The StorageGuard Model Context Protocol (MCP) server connects StorageGuard to your organization's approved enterprise AI platform, and the StorageGuard AI Assistant puts a natural-language chat interface on top of it. This article is for administrators who install the MCP server, configure an AI provider, validate connectivity, and open the AI Assistant for the first time.
APPLIES TO: STORAGEGUARD 10+ / ADMIN ROLE REQUIRED
In this article
How the integration works
The MCP server acts as a controlled bridge between StorageGuard and your AI environment. It exposes StorageGuard data to an approved enterprise AI platform — such as OpenAI GPT, Microsoft Copilot, Anthropic Claude, or Google Gemini — so that authorized users can query that data in natural language.
The AI Assistant is built on top of the MCP server and runs as an embedded chat panel inside the StorageGuard user interface. It analyzes findings, reviews configurations, investigates risks, and returns recommendations based on live StorageGuard data. Install and connect the MCP server first; the assistant becomes available once that connection is working.
Before you begin
Confirm all of the following before you start:
- StorageGuard version 10 or later. AI integration is not available in earlier versions.
- Node.js 22 or later on the StorageGuard virtual machine. The installer checks for this and stops if it is missing.
- An AI/LLM endpoint from your organization's approved AI platform, reachable from the StorageGuard VM.
- A valid API key for that AI provider.
- The MCP server installation package, available from your Core6 account manager.
- Administrator permissions in StorageGuard, and access to the StorageGuard VM file system and services.
Note: StorageGuard does not provide LLM infrastructure. You connect the MCP server to your own AI service endpoint, and your organization owns the contract, the usage costs, and the data-handling terms with that provider.
Install and configure the MCP server
Four steps, in order: install the server, add your provider API key, restart the Tomcat service, then test the connection from the StorageGuard UI.
Step 1: Install the MCP server
- Request the MCP server installation package from your Core6 account manager.
- Copy the relevant MCP installer build to the virtual machine where StorageGuard is installed.
- Double-click the installer to launch it.
- Accept the license agreement.
- Wait for the installer to verify that Node.js 22 or later is present.
- Click Next through the remaining wizard screens.
- Confirm the installation path:
[DRIVE]:\CSPlatform\MCP\ - Confirm the StorageGuard URL.
- Click Install.
- Wait for the installer to report that installation completed successfully.
Note: If Node.js 22 or later is not detected, the installer displays a message and stops. Install a supported Node.js version on the VM, then run the installer again.
Step 2: Add your AI provider API key
- On the StorageGuard VM, go to
C:\CSPlatform\MCP\Client - Open the
.envfile in a text editor. - Locate the API key parameter for the AI provider you plan to use.
-
Replace the placeholder value with your provider's API key. For Anthropic, the line reads:
ANTHROPIC_API_KEY=[your_api_key_here]
- Save the file.
Note: Only the key for the provider you selected is required. Leave the other provider keys blank.
Caution: The .env file holds a live credential in plain text. Restrict file system access to the account that runs the MCP service, and rotate the key through your provider if the file is ever shared or copied off the VM.
Step 3: Restart the Tomcat service
Restart the Tomcat service on the StorageGuard VM to apply the MCP configuration changes. StorageGuard does not pick up the new .env values until the service has restarted.
Step 4: Verify the MCP connection
- Log in to the StorageGuard UI.
- Go to Settings > Interfaces > MCP.
- Enter the connection details for your AI platform.
- Configure the authentication settings required by your organization.
- Select Test connection.
- Confirm that the test completes successfully.
- Select Save.
Once the connection test succeeds, the MCP server is ready to process AI requests and the integration is operational.
Open the AI Assistant
With the MCP server configured and connected to a supported LLM endpoint, the AI Assistant becomes available inside StorageGuard.
- Open the AI Assistant panel.
- Enter a question or request in the chat window.
- Select Send.
Verify it worked
The AI Assistant panel opens inside the StorageGuard interface and your first question returns a response drawn from live StorageGuard data — not a generic answer. A useful first test is a question with a verifiable answer, such as asking how many storage systems were scanned in the most recent run, so you can check the response against the UI.
If the panel does not open, or opens but returns nothing, work through Troubleshooting before going further.
What you can ask the AI Assistant
The assistant works against the data StorageGuard has already collected. Use it to:
- Investigate security risks
- Review compliance and baseline violations
- Analyze exposure and configuration issues
- Explore scanned infrastructure
- Generate reporting insights
- Support remediation workflows
Prompts to try:
- Show me storage systems that are not compliant with our security baseline.
- Identify backup systems affected by high-severity vulnerabilities.
- Summarize hardening opportunities across the environment.
- Review exposure risks for internet-facing assets.
Tip: Name the scope in the prompt — a site, a system type, or a severity level. Narrow questions return answers you can act on; broad ones return summaries you then have to narrow yourself.
Security and governance
The StorageGuard AI integration ships with security controls and operational guardrails:
- Role-based access control (RBAC)
- Scope enforcement
- No direct system access by the AI platform
- Protection of sensitive credentials and secrets
- TLS-secured communication
- Logging and auditing
Together these keep AI interactions inside the same access boundaries as the rest of StorageGuard, so a user cannot reach data through the assistant that they could not reach through the UI.
Troubleshooting
| Symptom | What to check |
|---|---|
| The AI Assistant is unavailable | The MCP server is running; the AI endpoint is reachable from the StorageGuard VM; the MCP configuration was saved successfully in Settings > Interfaces > MCP; the user account has the required permissions. |
| The assistant opens but returns no response | The configured LLM endpoint is operational; network connectivity exists between the MCP server and the AI platform; the API key in .env is valid and has not expired; the Tomcat service was restarted after the key was added. |
Still need help?
Open a ticket from the Core6 Support portal. Include your StorageGuard version and, where relevant, the scan task name and run timestamp.
Comments
0 comments
Please sign in to leave a comment.