Data access

One dataset. Five doors. Zero lock-in.

Every audience reads the same live data through whichever door fits their work. The web platform for teams and executives, CSV and JSON export for analysts and auditors, a REST API for engineers, MCP for AI assistants, and A2A for agent-to-agent automation. Same dataset, same strict organisation-level isolation, on every door.

The five doors

Five ways to consume the data.

  1. Web platform

    The full experience for security teams and executives: dashboards, inventories, posture ratings, AI analyst briefings, investigation tools, governance workflows, and the Ontology & Apps automation layer.

  2. CSV / JSON export

    40+ inventory and report views export directly. No row caps, no truncation. Exports honour on-screen filters, search and sort order, so what is downloaded is what was on screen.

  3. REST API

    A versioned, read-only API for engineers and integrators feeding Klarvant data into their own tooling: SIEM, ticketing, CMDB, risk platforms. 34 documented operations, plus a backward-compatible mirror of the previous generation.

  4. MCP

    8 read-only tools that plug Klarvant into AI assistants such as Claude via the Model Context Protocol. Analysts ask questions in plain language and get answers grounded in their own attack-surface data.

  5. A2A

    An Agent2Agent endpoint on the open Linux Foundation standard v1.0, with 9 published agent skills, so customer and partner agents can query Klarvant inside automated workflows, deterministically or conversationally.

What is common to all five

  • The same live dataset. A number retrieved through the API, asked for through an AI assistant, or read on a dashboard is the same number.
  • The same strict organisation-level isolation. A credential can never see beyond the organisation, and where applicable the organisational unit, it belongs to.
  • The REST API, MCP and A2A machine interfaces are read-only by design. No external integration can modify platform data. (Apps, part of the platform itself, act from the inside under the same isolation and log every action in the App actions ledger.)

Agent-ready

A2A: the nine published skills.

Namespace Command implements the open Agent2Agent (A2A) protocol v1.0, governed by the Linux Foundation, so agents built on any major agent framework can discover and query the platform. The publicly discoverable agent card advertises nine skills.

SkillWhat it returns
describe_orgOrganisation profile and live finding vocabulary.
list_inventoryAsset inventory browsing across domains, DNS records, certificates, TLS endpoints, IP addresses, suppliers, web pages and email security records.
search_gapsFaceted security-finding search.
get_gapFull evidence, history and remediation guidance for a single finding.
impact_searchFederated exposure search across the whole estate.
certificate_postureCertificate expiry posture.
tls_postureTLS protocol and cipher posture.
supplier_exposureThird-party supplier and supply-chain exposure.
analyst-qaA conversational security analyst that plans and executes the deterministic skills and answers in plain language, with the grounding evidence attached.

Two invocation styles: a deterministic call path for high-volume automated workflows, and a conversational path for agent platforms that relay natural-language questions. Read-only. Scoped to the organisation. Enabled per organisation by an administrator.

Two enterprise use cases the agent is built for

Supply-chain first response.

The moment a vendor incident breaks, the agent answers "where are we exposed to this supplier, product or technology?" across the whole estate. The supplier_exposure and impact_search skills are built for exactly that fan-out.

Post-quantum cryptography transition.

National-standards guidance makes clear the migration must start now, before "store now, decrypt later" attacks mature, and it starts with knowing where an organisation's public-facing cryptography lives. The agent serves the continuously refreshed certificate, TLS endpoint, protocol and cipher posture on demand over the open A2A standard, so security and infrastructure teams, and their agents, can plan, prioritise and evidence the transition.

Governance

Machine interfaces you actually govern.

  • Each machine interface (REST API, MCP, A2A) is a separately switchable product per organisation. Off by default. Your own administrator turns it on and mints keys.
  • Keys are bound to one interface at minting, carry granular read scopes aligned to your licensed modules, and can be rotated or revoked at any time.
  • Calls can be restricted to approved IP addresses (deny-by-default, with one-click presets for common AI and automation vendors), and keys can be annotated with notes.
  • Administrators are prompted to review keys whose creator has left the organisation.
  • The full API reference, the MCP tool catalogue and the A2A reference are published inside the platform, generated from the running system, so the documentation cannot drift from reality.

See it running on your own estate.

We run zero-integration discovery against your namespace before the call, and can demo whichever door your team consumes through.

Book a demo