Skip to main content

New AI Agents Live in Minutes – AI Orchestration Layer (Claude, MCP) for a US Cybersecurity Platform

Since 2020 we took a US cyber risk platform from prototype to Fortune 500 SaaS (+150% revenue), then added a Claude + MCP AI layer: new agents live in minutes.
New AI Agents Live in Minutes – AI Orchestration Layer (Claude, MCP) for a US Cybersecurity Platform
  • Client

    🔒 NDA

  • Location

    🇺🇸 USA

  • Cooperation dates

    July 2020

  • Project status

    🟢 Ongoing

  • Scope of work

    ResearchMVP DevelopmentPrioritization and Long Term RoadmapScalingAI ArchitectureMCP integration

We have been the design and development partner of a US cyber risk platform since 2020, taking it from a prototype to a SaaS with Fortune 500 customers, +150% revenue in one year and 400% growth in B2B clients. In 2025 we rebuilt its runtime around an AI agent powered by Anthropic's Claude. The platform now works as an orchestration layer for the customer's whole security stack, and the customer's own admins ship new AI agents without engineering involvement.

From prototype to SaaS used by Fortune 500 firms

The client, a cybersecurity company founded in 2015, came to us with a prototype decision-making tool for C-suite executives, extensive technical documentation and paying corporate customers. The product was entirely offline. Our task was to turn it into a scalable SaaS without losing momentum. A product discovery process produced a prioritized feature list; we then built a custom front end that translates the platform's mathematical risk model into information executives can act on, aligned with NIST and CIS frameworks. Because the platform handles highly sensitive data, we set up a dedicated GCP cluster in the client's preferred location.
 

After the MVP we extended the product to a second audience, private equity firms. The corporate customer base more than tripled within 3.5 months of launch, from 8 to 26 customers, bringing in major market players and Fortune 500 clients, revenue grew 150% in one year and B2B clients grew 400%. NPS stayed consistently above target throughout.

The Challenge in 2025


The platform was mature, respected and underused: expert-level interpretation was required, most users logged in quarterly, and onboarding needed 45 minutes with support. The client wanted agentic AI inside the product, for a Fortune 500 customer base with strict security requirements. Adding a chat window was not an option. The AI had to run in production, across tenants, on live security data, without expanding the audit boundary.

Our Approach: Architecture


We rebuilt the runtime around three decisions that matter for enterprise AI deployments: how the agent reasons, how it stays inside the customer's boundaries, and how it connects to the customer's live security stack.
 

Inside the agent: reasoning and security

Reasoning: Claude at the core.

Aria plans investigations across dozens of tools, runs multi-step “Do it for me” commands on live security data and keeps multi-turn context. It uses different Anthropic models per task; new models go live within a day. Orchestration runs on LangGraph.

Security by construction.

Each tool is bound to the user, organization and profile; the model can’t see or change that identity, so it can’t reach tools outside its tenant. Business unit names are pseudonymized before reaching the model. Security controls stay unchanged.

Live integrations through MCP.

Aria connects to the customer’s security stack via the Model Context Protocol, starting with CrowdStrike Falcon, with OAuth 2.1 per profile. Any MCP-compliant tool can be added; Aria is also becoming an MCP server for Claude Desktop and Cursor.

Admin-defined agents.

The customer's administrator creates new Claude-powered specialists from the application UI: name, prompt, tools. New agents go live for the whole organization in minutes, without a release.

The Solution

The platform's core infrastructure, data model and codebase stayed intact; the AI layer sits on top, not inside. Structurally, the product changed from an analytics tool into an orchestration layer for the customer's security operation. Product evolution is no longer gated by release cycles: the admin team ships new agents, prompts and connectors to live security tools directly from the UI.

The Results

+150% revenue in one year

after the platform launch (2020–2023, before the AI layer)

400% growth in B2B clients

including Fortune 500 companies.

New AI agents, prompts and workflows live in minutes

configured by the customer's admins without engineering.

Security architecture unchanged

Embedded AI added without expanding the audit boundary; cross-tenant access cannot be bypassed by prompt injection.

Live security stack connected through MCP

starting with CrowdStrike Falcon.

No rewrite of the core platform.

Core analytics engine preserved; AI added as a layer.

Let's talk about adding an AI layer to your existing platform

Book a free consultation

Ready to centralize your know-how with AI?

Start a new chapter in knowledge management—where the AI Assistant becomes the central pillar of your digital support experience.

Work with a team trusted by top-tier companies.

Siemens logo
PwC logo
Toyota logo