DUBLIN, Calif. — June 12, 2026, 10:00 a.m. PT — Safeguard, the AI-native software supply chain security platform, today announced that it is now available as a connector in Claude, listed in the Claude connectors directory. The listing puts Safeguard's software supply chain security — vulnerability and SBOM intelligence, AI-powered remediation, and policy enforcement — directly inside Claude, and pairs it with continuous, activity-log-based compliance monitoring for Claude Enterprise and Claude Platform built on the Claude Compliance API.
The connector is the centerpiece. Once a team adds it in Claude — under Settings → Connectors → Add custom connector, with explicit authentication and approval — Claude can call Safeguard's 190+ security tools at the connector endpoint, https://mcp.safeguard.sh/mcp/anthropic. The connector speaks the Model Context Protocol over standards-compliant transport (HTTP and SSE), authenticated with OAuth 2.0 or a scoped API key — so it runs inside Claude's own connector controls, approved per user.
How Teams Use the Connector
From inside Claude, in plain language — no query syntax — teams can:
- Query vulnerabilities and findings across every project, by CVE, severity, or status.
- Explore SBOMs, packages, and licenses — components, transitive dependencies, and license obligations pulled straight from real SBOMs.
- Generate AI-powered remediation plans for npm, pip, Maven, Go, and Cargo — with upgrade paths and breaking-change notes.
- Compare and analyze SBOMs in CycloneDX and SPDX to see what changed between builds and releases.
- Reach real code across GitHub, GitLab, Bitbucket, and Azure DevOps to scope questions to actual repositories.
- Surface risk scores, compliance posture, and policy-gate decisions — and see exactly why a build would pass or be blocked.
Typical first prompts are as direct as "Find critical vulnerabilities across my projects," "Generate a remediation plan for my npm project," or "Which packages violate my license policy?"
How It Helps Secure the Software Supply Chain
The connector turns Claude into a front door for the supply-chain security work teams already do in Safeguard. Instead of switching tools to answer "which of our projects are exposed to this CVE?" or "what breaks if we upgrade this package?", a developer or security engineer asks Claude and Safeguard answers from the same system of record — with cited findings, real SBOM data, and concrete fix paths. Policy gates make those answers enforceable: a build that violates policy is flagged with exactly why, so risk is caught before it ships rather than after. Safeguard is multi-tenant, so large organizations keep teams and data cleanly isolated.
Continuous Compliance, Built In
Alongside the connector, the Claude Compliance API integration gives security and compliance teams continuous governance of Claude usage itself. Safeguard ingests activity logs from Anthropic-hosted Claude Enterprise and Claude Platform deployments and evaluates them against policy in real time — producing immutable audit trails, anomaly detection, and audit-ready evidence mapped to SOC 2, NIST, and PCI-DSS. It works with activity logs only: conversation content is never accessed, and Safeguard does not control, restrict, or modify Claude's behavior.
"Listing Safeguard as a connector in Claude puts our software supply chain security where engineers already work," said Hritik Kumar Sharma, Founder and CEO of Safeguard. "A developer can ask Claude which projects a new CVE touches and get an answer backed by real SBOM data and a concrete fix — while the security team gets continuous, audit-ready governance of how Claude is used, from the same platform. Both run inside Claude's own connector controls."
How to Enable the Connector
- Create or sign in to your Safeguard account at app.safeguard.sh.
- In Claude, open Settings → Connectors → Add custom connector.
- Name it "Safeguard Security" and set the URL to
https://mcp.safeguard.sh/mcp/anthropic. - Approve the authentication — sign in to Safeguard and click Approve.
- Safeguard's 190+ security tools are now available to Claude. Start asking questions.
Developers can also wire the same endpoint into a desktop client via mcp-remote; an SSE transport (https://mcp.safeguard.sh/mcp/sse), an OpenAPI spec (https://mcp.safeguard.sh/openapi.json), and a health check (https://mcp.safeguard.sh/health) are available. Enterprises can request a demo or explore the integrations catalog to get started.
Frequently Asked Questions
What is the Safeguard connector in Claude?
It is a connector listed in the Claude connectors directory that makes Safeguard's 190+ software supply chain security tools available inside Claude — query vulnerabilities and SBOMs, generate remediation plans, and enforce policy gates in plain language. It connects over the Model Context Protocol at https://mcp.safeguard.sh/mcp/anthropic, authenticated with OAuth 2.0 or a scoped API key.
How do I add the connector in Claude?
In Claude, open Settings → Connectors → Add custom connector, set the URL to https://mcp.safeguard.sh/mcp/anthropic, then sign in to Safeguard and click Approve. Full steps live in the Safeguard integrations catalog.
How does the connector help secure the software supply chain? It brings Safeguard's vulnerability and SBOM intelligence, AI-powered remediation, and policy-gate enforcement into Claude, so engineers can investigate and fix supply-chain risk conversationally — answers come from Safeguard's system of record, with cited findings and concrete fix paths.
Does it read Claude conversation content? No. The companion Claude Compliance API integration works with activity logs only — it does not access conversation content, and it does not control, restrict, or modify Claude's behavior.
Which Claude deployments are supported? The connector works with Claude; the Compliance API integration applies to Anthropic-hosted Claude Enterprise and Claude Platform deployments.
On Social
Logos & Brand Assets
Safeguard brand assets are available in the Safeguard press kit. Claude is a product of Anthropic; Claude and Anthropic are trademarks of Anthropic, PBC. Official, unmodified Claude and Anthropic logos must be obtained from Anthropic and used per their guidelines — Claude logos: https://assets.anthropic.com/web/84339bb83a4cc7eb/claude-logos/ ; Anthropic logos: https://assets.anthropic.com/web/5359dc6fda7e5428/anthropic-logos/ (see anthropic.com/news). Use Slate on light backgrounds and Ivory on dark backgrounds; maintain clearspace of at least the height of the Claude spark around the Claude logo, and at least 1.5× the height of the "A" around the Anthropic logo. Logos are shown separately and are not combined with the Safeguard logo into a co-branded lockup.
About Safeguard
Safeguard is the software supply chain security platform that helps security and compliance teams secure their software supply chain and their use of AI. The platform unifies SBOM analysis, reachability-aware vulnerability management, policy gates and guardrails, MCP server governance, and continuous compliance — including SOC 2, NIST, and PCI-DSS — into a single system of record. Learn more at safeguard.sh, browse the connectors directory, or read the Safeguard blog. Read the announcement on LinkedIn and X.
About Claude's Compliance API
Claude's Compliance API is a capability from Anthropic that gives Claude Enterprise and Claude Platform administrators programmatic access to activity logs from their Anthropic-hosted deployments, supporting governance, monitoring, and audit use cases. Claude is a product of Anthropic. For official product details, see anthropic.com. (This is a factual product description, not a statement, quote, or endorsement by Anthropic.)
Official Claude resources: Get started with Claude Compliance API integrations · Claude blog: Compliance API security partners · Claude for Business on LinkedIn
Media Contact
Claude and Anthropic are trademarks of Anthropic, PBC. This integration uses Claude's Compliance API and works with activity logs from Anthropic-hosted Claude Enterprise and Claude Platform deployments only. Safeguard is an independent company; this announcement does not imply endorsement, certification, or sponsorship by Anthropic.