Jacksonville, FL, September 17, 2026. UnderDefense, a cybersecurity company delivering Agentic AI SOC and Compliance AI to enterprise clients across the US and EU, today announced the launch of MAXI MCP, a single connection that brings SIEM, EDR, and SOC data directly into the AI assistants and IDEs security teams already use, including Claude, ChatGPT, Cursor, and any other MCP-capable client.
Most investigations still move by hand across four or five consoles, each with its own login and query language, before an analyst can even start comparing what they found. MAXI MCP removes that step: one authenticated connection reaches every source already live in a tenant, and the assistant does the moving instead of the analyst.
What Used To Take Four Logins
Wednesday, 11:20. An analyst spots a host behaving oddly. Then comes the usual route: Elastic, then Splunk, then Darktrace, then Defender. Four consoles, four query languages, four logins. Context gets carried by hand, and half the time goes to something other than the investigation.
Now he writes one sentence to his assistant: check this host across all sources for the last 24 hours.
The assistant goes to Elastic for processes, Darktrace for network, SentinelOne for the endpoint, and MAXI for open incidents tied to that asset. It comes back with one answer and a list of every query it ran.
One conversation instead of four tabs.
That is how it works now. MAXI MCP is one secure entry point to all your security data, from the AI assistant you already use.
One Connection Instead Of Every Console
- Every MAXI integration behind one endpoint. Not a fixed list. Exactly what is already connected in your tenant: the MAXI data lake plus your SIEM, EDR, cloud, identity, network and UEBA tools. Each source used to mean its own access and its own console. Now it is one MCP Gateway and one way in. Add a new integration to MAXI and it shows up in the assistant on its own.
- One sign-in instead of a key for every system. You connect over OAuth 2.1 with PKCE and dynamic client registration. There is no API key to create, store or rotate. The assistant never receives your MAXI password, and tokens expire.
- This is the same gateway our own AI SOC uses. The Investigation Agent and CISO Copilot reach this data the same way. You are not getting a stripped-down copy for outsiders. You get the same access.
- It works where you already work. Claude, Claude Code, ChatGPT, Cursor, VS Code, Codex, Windsurf, Zed, and any other MCP-capable client. The data comes to your terminal, your IDE, your document. Not to one more browser tab.
Access You Do Not Have To Rebuild
- The assistant sees exactly what you see. Your role and your tenant decide which tools appear in the session. No access in the console means no tool for the agent. There is no second permission model, so nothing can drift out of sync.
- Other tenants are out of reach by design. Every call is scoped to your tenant at the gateway. A request for someone else’s ID is denied, even if that object exists in another tenant.
- The tool list is assembled for you. The gateway checks which connectors are actually live in your tenant and publishes only those. No Splunk means no Splunk tools. The agent never sees what you do not have, and never offers what would not work.
- Read only. Search, query, details. The connector does not modify detection rules, policies or platform configuration. The assistant can look at everything and break nothing.
- Every call is logged. Who, from which tenant, which tool, which connector, how long it took, how it ended. Activity through an assistant is attributable to a user, exactly like console activity.
- US and EU stay separate. Two independent regional deployments. A request to one region is never served from the other, and data does not cross the line.
- We do not train models on your data. Full stop.
Compliance In The Same Conversation
Frameworks, audit readiness, tasks, controls, policies, evidence, autochecks, and the risk register are all available through the same connection.
That means you can read a draft policy or a vendor contract on your own machine and ask right there whether the data retention clause conflicts with your current policy. Or ask what is blocking SOC 2 readiness and get the failed controls, overdue tasks, and missing evidence instead of a link to a dashboard.
Compliance tools follow the role too. An Auditor sees one thing, a Restricted Collaborator only their own tasks, an Employee only policies.
What People Actually Ask It
Walk me through incident 4821. What evidence led to that verdict?
Which detections produced the most false positives this month, and which are worth tuning?
Any endpoints missing an agent, or log sources that went silent?
What did we expose to the internet in the last 30 days, and how is that different from last month?
Summarise last month: volume, response times, and the two incidents that mattered.
MSSPs, This Is For You Too
Running on MAXI and serving your own clients? One service-scoped token reaches every tenant in a single session. A comparative view across clients, several QBRs prepared back to back, one pattern traced across environments. No re-logins, and no separate credentials per client and per tool.
Try It
One-click install: underdefense.com/maxi-mcp. Pick your region and your harness, and the button does the rest.
Direct endpoints:
US – https://mcp-gateway.us.app.underdefense.com/mcp
EU – https://mcp-gateway.eu.app.underdefense.com/mcp
The region has to match where your tenant lives. Pick the wrong one and sign-in simply fails, because your account does not exist there.
Your security data should not live in a separate tab.
One connection. Every source you have. Your assistant.
To see it in action: underdefense.com/book-a-demo
About UnderDefense
UnderDefense is a global cybersecurity company operating across the United States, Europe, and international markets.
Its Agentic AI SOC is a vendor-agnostic security operations platform that integrates with clients’ existing SIEM, EDR, cloud, identity, and security infrastructure. The platform combines autonomous AI-driven triage with experienced human analysts who retain decision authority over confirmed incidents and response actions.
UnderDefense serves organizations across multiple industries, including financial services, healthcare, technology, telecommunications, and the public sector.
UnderDefense
111 John Street, Suite 420
New York, NY 10038
United States
Tel: +1 (929) 999-5101




