Viso Mcp Server is an MCP server that connects AI assistants to the VISO TRUST third-party risk management platform. Designed for security teams, compliance officers, and risk analysts, it enables users to monitor vendor security postures and manage third-party assessments directly through conversational interfaces. The server provides tools to search vendor directories by domain or URL, onboard or offboard supplier relationships, track assessment lifecycles, and configure event webhooks. It also allows risk practitioners to query audit log events for compliance tracking and ingest threat intelligence reports from third-party services including BitSight, SecurityScorecard, and Recorded Future. Organizations can connect their AI clients using a hosted managed remote endpoint over Streamable HTTP, or deploy the server independently using Docker or Java 21 Spring Boot profiles. By bridging third-party security workflows into LLMs, the server simplifies risk oversight, vendor status checks, and data collection without requiring manual navigation of the primary web interface.
Category: Other & General Purpose
Tags: boilerplate, starter, template
Follow these steps to configure the server in your MCP client: 1. Obtain an API token from your VISO TRUST platform account. 2. Connect via the hosted remote endpoint by adding the server configuration to your MCP client settings file (such as Claude Desktop): json { "mcpServers": { "viso-mcp": { "type": "streamable-http", "url": "https://mcp.visotrust.com/mcp", "headers": { "Authorization": "Bearer <your-api-token>" } } } } 3. Alternatively, run locally via Docker by configuring the docker command with the image visotrustai/viso-mcp-server:latest and passing your VISOTRUST_API_TOKEN and VISOTRUST_API_BASEURL (defaulting to https://app.visotrust.com). 4. Restart your MCP client to verify tool registration.
search_vendor_directory directly inside an LLM conversation. - Risk assessment management: Initiate supplier assessments using create_assessment, fetch assessment results via get_assessment, and adjust deadlines or follow-ups. - Vendor lifecycle administration: Create, update, onboard, offboard, or archive third-party relationships using tools like create_relationship and onboard_relationship. - Threat intelligence ingestion: Submit external security evaluations from BitSight, SecurityScorecard, or Recorded Future into the VISO TRUST platform. - Audit log and webhook review: Query user and platform audit events over defined time ranges and inspect or update active webhook configurations.Part of MCP Servers
Viso Mcp Server allows AI assistants to interact directly with the VISO TRUST platform. It provides tools to search vendor directories, onboard or offboard third parties, initiate and monitor risk assessments, ingest external intelligence reports from providers like BitSight, query audit events, and configure platform webhooks.
You can connect without local installation by configuring the hosted Streamable HTTP endpoint at https://mcp.visotrust.com/mcp using your bearer token. If running locally, you can deploy the Docker container using visotrustai/viso-mcp-server:latest or run the packaged Spring Boot jar with Java 21.
It works with any MCP-compliant client that supports Streamable HTTP or standard I/O command execution. Compatible environments include VS Code via standard MCP extensions, Claude Desktop, and testing utilities like the Model Context Protocol Inspector.
The server requires a valid VISO TRUST API token. When using the hosted remote HTTP endpoint, the token is passed in the Authorization HTTP header. When running the server via Docker or Java, it is supplied through the VISOTRUST_API_TOKEN environment variable.