Disrupt 2026Meet Himaya at TechCrunch Disrupt 2026. October 13–15 · Moscone West, San FranciscoBook time with us

Your agentic security engineer, in Himaya and in your AI tools

Falcon reads your real-time security context (threat history, DLP events, SaaS alerts and compliance posture) and turns it into decisions. Through MCP, the same context is available in the AI assistants your team already uses.

Falcon in Himaya

Ask Falcon anything about your workspace

Falcon reads your threats, data and history to answer questions, draft policies with their impact, and generate reports for leadership.

Falcon AgentWorkspace Security Intelligence Assistant
Hi! I’m Falcon, your security intelligence assistant. I can analyze threats, generate reports, and answer questions about your environment. What would you like to know?
Build me a policy based on my most recent threat
Policy drafted: Block spam from offers.dealstream-mail.com
  • Conditions: Inbound messages where the threat type is spam and the sender domain is offers.dealstream-mail.com.
  • Action: Block. Messages move to trash, and admins and the recipient are notified.
  • Rationale: This domain sent 2 unsolicited marketing emails in the last 30 days. Both were classified as spam with high confidence.
  • Impact: Would have affected only those 2 messages, 0.1% of mail scanned. No legitimate traffic matched.

No existing policy covers this sender, so this rule is new and narrowly scoped.

Opens Policies with this draft prefilled.
Generate this week's executive report
Weekly executive report ready
  • Summary: 14,200 messages reviewed. 20 threats quarantined, no compromise.
  • Top risk: Invoice fraud impersonating a supplier's finance team, 6 attempts.
  • Data protection: 7 outbound messages held by DLP, mostly spreadsheets with card numbers.
  • Posture: Risk is Guarded at 35 of 100, down from 41 last week.

Includes trend charts, compliance coverage by framework and recommended next steps.

Exports a PDF for leadership.

Quick questions

MCP

Falcon's context, inside the AI tools you already use

Connect Claude, ChatGPT or Cursor to Himaya's MCP server and ask about threats, DLP and policies without leaving your tool.

ClaudeConnected to himaya

Which phishing campaigns hit us this week?

Used query_messages from Himaya

Used get_sender_relationship from Himaya

Two campaigns. A payroll lookalike (northwind-payroll.co) sent 8 credential-harvesting emails, all quarantined. A fake IT helpdesk sent 3, with 2 flagged for review.

himaya-mcp · session log
  1. → initialize client: claude
  2. ← ok tools: 7
  3. → tools/call query_messages {"threat_type": "PHISHING", "days": 7}
  4. ← result 11 messages · 9 quarantined · 2 flagged
  5. → tools/call get_sender_relationship {"domain": "northwind-payroll.co"}
  6. ← result first seen 3 days ago · no prior mail
How it works

From question to policy

  1. Step 1

    Ask

    Ask in the Himaya console, or from an MCP-compatible AI client.

  2. Step 2

    Investigate

    Falcon queries messages, outbound DLP events and sender relationships in your tenant.

  3. Step 3

    Draft

    It proposes a policy shaped by your mailbox history. Every condition is validated, so a draft can never silently match all mail.

  4. Step 4

    Preview and apply

    The draft is dry-run against past threats to show its impact. You open it in Policies to review and enable it.

Capabilities

What Falcon Agent & MCP covers

Context-aware intelligence

Reasons over live email threats, DLP, SaaS and compliance data across your environment.

Policy co-pilot

Builds detection rules shaped by your own mailbox history, ready to review in Policies.

Instant reporting

Executive, compliance and data-exposure reports generated on demand.

Validated drafts

Policy conditions are checked in code against what the policy engine understands, not left to the model.

Impact preview

See which past messages a draft would have caught before you turn it on.

MCP server

Connect MCP-compatible clients such as Claude and Cursor to your Himaya security context.

How we build it

Designed to be trusted

  • Drafts are validated in code, not by the model.
  • You review every policy before it is enabled.
  • Falcon proposes. Your team decides.

Frequently asked questions

What is MCP?

The Model Context Protocol is an open standard that lets AI assistants use external tools. Himaya's MCP server gives MCP-compatible clients access to Falcon's security context.

Does Falcon change policies on its own?

No. Falcon proposes a draft. You open it in Policies to review and enable it.

What can Falcon see?

Your tenant's threats, outbound DLP events, sender relationships and existing policies.

Can Falcon generate reports?

Yes. Ask for an executive summary or a weekly report and Falcon compiles threats handled, DLP holds, risk trends and compliance coverage into a report you can export as a PDF for leadership.

What kinds of questions can I ask Falcon?

Anything about your workspace security: this week's top threats, why a message was quarantined, how your risk score is trending, or which DLP rules are firing most.

Can Falcon investigate a specific email or sender?

Yes. Ask about a message or domain and Falcon pulls its verdict, the reasoning behind it and the sender's relationship history with your organization.

Can I use Falcon from my own AI tools?

Yes. Through Himaya's MCP server, MCP-compatible AI assistants can query the same security context you use in Himaya.

Try Falcon Agent in your workspace

Book a walkthrough and ask Falcon about your own threats.