Map what attackers are looking for once they find their way in. Then remediate with best practice, verified TideCloak guidance served straight to your AI agent, which does all the work.
> Works where you do
Raziel, Tide's MCP, takes your project from one that relies on your security being perfect all of the time to one whose security survives your worst day, in three prompts.
Map
One prompt maps the points in your project where a single compromise yields everything an attacker wants, each scored by what falls.
About the scanPlan
A follow-up report maps each finding to its fix, including the ones only TideCloak's technology can remove, and hands back the ordinary app fixes that stay yours.
See sample findingsRemediate
Raziel guides your agent through the changes with verified playbooks and canon, locking identities, data and access with keys no one will ever hold.
The Blast Radius scan
Every scanner tells you where an attacker might get in. None tell you what they'd walk out with. The Blast Radius scan red-teams your project the way an attacker's agent would, mapping the concentrated pockets of authority where one compromise yields everything it governs. A database credential that reads every record. An identity provider whose word is taken on faith. A session that works for whoever holds it.
Map my blast radius
Secure by default
Say what should be true of your app in plain English. Only doctors decrypt clinical notes. Distributions over ten thousand need a manager. Your agent builds each rule into the infrastructure, where Tide's cybersecurity Fabric enforces it before anything happens, rather than leaving it as a convention every future commit has to remember.
That is the difference between a weekend prototype and something you can put real users and real data on. The gap is almost entirely security work, and it is now work your agent does properly the first time. You keep shipping features, with keys no one holds and rules no stolen credential can get around.
# ask your agent
> Whether you are remediating or starting clean, the work is only as good as the knowledge behind it. Raziel serves deep, battle-tested security guidance your agent can act on, and the best-practice blueprints for solving the trust problems only Tide's technology can solve. Both routed to the right answer in a single call.
Security invariants, anti-patterns and the framework matrix that every piece of Tide code must satisfy. Your agent consults it before proposing architecture instead of guessing.
A remote Model Context Protocol (MCP) server, named Raziel, that gives AI coding agents verified TideCloak knowledge. Security canon, step-by-step playbooks, reference architectures and routing tools, so they build on Tide correctly instead of hallucinating security code.
Raziel is the archangel of secrets, keeper of the hidden knowledge of heaven. Tide locks your secrets, identities and access with keys no one will ever hold, and Raziel carries the knowledge that teaches your agent to build that way. It felt right.
Ask a connected agent to “Map my blast radius” and it performs a structural security review of your project. Instead of hunting known CVEs it maps the points where authority is concentrated, so one compromise yields everything that point governs. Findings are scored by blast radius, and each deep finding maps to a TideCloak remediation your agent can implement. See a full sample report.
Anything that speaks MCP or can read a URL. Cursor, VS Code, Claude Code, OpenAI Codex, Gemini CLI, Windsurf and Zed on the coding side. Claude, ChatGPT, T3 Chat and Perplexity as chat assistants. v0, Bolt and Lovable as app builders. Clients without remote MCP support can bridge through mcp-remote or run the local package.
All nine tools the server exposes are read-only. They serve guidance and nothing else. Nothing writes, nothing executes, and the server cannot touch your machine, your repository or your data.
No, and that is the point. The pack encodes Tide best practices so your agent applies them for you. It identifies concentrated pockets of authority in your design and remediates them before they become a target.
You can. The whole pack is published as a single markdown doc at tide.org/tide-agent-pack.md for exactly that. But the MCP server stays current as guidance evolves and routes any request straight to the right playbook. Pasted docs go stale the day you paste them.
The hosted endpoint and content are live and usable today, but may change before general availability. The endpoint URL is stable and playbooks are versioned, though the tool surface may evolve. It serves from https://mcp.tide.org/mcp if your client needs it entered by hand, and the manual setup instructions cover the clients without one-click install.
Let your agents make breaches inconsequential, so you can focus on the features your users actually care about.