Back to the registry
Agent passport

SentinelOne Purple AI MCP Server

SentinelOne · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews · G2 4
Runs onUnknownContainer
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

The SentinelOne Purple AI MCP Server serves as a pivotal gateway, democratizing access to the vast security context within the Singularity Platform for any generative AI application. By implementing the Model Context Protocol, this server delivers comprehensive security telemetry that includes device inventory, real-time alerts, vulnerability data, and misconfiguration findings, directly into your cloud-native workflows.

It is engineered to facilitate the creation of next-generation, agentic security solutions. AI agents can leverage SentinelOne's data lake, running PowerQueries on events and interacting directly with Purple AI for conversational threat analysis and guided security actions. This capability accelerates the shift to an autonomous Security Operations Center (SOC) model, where agents can automatically perform incident enrichment, validate security posture, and inform strategic decisions across enterprise and cloud assets. The Purple AI MCP Server provides the essential integration layer for embedding true security intelligence into your custom AI systems.

Show the rest of the publisher’s description (2 more lines)

To learn more about this open-source resource and explore its deployment capabilities, visit the official project page at: https://github.com/Sentinel-One/purple-mcp Purple AI MCP Server is also deployable as an EKS and through Amazon Bedrock, using Agent Core.

Users will need to have an active deployment of SentinelOne console and be able to obtain the SentinelOne Singularity Console token and url to be able to deploy and use the Purple AI MCP server.

Highlights

Highlighted by the publisher on AWS Marketplace.

The Purple AI MCP Server uses the open-source Model Context Protocol (MCP) to establish a universal, standardized bridge, connecting the SentinelOne Singularity Platform with any AI framework or LLM.

It exposes comprehensive, read-only security services, including Purple AI for conversational security investigation, Alerts, Vulnerabilities, Misconfigurations, Events (PowerQuery), and Asset Inventory to enrich AI-native workflows.

Empowers developers and partners to build custom, context-aware agentic AI use cases for security operations (SecOps), enabling autonomous threat triage, real-time posture analysis, and advanced threat hunting.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMP AuthorizedConfirmed95%, domain-verifiedSentinelOne Singularity Platform High is FedRAMP Authorized at High impact (domain match)FedRAMP Marketplaceregistry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment

CompanySentinelOneAutomated

Refund terms

As stated by the publisher on AWS Marketplace.

All fees are non-cancellable and non-refundable except as required by law.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Linked repositories

1 repo
Sentinel-One/purple-mcpgithub · AWS MarketplaceSource

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Container
Multiple support options are available. Email support at support@sentinelone.com
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.