You Don't Have to Build Your Own AI to Get the Benefits of BYOAI
by Beth Barach, VP of PM//6 min read/

We've talked before about how Brinqa's API and MCP server let you bring your own AI into the platform. Point Claude, Copilot, or any MCP-compatible client at your Brinqa data, and perform many tasks. You can query your risk data, generate BQL from a natural language question, and pull CVE context on demand. That's still true, and it still matters for teams who want their own agents working against Brinqa's data model.
But not every team wants to build out their own AI agents before they get value. Some just want to ask a question and get an answer. That's what BrinqaIQ is for.
The Same Capability, Two Ways In
BrinqaIQ is Brinqa's own AI agent, built into the platform. It runs on self-hosted, open-source models, so your data never leaves Brinqa's environment to reach a third-party LLM. There are two ways to use it, and they share the same underlying tool registry, so the capability is identical no matter which door you walk through.
BrinqaIQ Assistant is the chat interface inside the platform. Ask it a question in plain language and it constructs the query, pulls the CVE, or checks the status of a running automation, all without you opening the query builder or memorizing your data model's structure.
BrinqaIQ MCP exposes that same capability to any MCP-compatible AI client: Claude Desktop, GitHub Copilot in VS Code, Goose, or Open WebUI. Connect it once with an API key, and your existing AI tooling can query Brinqa data, generate BQL, and trigger automations without you switching windows.
Same capabilities, either way:
- BQL generation. Describe the data you want in plain language and get a valid BQL query back.
- BQL execution. Run the query and get paginated results, ready to feed into your own reporting or agent pipelines.
- CVE Explorer. Look up severity, exploitability, and cyber risk score for any CVE without leaving the conversation.
- Docs Assistant. Ask a platform question and get an answer sourced from official Brinqa documentation.
- Automation lifecycle management. Launch, resume, cancel, or check the status of automations and flows.
- Flows and automations discovery. List everything configured, inspect any flow by name or ID, and see what's currently running.
Ask It Like You'd Ask a Colleague
The value shows up fastest in the two capabilities practitioners leverage every day: finding the answer to a platform question, and finding the right data.
The Docs Assistant lets you ask how a feature works, how to set something up, or what a configuration step requires. BrinqaIQ answers from the official documentation in plain language, right where you're working. No separate search, no digging through pages to find the section that applies to you.
The BQL Query Builder does the same for data. Describe what you want to find, in your own words, and BrinqaIQ turns it into a query you can review and run. Finding recent findings, filtering by asset status, prioritizing by risk, or scoping results to a specific tag all work the way you'd expect: you ask the question, and you get back something ready to use.
Both are built to save the steps between having a question and getting an answer, so you spend your time on the analysis, not the lookup.
Access Without Exposure
The question every security team asks about an AI feature is what it can see. With BrinqaIQ, the answer is scoped tightly on purpose.
BrinqaIQ Assistant works from metadata: data model names, attribute types, relationships, and public documentation. It never touches your actual database records, your reports, or your dashboards, and that metadata isn't used to train any model. Every query, whether typed into the Assistant or generated through MCP, runs under your logged-in permissions. If you can't see it in Brinqa today, BrinqaIQ can't surface it for you tomorrow.
That's the same access control model whether you're inside the platform chat or connecting through Claude Desktop with an API key. MCP only reaches the documented BrinqaIQ endpoints, and every call inherits your account's existing role-based and data-level restrictions.
None of it trains a model. Conversation data is discarded once a session ends, with narrow exceptions for security review and internal quality feedback. BrinqaIQ doesn't support file uploads or web search, so there's no path for data to leave your configured environment through the assistant. And because responses are grounded in your documentation and platform data rather than open generation, BrinqaIQ is built to say it doesn't know when a question falls outside what it's allowed to see, rather than guess.
Build Your Own, or Use What's Already Built
Teams running custom agent pipelines against Brinqa's API still have the open door they've always had, and MCP makes that door easier to walk through with any client that speaks the standard. Teams who want AI-assisted BQL and CVE research without standing up their own integration get it out of the box with BrinqaIQ Assistant.
An open platform gives you both paths on the same data, under the same access controls, so the option that fits your team is the one you get to use.
Watch the demo of BrinqaIQ at work:
FAQs
BrinqaIQ is Brinqa's built-in AI agent. It runs on self-hosted, open-source models inside Brinqa's environment, and answers questions, generates BQL queries, pulls CVE context, and manages automations without your data reaching a third-party LLM.
They're two ways into the same capability. Brinqa's API and MCP server let you point your own AI (Claude, Copilot, or any MCP-compatible client) at your data. BrinqaIQ Assistant is Brinqa's own agent, built into the platform, for teams who don't want to build or maintain that integration themselves.
No. Conversation data is discarded once a session ends, with narrow exceptions for security review and internal quality feedback. BrinqaIQ Assistant works from metadata, not your actual records, reports, or dashboards, and none of it is used to train a model.
Six things: generate BQL from a plain-language question, execute BQL and return paginated results, look up CVE severity, affected products, and remediation context, answer platform questions from Brinqa's documentation, manage the lifecycle of automations, and list or inspect flows currently configured or running.
No. Every query, whether typed into the Assistant or run through MCP, executes under your logged-in permissions. If you can't see something in Brinqa today, BrinqaIQ can't surface it for you.
Through BrinqaIQ MCP. Connect once with an API key, and any MCP-compatible client, including Claude Desktop, GitHub Copilot in VS Code, Goose, or Open WebUI, can query Brinqa data, generate BQL, and trigger automations directly.
Nothing outside your existing controls. BrinqaIQ runs on self-hosted, open-source models inside Brinqa's environment, so no data reaches a third-party LLM. Every query, through the Assistant or through MCP, executes under the requesting user's existing role-based and data-level permissions, and conversation data is discarded at session end. There's no file upload or web search path for data to leave the environment.


