter MCP Server is the secure connection layer between AI agents and your platform. Every request is authenticated, permission-scoped and logged.
Agents work through the same roles, permissions and audit trail your team already relies on. Nothing moves outside your governance.
Without context, AI is just guessing.
Security Reporter gives AI agents access to the assessments, findings, evidence and workflows they need to be useful.
Why AI works better with Security Reporter
AI is only as useful as the context it receives.
Records tell AI what exists. Relationships tell AI what matters.
Not just for chat-based prompts
AI agents can continuously monitor, analyse and assist throughout the security assessment lifecycle.
Ask AI a question, or let AI continuously assist your security workflows.
Ask questions relevant to your role
Different teams ask different questions. Security Reporter gives each role the context they need, based on their permissions and responsibilities.
Built for sensitive security data
Assessment data is some of the most sensitive a security team holds. AI workflows in Security Reporter never compromise that: access is scoped, auditable and entirely under your control.
Model-agnostic by design. Connect European AI providers, private models or enterprise-approved AI platforms, and combine AI workflows with strong data governance and European digital sovereignty.
Built on an API-native foundation
AI workflows build on the same foundation that powers Security Reporter. Explore the API and extensibility.
Frequently asked questions
What is the Security Reporter MCP Server?
It's the secure connection layer that lets AI agents work with your Security Reporter platform. Agents retrieve context such as assessments, findings, evidence and assets, and perform scoped actions inside your reporting workflows. Your team keeps full control.
Is it tied to one AI provider?
No. It's model-agnostic: connect your preferred AI agent or LLM, including European AI providers, private models or enterprise-approved AI platforms.
Can it run in self-hosted environments?
Yes. Like the rest of Security Reporter, it's built for self-hosted deployment, so sensitive findings and evidence stay inside infrastructure you control.
Does it respect user permissions?
Yes. Access resolves against the same roles and permissions you already manage in Security Reporter. Agents can only reach the tools and data their role allows, and every action is auditable.
What kind of data can agents access?
Within the limits you set, agents can work with assessments, findings, evidence, assets, workflows and reporting content. You decide exactly which of these each role and agent may reach.
Which users can use the MCP Server?
Access follows existing Reporter permissions. Administrators, researchers and optionally clients can use the MCP Server when enabled. Every request is scoped to the permissions of the authenticated user.
Can we use European AI models?
Yes. Connect European AI providers, private or on-premise models, and enterprise-approved platforms. This supports data governance and European digital sovereignty goals.
More of what Reporter does
- Collaborate with Team Members Work together on assessments without document chaos, conflicting versions, or handoffs that slow delivery down. Reporter gives pentesters, reviewers, and leads a shared workspace built for professional assessment workflows.
- Extend & Automate Your Workflow Fit Reporter into the way your team already works. Connect it to tools such as Jira and Azure DevOps via REST APIs and webhooks, or use n8n and Zapier for no-code automation. For AI-driven workflows, let AI agents work directly with your data through the Reporter MCP server.
- Focus on Testing Spend less time on repetitive reporting work and formatting, and more time on the assessment itself. Reuse proven finding content, work from templates, and build on previous findings to document faster and more consistently.
- Professional PDF Reporting Generate clear, well-structured PDF reports directly from your assessment data. Deliver output that looks professional, consistent, and ready to share with clients, auditors, and internal stakeholders.
- Work with Clients in One Place Keep client communication tied to the assessment instead of spreading it across email threads and separate documents. Comment on findings, coordinate retests, and discuss remediation in a more structured way.
Bring AI agents into your security assessment workflow.
Build AI-powered workflows on Security Reporter while keeping sensitive security data under control.