Agentic security workflows
Anthropic's Claude reading live security data and producing the artefact your team has to file — a vendor decision, a triage order, a board briefing — with the evidence trail attached.
Security work is a better candidate for AI than most of what is currently being automated, for an unglamorous reason: the inputs are already machine-readable. Ratings, findings, advisories, asset inventories and control frameworks are structured data, and a great deal of skilled analyst time goes into assembling and cross-checking them rather than into judgement. The judgement still belongs to the analyst. The assembly does not have to.
What that demands in return is an evidence trail. A security answer is used to sign off a vendor, brief a board or satisfy an auditor, so it has to be checkable rather than trusted — which rules out most of what is currently sold as enterprise AI, and is the constraint everything below is designed around.
Most AI consultancies ask you to take the engineering on trust. Ours is on GitHub. BitScoreCoWork is an MIT-licensed Claude plugin we built and published: a zero-dependency MCP server wrapping the Bitsight REST API, plus sixteen skills that turn ratings data into vendor decisions, exposure sweeps, board packs, framework evidence, regulatory incident notifications and scoped security-testing plans. Install it, point it at your own Bitsight tenancy, and it runs — it is not a demo we drive.
Vendor portfolios triaged continuously rather than annually: measured posture read from Bitsight and your own sources, assembled into pre-contract due-diligence briefs and renewal reviews that end in a recommendation and the clauses worth negotiating. This is where the hours are, and where a questionnaire is least informative.
When an advisory lands, the question is which of your entities and vendors is observably exposed, and in what order to call them. Agents sweep the estate, attach the evidence, and produce a triage order — a job that is mechanical, urgent, and consistently done late because it is done by hand.
Findings mapped to NIST CSF 2.0, ISO/IEC 27001:2022 and Indian obligation areas — RBI, SEBI, IRDAI, IFSCA, CERT-In and DPDP — with each row marked by where its evidence came from. An outside-in view evidences the external surface and no more, so the honest output is an evidence pack the compliance team works from, not a verdict.
The recurring translation problem: posture into a page a board can act on, and, where it is wanted, into an indicative financial exposure range with every assumption on show. Assembled in minutes, in your house style, from data that is current on the day of the meeting rather than the day the deck was started.
Identity, access control, retention, logging and evaluation, deployed into your own Google Cloud tenancy. Your data stays in your environment. This is the part that determines whether a pilot becomes production in a regulated organisation, and it is routinely the part left until last.
With one security workflow, not a platform decision. We look for something expensive, repetitive and evidence-heavy — vendor due diligence, exposure triage, framework evidence, board reporting — build it properly end to end, and establish whether the accuracy, the controls and the economics actually work for your organisation. That produces something your team keeps using and a real basis for the next decision, which a proof of concept generally does not.
Nimitt Jhaveri, BitScore's Managing Partner, is a judge for FIND EVIL!, the SANS Institute hackathon on autonomous AI agents for incident response, which ran from April to June 2026. Entrants built agents that detect and triage a live intrusion in seconds rather than hours, and judging meant assessing dozens of them against the question this whole practice turns on: can you tell what the agent actually saw, and would you let it act on that alone?
It is a useful vantage point. Seeing where a hundred serious attempts at agentic defence succeed and where they quietly break is a faster education in the failure modes than building alone, and the answers feed straight back into what we are willing to put in front of a client.
BitScore is an authorised partner for Bitsight, a solutions partner for Anthropic's Claude frontier AI, and a cloud partner for Google Cloud, which is the deployment platform for the AI work.
AI systems for security and risk work: agents that read live security data and produce the artefact a team has to file — a vendor decision, an exposure triage, a framework evidence pack, a board briefing — plus the deployment work around them, meaning identity, access control, retention, logging and evaluation. BitScoreCoWork, our open-source Claude plugin for the Bitsight API, is the same pattern published in full.
Because it is the domain we already answer for. BitScore runs a cyber risk practice as an authorised Bitsight partner, so the data, the failure modes and the standard of evidence are familiar rather than researched. Security work is also unusually well suited to AI: the inputs are machine-readable, the analyst hours go into assembling and cross-checking rather than judgement, and every output has to survive an auditor.
In your own Google Cloud environment, under your enterprise controls and your existing identity model. BitScore builds and deploys into your tenancy rather than hosting your data in a BitScore product — which matters when the material is your own attack surface, vendor assessments and audit evidence.
Only where you decide it should, and our default is narrower than most buyers expect. The systems we build read, correlate and draft; actions with consequences stay behind human approval. The security-testing skills in our own plugin illustrate the principle — they produce a scoped engagement plan for licensed testers to run, and never execute anything.
With one security workflow that is expensive, repetitive and evidence-heavy — vendor due diligence, exposure triage, framework evidence or board reporting — rather than with a platform decision. A single well-chosen workflow establishes whether the accuracy, the controls and the economics work for your organisation, and produces something your team keeps using.
The fastest way into a useful conversation is one concrete security process that costs your team real hours — vendor reviews, exposure triage, evidence packs. We will tell you honestly whether it is a good candidate; several are not.