Skip to content
RidgeKEPPTIC

Built for MSPs and IT teams

Give your team AI access to your tools — without giving up control

Ridge is a secure MCP gateway that connects Claude, ChatGPT, Microsoft Copilot, and Cursor to Autotask, Hudu, Datto RMM, Microsoft 365, and more — with per-user permissions, per-client scoping, approval on destructive actions, and a full audit trail.

13
integrations, live today
0
shared API keys
Every
action audited
Any
MCP client

The problem

Every AI client can call your PSA and RMM now. Almost none of them are governed.

Claude, ChatGPT, and Copilot can all reach your business tools today. What's missing is the layer between the model and the tool: identity, least privilege, approval, and audit.

One shared vendor key

Most AI-to-PSA/RMM setups run on a single API key handed to the whole team. Anyone who can reach the chat client can do anything that key can do.

No identity behind the call

The AI knows which chat it's in, not which technician is behind it. There's no seat, no role, no per-client boundary — just a key that works or doesn't.

No approval, no record

An AI client reboots a device, closes a ticket, or runs a command the moment it decides to. Nobody approves it, and nothing is written down.

Ridge sits between your team's AI clients and your business tools. Every call has a person behind it, a permission model that says exactly what they can touch, a hold on anything destructive until someone approves it, and an audit record of what happened.

How it works

Ridge is the MCP gateway between your team and your tools

Nobody talks to your business tools directly. Every AI client goes through Ridge, and Ridge decides what happens next.

1

Connect your tools

Credentials are added once, in Ridge, and never live in a chat client.

2

Decide who can do what

Grants are set per person or per team, per tool, per client — in three tiers: read, write, destructive.

3

Your team works from any AI client

Ridge enforces every call, holds destructive actions for a human, and writes an audit record.

Your team's AI clients

Claude, ChatGPT, Copilot, Cursor

Ridge

identity · permissions · approvals · audit

Your tools

PSA, RMM, documentation, and more

In practice

What it looks like in a working day

Three examples of how Ridge behaves once it's in front of your tools.

Service desk

“Show me every open ticket for this client and draft an update.”

The tech only sees the clients they're assigned to. Ridge filters the tool results before the model ever sees them.

Endpoint ops

“Isolate that device.”

Ridge holds the action until an approver says yes — from the console or right in the chat — and records the decision either way.

Documentation

“Pull the VPN setup procedure from Hudu.”

The model gets the steps. It never gets the password.

Integrations

13 integrations, built for how MSPs actually work

Every integration below is live today — no roadmap, no waitlist.

PSA & documentation

  • Autotask
  • Hudu

Search tickets, create tickets, add notes, and log time in Autotask; pull procedures and documentation from Hudu — never the secrets stored alongside them.

RMM & endpoint

  • Datto RMM
  • Conduit
  • SentinelOne
  • Huntress

List devices, check status, and review alerts. Isolation and remediation actions are held for approval before they run.

Network & security

  • Sophos
  • FortiGate
  • UniFi
  • Cloudflare

Look up firewall rules, network status, and DNS records. Changes are a separate permission, and the high-impact ones — deleting records, removing rules — wait for a human.

Business & cloud

  • Microsoft 365
  • Pax8
  • QuickBooks Online

Check licensing, subscriptions, and invoices without handing out a shared admin login.

Need another integration? Ask us.

Security posture

The control layer a shared API key skips

Eight product principles that don't get compromised for convenience.

Every call has a person behind it

Every action is tied to the person who's signed in — never to a shared key that could be anyone on the team.

Least privilege, per person and per client

Grants are set per person, per tool, per client, in three tiers: read, write, destructive. People only ever see what they're allowed to touch.

Destructive actions wait for a human

Reboot, uninstall, isolate, delete — high-impact actions are held for approval before they run, decided from the console or right in the chat. Routine changes need their own explicit permission.

Secrets never enter the chat

Passwords and API keys are never returned into a model's context. A governed reveal happens outside the conversation, not inside it.

Credentials never leave Ridge

A chat client's token never reaches your vendor, and a vendor credential never reaches a chat client. Ridge is the only thing that ever holds both.

One enforcement point

Every AI client — Claude, ChatGPT, Copilot, Cursor — goes through the same gateway and the same rules. Nothing gets a side door.

Complete, tamper-evident audit trail

Every call writes a permanent record before it returns. Export the stream to a webhook, Splunk, or Microsoft Sentinel.

Works for one person or a whole company — same rules

One technician or five hundred run the identical permission model, approval flow, and audit trail. Nothing is special-cased.

Works with

Any MCP client — the same gateway, the same grants

Any MCP client. One sign-in, the same permissions everywhere.

  • Claude

    Desktop and claude.ai

  • Claude Code

    One-line setup

  • ChatGPT

    Business & Enterprise connector

  • Microsoft Copilot Studio

    Entra-aware

  • Cursor

    Any MCP-capable editor

Enterprise

For organizations that already have an identity provider

The same gateway, with the controls a security or IT team asks for first.

Entra SSO + SCIM

Sign in through Microsoft Entra (OIDC) with domain-verified auto-provisioning and IdP attribute → role mapping. SCIM keeps membership in sync as people join and leave.

Bring your own encryption key

Stored credentials are already encrypted per organization. With BYOK, the key that wraps them is one you control.

SIEM export

Stream the audit trail to a webhook, Splunk, or Microsoft Sentinel as it's written.

Deploy your way

Run Ridge in the cloud, or deployed on your own infrastructure — with the same security model either way.

Pricing

Per-seat cloud pricing. Private deployment available. Tell us your seat count and we'll send a quote.

Contact us

FAQ

Frequently asked questions

What is MCP?

MCP (the Model Context Protocol) is an open standard that lets an AI client — Claude, ChatGPT, Copilot, Cursor — call tools exposed by a remote server. Ridge is that server: it sits in front of your team's real business tools.

Does Ridge (or the AI) see our secrets?

No. Secret values never enter a chat conversation. A governed reveal decrypts a credential outside the model's context, only for someone explicitly granted that access. Ridge is the only thing that ever holds a vendor credential.

Which AI clients does it work with?

Any MCP client: Claude (Desktop and claude.ai), Claude Code, ChatGPT, Microsoft Copilot, and Cursor — plus anything else that speaks MCP.

Which tools does it integrate with?

Autotask, Hudu, Datto RMM, Conduit, SentinelOne, Huntress, Sophos, FortiGate, UniFi, Cloudflare, Microsoft 365, Pax8, and QuickBooks Online — 13 integrations, all live today. Ask us about adding another.

How is this different from a shared API key?

A shared key means anyone with access to the chat client can do everything the key can do, with no record of who did what. Ridge puts a real person behind every call, per-user and per-client permissions, human approval on destructive actions, and a full audit trail in between.

Can we run it on our own infrastructure?

Yes — talk to us. We support both cloud and private deployment, with the same security model either way.

Is Ridge SOC 2 / ISO 27001 certified?

Not today. Ask us about our roadmap.

Give every AI client a governed way in.

See Ridge with your own tools.