Borneo for AI agents

Borneo is a data privacy platform that security teams use to scan cloud resources for sensitive data and manage the processing activities and DPIAs tied to it. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Security and identityOAuth 2.0MCP + RESTborneo.io
AUDIT LOG · BORNEOPOLICY: acme-support
09:41:07 · claude · u_8f2read
borneo.list_insight_filters
List insight filters✓ allowed · 212ms
09:41:08 · claude · u_8f2read
borneo.get_domain_by_id
Get domain by id✓ allowed · 164ms
09:41:09 · claude · u_8f2write
borneo.create_new_asset
Create new asset✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
borneo.delete_dpia_by_id
Delete dpia by id✕ blocked · policy: deny
EVERY BORNEO CALL, ON THE RECORD
01 · USE CASES

What agents do in Borneo.

01

Scan a cloud resource

Schedule a cloud resource scan to discover sensitive data before deciding on any remediation steps.

02

Review a processing activity

Look up a processing activity or its risk threshold before creating a new DPIA for it.

03

Require approval before deleting an asset

Treat deleting an asset, domain, or recipient record as destructive since it removes tracked privacy data.

02 · ACTIONS

153 Borneo actions, graded by risk.

Every Borneo action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

72

Look things up. Allowed by default.

  • borneo.get_domain_by_id
    Get domain by id
  • borneo.get_scan_by_scan_id
    Get scan by scanid
  • borneo.get_threshold_by_id
    Get threshold by id
  • borneo.list_insight_filters
    List insight filters
  • borneo.get_category_by_label
    Get category by label
  • borneo.get_headquarters_by_id
    Get headquarters by id
  • borneo.get_user_profile_by_id
    Get user profile by id
  • borneo.get_cloud_account_by_id
    Get cloud account by id
  • borneo.list_scans_with_filters
    List scans with filters
  • borneo.list_data_breach_filters
    List data breach filters
  • borneo.list_discovered_document
    List discovered document
  • borneo.list_events_with_filters
    List events with filters
  • borneo.list_issues_with_filters
    List issues with filters
  • borneo.list_discovered_infotypes
    List discovered infotypes
  • borneo.list_or_filter_recipients
    List or filter recipients
  • borneo.get_department_filter_list
    Get department filter list
+ 56 MORE

write

62

Create and change things. Allow, or ask the user first.

  • borneo.create_new_asset
    Create new asset
  • borneo.update_dpia_by_id
    Update dpia by id
  • borneo.create_dashboard_user
    Create dashboard user
  • borneo.post_dashboard_report
    Post dashboard report
  • borneo.update_domain_details
    Update domain details
  • borneo.update_employee_by_id
    Update employee by id
  • borneo.update_department_name
    Update department name
  • borneo.update_threshold_by_id
    Update threshold by id
  • borneo.post_support_chat_query
    Post support chat query
  • borneo.create_headquarter_entry
    Create headquarter entry
  • borneo.update_data_breach_entry
    Update data breach entry
  • borneo.add_discovered_recipients
    Add discovered recipients
  • borneo.post_classification_stats
    Post classification stats
  • borneo.post_filtered_access_logs
    Post filtered access logs
  • borneo.post_scan_resource_status
    Post scan resource status
  • borneo.update_category_infotypes
    Update category infotypes
+ 46 MORE

destructive

19

Delete, cancel or archive. Ask first, or deny outright.

  • borneo.delete_dpia_by_id
    Delete dpia by id
  • borneo.delete_asset_by_id
    Delete asset by id
  • borneo.delete_domain_by_id
    Delete domain by id
  • borneo.delete_employee_by_id
    Delete employee by id
  • borneo.delete_recipient_by_id
    Delete recipient by id
  • borneo.delete_threshold_by_id
    Delete threshold by id
  • borneo.delete_department_by_id
    Delete department by id
  • borneo.delete_category_by_label
    Delete category by label
  • borneo.delete_data_breach_by_id
    Delete data breach by id
  • borneo.delete_tag_from_resource
    Delete tag from resource
  • borneo.delete_headquarters_by_id
    Delete headquarters by id
  • borneo.delete_legal_document_by_id
    Delete legal document by id
  • borneo.archive_discovered_recipient
    Archive discovered recipient
  • borneo.delete_lopdp_threshold_by_id
    Delete lopdp threshold by id
  • borneo.delete_dashboard_report_by_id
    Delete dashboard report by id
  • borneo.delete_processing_activity_by_id
    Delete processing activity by id
+ 3 MORE
03 · HOW IT WORKS

Borneo in three steps.

  1. 01Your users connect BorneoThey sign in to Borneo on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create new asset” can wait for the user, and “delete dpia by id” can be denied outright.
  3. 03Any agent can actYour agent calls Borneo through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('borneo', {
  read: 'allow',
  write: 'ask',        // create_new_asset
  destructive: 'deny',  // delete_dpia_by_id
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Borneo connects.

Users sign in to Borneo on Arc0 Connect and approve the scopes you request. Build with Arc0’s Borneo OAuth app, or bring your own so the Borneo consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Borneo connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key · OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Borneo from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Borneo and Arc0, answered.

Q01

Can I use Borneo with Claude, ChatGPT or Cursor?

Yes. Connect Borneo to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Borneo actions you allow.

Q02

How do users connect Borneo?

Users sign in to Borneo on Arc0 Connect and approve the scopes you request. Build with Arc0’s Borneo OAuth app, or bring your own so the Borneo consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Borneo actions can my agent take?

153 in total: 72 read, 62 write and 19 destructive, such as “create new asset”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Borneo?

Yes. Actions like “delete dpia by id” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Borneo too?

Yes. The same Borneo connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Borneo into your agent.

Your users connect Borneo once, under your brand. Your agent gets 153 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan