Exenai Connect
One MCP server for Claude, ChatGPT or Copilot that reaches every system connected to it, with permissions, guardrails and a full audit on every request.
Why now
Your people are already using AI. The firms that win the next decade won't be the ones adopting it fastest, but the ones that can govern it, measure it and prove what it did.
Client and candidate details pasted into chat tools, with no record of what went where.
Nothing deciding what an AI tool can read, change or export in your systems.
No way to see who is using AI, for what, or whether it's paying its way.
One MCP server
Connect presents as a single MCP server. Add it once to Claude, ChatGPT or Copilot and it reaches every system connected to the gateway, from your system of record to tools such as Timesheet Portal and Xero.
Governance
Every call from every AI tool, person and agent passes through one gateway and the same four controls before it reaches your systems.
Connect Apps
Describe the app you need in two or three lines and it's working on your live data in minutes. Read and write, inside the Bullhorn or Invenias record or standalone, with every request still flowing through the gateway.
Connect Surfaces
Put the apps you build in front of consultants, candidates, clients and partners, each with their own sign-in and only the data that's theirs.
Audit
Every AI request by every person and agent is recorded, and leaders can question it in plain English: who is using AI, for what, how often, and what was stopped.
Setup
Book a demo and we agree the systems to connect and who needs access.
Your Connect workspace is provisioned on Microsoft Azure.
Connect Bullhorn or Invenias and your other systems, then add Connect to your AI tools.
Set permissions and guardrails, then build your first apps.
Your data stays in your system of record. Connect runs on Microsoft Azure, and every user signs in by name.
Pricing
A small group of firms are shaping Connect with us. When the programme closes, we'll launch our commercial pricing and licensing. Until then, founding customers join on these terms.
FAQ
One governed gateway between AI and the systems your firm runs.
Bullhorn or Invenias is the system of record, alongside the other systems you run, such as timesheets and pay, accounting, Microsoft 365 or Google Workspace, and project management. Your people ask questions, build apps and dashboards, and run agents on live data. Every request is allow-listed, approved where needed and logged. Connect is also where the apps your AI builds are hosted. Nothing is copied out of your systems.
Through an MCP connector, and be careful which one.
MCP is the open standard AI tools like Claude, ChatGPT and Microsoft Copilot use to reach other systems, so connecting AI to your ATS means putting an MCP connector in front of it. Bullhorn may well launch official MCP connectors for Bullhorn and Invenias in time, though nothing is confirmed today. In the meantime a wave of unofficial connectors has appeared on the market, many built on the wrong authentication methods and operating outside Bullhorn's guidelines for secure, auditable API access. Wiring one of those into the system that holds your candidates' personal data deserves real scrutiny: ask how it authenticates, what it logs, and what governs each request.
Technically yes, but that's a side effect of what we built, not the aim.
We set out to build a governed gateway between AI and the systems your firm runs, not an MCP connector for your ATS. A plain MCP connector would wire AI straight into your system of record, and we wouldn't build one. Connect talks to Bullhorn and Invenias the official way, through their REST APIs, with the authentication, permissions and audit logging that come with working with those platforms properly. Because AI tools reach other systems through MCP, Connect presents itself to them as an MCP server. Claude, ChatGPT, Microsoft Copilot and any other MCP-capable tool or agent connect to Connect, and everything they ask for passes through the gateway, allow-listed, intercepted where risky, approved where needed and logged, before a single field is read or written. So MCP is how your AI gets in; the gateway is what Connect is. Your AI speaks MCP, and your ATS only ever speaks to Connect. One deliberate boundary stays in place: large-scale search and match isn't exposed over the API, so it isn't reachable through Connect. That stays with Amplify.
Amplify is AI in Bullhorn. Connect is the AI gateway for everything else, and it steers people to Amplify.
Connect works with Bullhorn's own AI, not in place of it. Prompt interception reads every request at the gateway, so when someone asks for something Amplify already does well, search and match included, they're redirected to Amplify inside Bullhorn, with candidate data kept where it belongs. Connect's job starts where Amplify's ends: the AI tools your people use outside Bullhorn, such as Claude, ChatGPT and Copilot, the other systems you run alongside your CRM, and every solution you'd otherwise be shopping the marketplace for.
The ones your people already use.
Claude, ChatGPT, Microsoft Copilot or any other client that supports MCP. There is no new chat app to roll out, and the same rules apply whichever tool a request comes from.
Their instinct is right. The route is the problem.
AI has made using and building cheap. People paste exports into public chat tools, and anyone with Claude, ChatGPT or Cursor can knock together a script or app against your ATS in an afternoon. Your most capable people are already doing both. But look at what that actually is: company data in ungoverned tools, API credentials pasted into code, candidate data flowing through unreviewed AI-written scripts, no audit trail, no access control, and API usage outside Bullhorn's guidelines, invisible to leadership until something breaks or leaks. The answer isn't to ban it; it's to give it a sanctioned home. Connect gives your team a governed place to use AI on live company data, with the same speed for building, so you describe it and it's built. Every request and every app runs behind the gateway: official API access, scoped permissions, a review pipeline before anything publishes, and every read and write in the audit log. Your people keep using AI. Your data stays governed.
That's the model Connect replaces.
Instead of a separate app, contract and integration for each need, your team describes what they need and Connect builds it, on your live data, governed, in minutes. One subscription covers what you build under our fair usage policy, and everything it builds lives in your control rather than a third party's.
No. Your system of record stays the source of truth.
Every read and write goes live to Bullhorn or Invenias, and Connect doesn't keep a copy of your CRM data. What it does record is the audit log of each request, which is yours to query and export.
On Microsoft Azure in West Europe, for every customer.
Connect runs in Microsoft's West Europe region in the Netherlands, wherever you're based. Your CRM data stays in your CRM; Connect reads and writes it live and doesn't keep a copy. Exenai Candidate runs on the same platform.
Not by us. Your own AI tools' settings are yours to manage.
Exenai doesn't train any public or private model on your data, and our own AI subscriptions have training switched off. Connect lets your people use the AI tools you choose, such as Claude, ChatGPT or Copilot, and whether those tools use your data for training depends on the plan and settings you have with each provider. That's your responsibility under our terms, so we recommend business or enterprise plans with training switched off.
Four questions, and be suspicious of soft answers.
How do you authenticate: through Bullhorn's official APIs and guidelines, or a workaround? Do you copy our data, and if so, where does it live, who secures it, and how do we get it deleted? What does the AI actually do with candidate personal data, and can it act without a human? And can we see an audit trail of every action your product takes? These questions have hard answers for any vendor doing it properly. For the record, Connect's are: official REST APIs only; no copies, ever, with real-time pass-through; every AI action governed by allow-lists, guardrails and approvals; and a complete audit log you can query yourself.
Connections are held centrally and access is by role.
Authenticated connections to your systems sit in one place, so access is granted and revoked in one place. Every user signs in by name. People outside the firm sign in with Microsoft, Google, Apple, LinkedIn or a one time passcode, and only see their own data.
Four things, all enforced at the gateway before anything touches your systems.
An allow-list of what each user and agent may do, prompt interception for risky requests, human approval steps for actions that need them, and rate and cost caps. Permissions set which CRM APIs can be called, with a workspace default and overrides per person or portal. Every request from every actor, human or agent, lands in the audit log, and anything denied, held for approval or out of the ordinary raises an alert by email or Slack the moment it happens.
Every request, from a person or an agent, is read at the gateway before anything runs.
Interception applies one of four effects: deny for what should never happen, such as bulk exports or personal data heading somewhere it shouldn't; redirect to steer work to the right tool, so a prompt Amplify does better is sent to Amplify, inside Bullhorn; and warn or advise where a nudge is enough. Whatever happens, the person is told in their chat, in the moment. And every deny raises a real-time alert by email or Slack, so leadership sees issues as they happen, not in a report afterwards.
Yes, and for most firms it's the first time AI becomes visible at all.
Every request from every person and every agent lands in one audit log, and that log is data like any other. Ask it questions in plain English: how is AI being used across the business this month, which teams get the most value from it, was there any risky activity I should know about, what did that agent do yesterday. Or build dashboards and alerts on top of it. Adoption, value and risk, measured from what actually happened rather than what people say. It's how AI spend stops being an act of faith.
In full for 120 days, then as a summary.
Every request through Connect is recorded in full, including prompts and responses, and kept for 120 days. After that it's reduced to a summary of activity without the prompt or response content, kept for as long as you subscribe. You can export the log at any time, and for 60 days after your subscription ends.
Yes, under exactly the same rules as people.
Agents pass through the same allow-list, approvals and limits, and every action they take is written to the audit log.
Connect runs on Microsoft Azure, certified to ISO 27001 and SOC 2.
Connect is hosted in Microsoft's West Europe region, whose data centres and services are certified to ISO 27001 and SOC 2, among other standards. Our Data Processing Addendum, sub-processor list and technical and organisational measures are published on our Legals page.
Everything from simple data jobs to full interactive applications.
At one end, data-oriented processes: checking relationships, updating statuses across a whole desk in one governed action. In the middle, analytical dashboards that join live data from across your stack, such as placements against invoicing and payments, or pipeline-health boards that show time-in-stage and flag stale candidates. At the far end, fully interactive read-and-write applications, such as kanban boards and commission calculators, published standalone or embedded in your records, plus agents that run processes 24/7. And client-ready deliverables that used to be documents: a search report that's a live app in every assignment, editable in line, writing back to the system of record, shared as a link that's never out of date. Never a stale PDF again. None of it is limited to Bullhorn and Invenias. Anything you build can talk to any system in your connected stack, and where your systems don't hold the data a workflow needs, Connect creates flexible custom tables alongside them.
No. That's the point.
You describe what you need in plain English, such as “build me a commissions dashboard for my users, visible in placements and jobs”, and Connect builds it from your live data. Finished apps publish to the Exenai app host, standalone or embedded directly inside your Bullhorn records. Building stops being something you buy and becomes something anyone in the firm can do.
Minutes, not months.
Two or three lines of plain English are enough to create a working read and write app, inside Bullhorn or standalone. It goes through the review pipeline and can be published in under ten minutes.
Both, within the permissions you set.
Apps read and write live through the gateway, so a change made in an app lands in Bullhorn or Invenias straight away. Every write is covered by the same allow-list, approvals and audit log as any other request.
As tabs and cards on the records your team already uses.
You add the Connect app host to Bullhorn's view layouts once, and apps then appear on candidate, contact, company, job or placement records. Any app can also run standalone in a browser.
Yes. That's exactly what Connect is for.
Every other route to cross-system reporting starts by moving your data: a BI platform, a warehouse, a sync out of each system before you can chart a single number. Every copy is more cost, more risk, and another dataset to reconcile. Connect inverts it. Dashboards, reports and analytics are built on live reads through the gateway, such as placements from Bullhorn against invoices and payments from finance, pipeline health or commissions, joined in real time while the data stays exactly where it lives. Nothing exported, nothing warehoused, nothing to reconcile. What you build publishes standalone or embedded in your records, permission-aware and always current. The expensive part of BI was never the charts. It was moving the data, and Connect doesn't move it.
How you put apps in front of people outside your firm.
Client and partner surfaces deliver the apps you build to the clients and partners you work with, and there is a candidate surface inside Exenai Candidate. Each has its own sign-in and permissions, and everyone sees only what's theirs. Your own team uses apps through Connect itself, inside Bullhorn or standalone.
People who already exist in your Bullhorn.
Client and partner contacts linked to a company record, and candidates, sign in with Microsoft, Google, Apple, LinkedIn or a one-time passcode. Their access is scoped by the host, so a candidate only ever sees their own record and a client only their own shortlists and workforce. There are no separate accounts to manage, and they don't count towards the named users on your subscription.
Anything you'd otherwise send as a document or chase by email.
A client reviewing a live shortlist and leaving feedback, a client viewing their contractors and timesheets, a partner seeing the work you share with them, or a search report that is a live app rather than a PDF, always current and writing back to your system of record.
Candidate is built on one.
Exenai Candidate is a ready-made candidate experience, covering applying, profiles, onboarding and compliance, running on the candidate surface. Client and partner surfaces let you deliver your own apps to the people you work with outside the firm.
Nothing publishes unreviewed.
Every app goes through the publish pipeline: scanned for anything unsafe, reviewed by a separate AI that reports exactly what the app does, reads and writes, and held for human approval where it matters. And even a published app can only reach your data through the gateway, with the same scopes, caps and audit log as every other actor. Every version is kept, and you can roll back to an earlier one by asking your AI tool, so nothing is ever irreversible.
Yes, and you can always go back.
Every change goes through the same review before it publishes, and every version is kept. To roll back, ask your AI tool to return the app to an earlier version.
Minutes to connect. A day or two to be fully live.
We provision your workspace, you authorise the connection to Bullhorn or Invenias, and your people add Connect to the AI tool they already use. Full onboarding, including permissions and guardrails, takes a day or two.
You do.
Apps your team builds belong to you. We host and run them for you, and we never reuse them or make them available to anyone else. Anything from Exenai's own library stays ours, licensed to you while you subscribe.
You can take their definitions with you.
For 60 days after the end of your subscription you can export your app definitions, configurations and audit log. Your data never left your systems in the first place.
No set limit.
There is no charge per app, per agent or per call, and no feature gating. Use is covered by our fair usage policy, which protects the shared platform so it stays fast and stable for every customer.
A team that knows Bullhorn, Invenias and recruitment.
Support runs from 09:00 to 18:00 UK time on working days, by support portal and email, and by phone for critical issues. Critical issues have a one hour response target. Every customer also gets an introductory training session where we build the first things together.
Whether you want to govern the AI your teams already use or build your first apps on Bullhorn or Invenias, we'll show you how it works.