September 2026 · Siemba News
Siemba MCP is now generally available. It's a Model Context Protocol (MCP) server that connects the Siemba offensive security platform directly to MCP-enabled AI assistants. It ships as a single plugin containing the connector and six skills: Test Analysis, Kill Chain, Critical Briefing, Remediation Plan, Attack Surface and CISO Report and more.
Security and engineering teams can ask a question in plain English and get finished security analysis back, without opening a dashboard or logging in separately. Siemba MCP is included at no additional cost for Siemba platform customers.
Siemba MCP is a Model Context Protocol server that gives AI assistants direct access to Siemba's security data and testing capabilities. MCP is an open standard that lets AI clients connect to external tools and data. With Siemba MCP, the assistant works with the platform itself rather than a summary of it. Siemba announced general availability on September 22, 2026.
You can start and analyze security testing through a conversation. You name a target, and Siemba enumerates it, builds the appropriate test suite and starts running it automatically. You can then use Siemba's skills for expert-level analysis and reporting on the results.
"You can now run pentests by chatting with your LLM," said Kannan Udayarajan, CEO of Siemba. "The MCP server gives your assistant the platform itself, not a summary of it."
Each skill is invoked with a simple command and runs a packaged workflow on top of the Siemba platform's test orchestration and analysis tools.
Siemba MCP brings the answer to where you already work. With a dashboard, you log in, find the data, and then do your analysis and reporting separately, often in spreadsheets. With Siemba MCP, you ask the question in your AI client and get finished analysis back. There's no console to open, no separate login and no switching between tools.
Yes. Every call through Siemba MCP is secured with OAuth 2.1 with PKCE and requires multi-factor authentication. Tokens rotate, calls are rate-limited, and access is scoped to the requesting account only.
Siemba MCP is also designed to limit the damage if a session is compromised. Access stays contained to:
and all activity is fully logged.
Siemba MCP is available now to customers on the Siemba platform, bundled at no additional cost. It works with MCP-enabled AI clients. Setup instructions and the server endpoint are at mcp.app.siemba.com.
Siemba is an offensive security company headquartered in Alpharetta, Georgia. It combines attack surface mapping, autonomous dynamic testing, AI-driven vulnerability assessment and expert-led penetration testing in one continuous program. Its coverage includes web, mobile, cloud and AI systems, including large language models and AI agents. Siemba has been named a Sample Vendor in the Gartner® Hype Cycle™ for Application Security, Security Operations, and XaaS in 2024, 2025 and 2026.
What is an MCP server?
An MCP server uses the Model Context Protocol, an open standard, to let AI assistants connect to external tools and data. Siemba MCP connects AI assistants to the Siemba offensive security platform.
Can I run a penetration test from an AI assistant with Siemba MCP?
Yes. You name a target, and Siemba enumerates it, creates the right test suite and starts testing automatically.
Which compliance frameworks does the CISO Report cover?
It covers ISO 27001, HIPAA, OWASP, GDPR, CMMC, NIST SP 800-53 Rev. 5 and PCI DSS v4.0.
What happens if a Siemba MCP session is compromised?
Access is limited to one user's permissions, on that customer's assets only, with non-destructive actions only, for a maximum of one hour, and all activity is logged.
How much does Siemba MCP cost?
It's included at no additional cost for Siemba platform customers.