Announcing Surf AI's Integration with the Claude Compliance API
AI is only as powerful as what you connect it to. Through MCP and connectors, Claude can reach directly into the tools where work actually happens. Once it is connected to your systems, it stops being something you talk to and becomes something that does the work alongside you.
That same reach is also where the exposure begins. Every connector opens up access to sensitive data along with the ability to act on it, and the connections that no one formally approved tend to be the ones that spread fastest and stay hidden longest. The value is real, but so is the risk that comes with it.
Claude became a core enterprise system almost overnight
As more teams put Claude to work across their day-to-day workflows, security and compliance groups have quietly inherited a new operational problem. They can increasingly see the AI activity happening across the organization, but being able to see it is not the same as being able to do anything about it.
That leads to new risks. Connectors get added that no one sanctioned. People who have left the company hold on to access they were supposed to lose. Sensitive content makes its way outside the organization without anyone really noticing. Most of the AI governance tooling available today is good at telling you what happened. What it usually cannot do is tell you who actually owns whatever was touched, or take any meaningful step toward fixing it. That gap between knowing and resolving is the one Surf AI was built to close.
What that looks like
Consider a connection that no one signed off on. When someone wires up a custom MCP server that sits outside your sanctioned registry, Surf surfaces it, works out who connected it, and routes it to the team responsible for making that call. Organizations also have the option to implement workflows that can automatically fix and deactivate unsanctioned MCP connections.
Offboarding is another familiar gap. If an employee leaves but their Claude access is still live afterward, Surf correlates the activity feed against Okta and Workday to confirm the identity has genuinely been terminated, models what that lingering access could reach, and routes a single-click revocation to whoever is accountable, so that access does not quietly outlive the employment it was tied to.
The same pattern holds when content leaves the building. If a project or file containing sensitive material gets shared outside the company, Surf picks up the event, connects it back to an owner by cross-referencing identity and data classification, models the potential exposure, and routes it for review before it turns into something worse.
In each of these cases Surf follows the issue all the way through rather than stopping at the alert. It writes the outcome back to the systems involved and leaves a complete, timestamped record on both sides.
Why resolution is the harder problem
Detection has rarely been the difficult part of security work. The difficult part is everything that comes after it: finding the owner, understanding the impact, and actually getting to a fix. This integration carries Claude governance through that harder stretch, giving each piece of AI activity an owner, a safe path forward, and a clear resolution. The practical effect is that Claude ends up governed like any other enterprise system, and the things it does no longer pile up unowned in a queue.
This is only the beginning. We expect to add more use cases over time, and the same approach to ownership and remediation will carry through each of them.
To learn more, or to see the integration in action, visit www.surf.ai.
Prasad Raman is Head of Technology Partnerships at Surf AI, with a decade of experience building alliance and partnership programs across the security industry.
