The integration leverages Claude’s Compliance API to automatically populate a live inventory within the Salt platform. Security teams can now track when specific MCP servers are added, updated, or removed, providing a clear view of their AI attack surface. This visibility is critical, especially as recent research from Trend Micro indicates that the number of unauthenticated, internet-exposed MCP servers has nearly tripled to 1,467 in just a few months.
Designed with a strict least-privilege approach, the tool functions solely through a read-only scope. It restricts data collection to lifecycle events, ensuring that sensitive chat content, file data, and user prompts remain untouched. According to Salt Security CEO Roey Eliyahu, this functionality allows organizations to govern their AI environments with the same rigor applied to traditional infrastructure. The service is available immediately to existing Salt Security customers, requiring only a compliance access key and an organization ID to initiate monitoring.


Comments (0)
No comments yet. Be the first!