Your AI tools are capable. They can draft policies, summarize documents, answer technical questions, and plan work. The problem is they have no idea what your compliance program looks like. Every query starts from scratch. The assistant has no access to your current controls, your evidence status, your open gaps, or your framework obligations. You end up copying and pasting context into a chat window just to get a useful answer.
Carbide’s Carbide Analyst closes that gap. It connects your live compliance program to your preferred AI tool, so every query draws on your actual, current program data. You can check a control’s evidence status, identify gaps before your auditor does, draft a policy grounded in your specific configuration, generate a board-level security report, or kick off a task — all from the AI tool you already work in.
Carbide Analyst and MCP: two distinct things that work together
Before getting into what Carbide Analyst does, it helps to understand the two components involved, because they serve different purposes.
Carbide Analyst lives inside the Carbide platform. It is a chat-based interface for generating documents, streamlining workflows, and taking action on your compliance program. You ask it a question or give it an instruction, and it responds using your live program data.
MCP (Model Context Protocol) is the extension layer. It is an open standard that lets external AI tools — Claude, ChatGPT, and others — connect to Carbide and query your program data from outside the platform. MCP is what makes Carbide Analyst accessible from your preferred LLM rather than only from within the Carbide platform.
This matters because it means your team does not need to change tools or log into another platform. A security lead working in Claude can query your ISO 27001 control evidence directly. A compliance manager in ChatGPT can get a full SOC 2 gap list. A technical team can pull pentest results from Carbide into Jira through the same connection and action them there.
What MCP is and why it matters for compliance
The Model Context Protocol is an open standard that lets AI tools fetch live data from external applications securely, without custom API development or manual integration work. Where a typical AI assistant draws on its training data and whatever text you paste in, an MCP connection gives it direct access to a specific, live data source.
Once Carbide is connected to your AI tool via MCP, your compliance program becomes something the AI can actually read from and act on. No static exports, no copy-paste, no stale snapshots.
This matters for compliance specifically because compliance data changes constantly. Controls get implemented, evidence is collected, tasks are completed, gaps are found and closed. An AI answering questions about your compliance posture needs to know your current state, not a document you exported last quarter.
What you can do with Carbide Analyst
The practical value comes from what you can query and act on once your live program is connected.
Run a gap analysis on demand
Ask Carbide Analyst to identify gaps across your compliance posture. It reviews your current evidence against your control requirements and surfaces what is missing before an auditor does. A gap analysis that previously took an hour or more now takes minutes.
Try: “Show me which SOC 2 controls have incomplete or missing evidence.” Carbide Analyst returns a prioritized gap list drawn from your live program. The AI surfaces the gaps and your Carbide advisor confirms the interpretation is sound.
Check control and evidence status without leaving your AI tool
Carbide Analyst queries your live program and returns the current state on demand. You do not need to log into the platform, navigate to a control, and read the status manually.
Try: “What’s the current status of our vendor risk assessment?” or “Which policies are past their review date?” Carbide Analyst pulls the answer from your actual program data, not from a static export. Inside the Carbide platform, Carbide Analyst is aware of the page you are on and the specific control or policy you have open, so responses are contextual to what you are working on.
Generate a board-level security report
One of the more immediate uses of MCP is custom reporting. Go to your preferred LLM, ask it to generate a board-level security report, and Carbide Analyst pulls your live program data through the MCP connection. The LLM then formats the output in the format, brand or tone already set in place in your LLM. The result is a board report that reflects your actual current security posture, not a generic template filled with placeholder language, formatted the way you would normally present it, without hours of manual assembly. This same approach applies to any regular reporting obligation: executive summaries, quarterly security updates, evidence packages for customer due diligence requests.
Draft policies grounded in your program
Ask Carbide Analyst to draft a policy and it generates the draft informed by your current account configuration: which frameworks you are working toward, what controls are in scope, and what your existing policies already cover.
Try: “Draft an incident response policy for our SOC 2 program.” The output reflects your actual program setup rather than a generic template. A credentialed advisor reviews it before it is finalized.
Map your controls to a new framework
When a new customer requirement introduces a framework you have not formally mapped, Carbide Analyst performs the initial mapping against your existing control set.
Try: “Map our current controls to ISO 27001.” Carbide Analyst identifies where your existing evidence satisfies ISO 27001 requirements and where gaps remain.
Kick off tasks and update control status using natural language
From inside the platform or through your AI tool, you can initiate tasks and move evidence through the audit workflow using plain-language instructions.
Try: “Create a task to complete our annual risk assessment and assign it to the security team.” or “Update the access control policy review to complete.” Carbide Analyst routes the action to the right platform module without you navigating menus.
Automation-only tools vs. Carbide Analyst:
| Automation-only AI tools | Carbide Analyst |
| Automate evidence collection and task tracking | Automates routine work and evidence mapping |
| Leave control interpretation to your team | Advisors interpret controls and fill gaps automation cannot resolve |
| Flag issues for you to research and resolve | Returns answers, not items to research |
| No review layer before documents reach an auditor | Credentialed advisor sign-off required before critical documents are finalized |
The advisor layer: why the AI is trustworthy
Compliance AI tools that operate without a review layer create a specific risk. The AI produces an answer that is plausible, well-written, and wrong in a way that only surfaces during an audit.
Left unchecked, AI gets things confidently wrong. It might recommend uploading board minutes as audit evidence when an experienced advisor knows a screen share is the safer path. That call requires judgment built from experience across hundreds of engagements, not pattern-matching on training data.
The platform and the advisory team share the same data. When Carbide Analyst produces a gap analysis, a policy draft, a framework mapping, or a board report, a credentialed Carbide advisor reviews that output. The AI makes the advisors faster; the advisors make the AI trustworthy.
For organisations working with a CISO this is what changes: The fractional CISO role has always required pulling together program data, assembling reports, reviewing documentation, and arriving at every client call prepared. Carbide Analyst handles that assembly work in minutes. The advisor’s time goes to the calls that actually require their judgment.
You can give Carbide Analyst full access to your account: your current controls, your evidence records, your task completion rates, your framework obligations, and your vendor assessments. What it does not determine is whether a control interpretation will hold up under auditor scrutiny, when to withhold a sensitive document, or how to push back on an auditor’s scope challenge. Those are advisor judgment calls, built into the process rather than left to you to resolve after the AI has already produced an answer.
Access controls and token management
Access to your compliance program through Carbide Analyst is granular and you control it. Access is managed through scoped tokens across areas including policies, risk assessments, audit requirements, and evidence. Each scope can be set to read-only or read-write independently.
Read-only tokens let your team query the program without the ability to change anything. Read-write tokens enable Carbide Analyst to initiate tasks and update statuses. You can run separate tokens for different use cases and revoke any one of them instantly without affecting the others.
What to do next
If you are a Carbide customer, your advisor can walk you through connecting Carbide Analyst and configuring your first token. The setup takes one conversation. If you are evaluating Carbide, the compliance program Carbide Analyst queries is the same program your advisory team builds and maintains. The AI extends what the advisors already handle. It does not replace the judgment they bring. See Carbide Analyst in action.