oolak / Features / AI assistant
AI assistant

Ask your security data a question, in plain language.

Connect the AI assistant you already use, or a model running inside your own network, and ask things like "which internet-facing servers have critical issues this week?". The assistant works with your permissions, and it can never approve anything on its own.

Every finding with its risk score, exploitation data and owner.

Answers in seconds

Questions about findings, assets, exceptions and deadlines are answered from live data.

Your rules still apply

The assistant sees only what you are allowed to see and can't approve anything.

Your choice of model

Use a local model for full privacy or a commercial model through its API.

AI assistant

What's included

  • A built-in MCP server lets Claude and other MCP-compatible AI assistants work with oolak.
  • Assistants search findings, look up assets, request exceptions and check SLA posture.
  • Local models running inside your network are supported for air-gapped sites.
  • Decision models suggest priorities and exception decisions, and a person confirms them.
  • AI models can be called as steps inside workflows.
  • Scanner text is cleaned and marked as untrusted, so it can't steer the assistant.
  • Changes such as assignment rules need a preview and a confirmation first.
  • Every AI action is marked separately in the audit log.
  • Any agent can use the documented REST API with its own scoped token.

See oolak on your own data in 14 days.

We install oolak in your environment, connect your tools and show you your real risk picture. You keep everything it finds.

Start a free 14-day trial → Try the live demo
For engineers

Technical details

How does the assistant connect?
The MCP server is a thin client of the REST API and uses the user's own API token. It never reads the database directly, so every request passes the same permission and row-scope checks as a person would.
How is prompt injection handled?
Text that comes from scanners and inventories is scrubbed and wrapped as untrusted data before an assistant sees it. There is no approval tool, and state-changing requests require an idempotency key so a retry can't apply twice.
Can we tell people and AI apart in the logs?
Yes. Every request made through the assistant is recorded with the actor type, the tool name and the token prefix.