Salt Security launches Claude Connect to inventory MCP servers on Claude Enterprise
Salt Security said Tuesday it introduced Salt Claude Connect, an integration that gives security teams continuous, read-only visibility into the Model Context Protocol servers connected to their Claude Enterprise organization through Claude’s Compliance API.
Companies are connecting outside tools to Claude faster than a security team can write them down. Salt Claude Connect is a live list of those connections for teams that already use Salt, and the list does not include the chats.
On Tuesday, 29 September 2026, Salt Security introduced Salt Claude Connect. The announcement went out on PR Newswire, datelined Palo Alto, California. The page stamps it Sep 29, 2026, 12:01 ET, which is 12:01 p.m. Eastern. Salt calls itself the leader in agentic and API security. Agentic, in that phrase, means software that takes actions, not only a chatbot that replies. Those lines are Salt’s.
What the product is. Salt Claude Connect gives a security team a continuous, read-only view of the Model Context Protocol servers connected to that team’s Claude Enterprise organization. MCP, the Model Context Protocol, is a shared plug that lets Claude call outside tools, databases, and services. The integration uses Claude’s Compliance API, the door Claude provides for this kind of check, to put the organization-managed MCP servers into a Salt inventory. Organization-managed means an administrator connected them for the company. The inventory records when each server was added, updated, or removed, and what its status is now. Those lines are Salt’s, in the release.
What the list shows. Salt says the integration reads the organization’s activity feed through that API and places the servers in the Salt inventory. The screenshot on the announcement calls that list the Salt Agentic inventory. Each server is labeled by where it came from. The row shows the server name, the status, and the time of the most recent lifecycle event. A lifecycle event is the record that the connector was added, updated, or removed. The list keeps updating as connectors change. Salt’s product page says the same row also carries a unique identifier, and that a change usually appears within one polling cycle. A polling cycle is one pass Salt makes through the activity feed. The product page also says these Claude servers sit in the same inventory as APIs, hosts, and Salt’s other agentic surfaces. An API is the door one program uses to talk to another. Those lines are Salt’s.
How narrow the access is. The release says the integration is built for least privilege, the smallest access that still does the job. It needs a single read-only scope, and it reads only MCP server lifecycle activity. It never sends prompts to Claude. A prompt is the instruction a person types into the chat. It never reads chat content, file content, or project data. The only information Salt says it stores is those lifecycle events. It never changes the Claude organization. Salt’s product page adds that the access key is stored encrypted and is used only to sign in to the Compliance API. The same page says the integration does not store user-level activity or personal workspace data, and that it does not require an agent on the network or a copy of the traffic. Those lines are Salt’s.
What stays out of the list, on the product page. Salt says Claude Connect finds organization-managed MCP connectors that administrators added. It names what that row can include: the server’s name and identity, a unique identifier, added, updated, and removed events, whether the server is active or removed, and the time of the latest lifecycle event. Servers installed only on one person’s computer are outside this view, because Claude’s Compliance API does not report them. Organization servers with no lifecycle activity inside that API’s retention window are outside it too. A retention window is how far back the feed keeps events. Salt does not say how many days that window covers. Those limits are on the product page.
Roey Eliyahu, Salt’s co-founder and chief executive, said MCP servers are one of the fastest-growing parts of the enterprise attack surface, and that for most security teams what is connected to their AI has been a blind spot they could not close. An attack surface is the set of places an attacker might get in. He said Salt Claude Connect turns that blind spot into a live inventory, so a team can see the MCP servers connected to its Claude Enterprise organization, track them as they are added, removed, or changed, and govern that environment without touching the prompts or the content that run through it. That quotation is his, in the release.
The count in the same release is Salt citing someone else’s research. Salt says Trend Micro found that MCP servers exposed on the public internet with no authentication and no encryption nearly tripled, to 1,467, in a matter of months. Authentication is a login. Encryption scrambles the traffic so a stranger cannot read it. Salt says most of those servers were hosted on major cloud providers and offered direct read access to the data behind them. 1,467 is the figure in that citation. The release does not say Salt counted those public servers itself.
Who can turn it on. Salt says Claude Connect is available now to Salt customers who have a Claude Enterprise organization. Setup needs a Compliance Access Key with a read-only scope and the organization’s ID. Salt says that takes a few steps from the Salt dashboard. The product page lists four: create the key in Claude’s organization settings, find the organization ID, enter both in Salt’s Data Source Hub, and then read the inventory. Salt says it checks the key, runs a first discovery scan, and sets the connector to Connected when that works. The product page also says the person connecting it needs Owner or Primary Owner permission on the Claude organization. The release points readers to salt.security for the full steps. Neither page prints a price.
Who the about box says Salt is. Salt says it protects companies from attacks on AI agents and on APIs, and that it covers the path from AI-written code through to the moment the software runs, across models, MCP servers, tools, and the APIs those tools call. Founded in 2016. The investors it names are Sequoia Capital, S Capital, Tenaya Capital, Salesforce Ventures, and Advent International. The press contact on the release is Dr. Karl Bateson, karlb@salt.security. The product page lists the address 3921 Fabian Way, Palo Alto, California 94303. Those lines are Salt’s.
In plain terms, Salt built a read-only feed so a security team can see which MCP servers an administrator has connected to the company’s Claude Enterprise account, and can watch that list as servers are added or taken off. The feed does not read the chats, the files, or the projects, and it does not change the Claude organization. A plug that lives only on one laptop is outside what this integration can see. The 1,467 figure is Salt citing Trend Micro.
The picture is Salt’s screenshot of that inventory. The Salt Agentic inventory lists organization-managed MCP servers. The source on the rows is the Claude Compliance API, and each row shows the latest activity. It is the image on the PR Newswire announcement. It is the company’s screen, not a diagram drawn for this story.
RELATED
Sources
- PR Newswire — Salt Security introduces Salt Claude Connect, 29 Sep 2026
prnewswire.com
- Salt Security — Claude integration
salt.security
