{
 "categories": [
  "enterprise"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-10-06",
   "fact": "homepage",
   "note": "Tenable presents Tenable One as its exposure-management platform and names Hexa AI as the agentic layer on the Exposure Data Fabric.",
   "source": "https://www.tenable.com/products/tenable-one",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "vendor",
   "note": "The product page identifies the vendor as Tenable and the product as Tenable One.",
   "source": "https://www.tenable.com/products/tenable-one",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "deployment",
   "note": "The FAQ says Tenable One is mainly cloud-based, with an on-premises option for vulnerability-management assets through Tenable Security Center Plus. The MCP and API documented here are the cloud service, so deployment is saas.",
   "source": "https://www.tenable.com/products/tenable-one",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "platforms[0]",
   "note": "The product is a hosted exposure console. This pass did not open a desktop or mobile client page.",
   "source": "https://www.tenable.com/products/tenable-one",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "license",
   "note": "The MCP page says use requires a Tenable One Foundation or Tenable One Advanced license. The product page is a commercial exposure platform.",
   "source": "https://docs.tenable.com/exposure-management/Content/getting-started/hexa-AI-MCP.htm",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.api.exists",
   "note": "Tenable documents APIs hosted under cloud.tenable.com and says that guidance includes Tenable One and Vulnerability Management.",
   "source": "https://developer.tenable.com/docs/api-basics",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.api.kinds[0]",
   "note": "The authorization example is an HTTPS GET to https://cloud.tenable.com/scans with an API-key header.",
   "source": "https://developer.tenable.com/docs/authorization",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.api.auth[0]",
   "note": "Cloud API requests use the X-ApiKeys header in the form accessKey=ACCESS_KEY; secretKey=SECRET_KEY. Keys are generated per user account.",
   "source": "https://developer.tenable.com/docs/authorization",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.api.coverage",
   "note": "The same guidance excludes Security Center, Cloud Exposure, Attack Surface Management, and OT Exposure. Coverage of the full Tenable One suite is therefore partial.",
   "source": "https://developer.tenable.com/docs/api-basics",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.api.docs",
   "note": "Opened the API basics page, which states the product scope of the cloud.tenable.com guidance and links authorization and file-format topics.",
   "source": "https://developer.tenable.com/docs/api-basics",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.mcp.first_party",
   "note": "Tenable documents a Tenable-hosted Hexa AI MCP server at https://cloud.tenable.com/mcp/ and says it exposes 90 structured tools.",
   "source": "https://docs.tenable.com/exposure-management/Content/getting-started/hexa-AI-MCP.htm",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.mcp.verdict",
   "note": "The page is Tenable product documentation and says Tenable fully hosts the server. The verdict is official.",
   "source": "https://docs.tenable.com/exposure-management/Content/getting-started/hexa-AI-MCP.htm",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.rpa.ui_stack[0]",
   "note": "Tenable One is used as a hosted web console. No UI probe was run.",
   "source": "https://www.tenable.com/products/tenable-one",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.rpa.drivability",
   "note": "No repeatable UI probe exists. The MCP and API documentation establish non-browser paths, so drivability stays unknown.",
   "source": "https://docs.tenable.com/exposure-management/Content/getting-started/hexa-AI-MCP.htm",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.computer_use.viability",
   "note": "No computer-use probe artifact was produced. Viability stays unknown.",
   "source": "https://www.tenable.com/products/tenable-one",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "The API basics fetch banner points at a documentation index. This pass did not open an llms.txt file, so agent documentation stays unknown.",
   "source": "https://developer.tenable.com/docs/api-basics",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "verdict.best_path",
   "note": "The MCP page documents 90 tools and concrete workflows. The cloud API is broader in host scope but less specifically mapped in this pass, so MCP is the highest score.",
   "source": "https://docs.tenable.com/exposure-management/Content/getting-started/hexa-AI-MCP.htm",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "verdict.scores.api",
   "note": "A documented cloud REST API with per-user API keys covers Tenable One and Vulnerability Management and excludes several other Tenable One domains. Score 6.",
   "source": "https://developer.tenable.com/docs/api-basics",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "verdict.scores.mcp",
   "note": "Official hosted MCP with useful read and confirmed write workflows. The Foundation or Advanced license, FedRAMP exclusion, and bring-your-own-model limit keep the score at 7.",
   "source": "https://docs.tenable.com/exposure-management/Content/getting-started/hexa-AI-MCP.htm",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "freshness.watch[0].url",
   "note": "Opened the Hexa AI MCP page, including the URL, header, license gate, and example workflows.",
   "source": "https://docs.tenable.com/exposure-management/Content/getting-started/hexa-AI-MCP.htm",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "freshness.watch[1].url",
   "note": "Opened the API basics page that names which Tenable products share the cloud.tenable.com guidance.",
   "source": "https://developer.tenable.com/docs/api-basics",
   "tier": "declared"
  },
  {
   "date": "2026-10-06",
   "fact": "freshness.watch[2].url",
   "note": "Opened the Tenable One product page, including the domain list and the cloud deployment FAQ.",
   "source": "https://www.tenable.com/products/tenable-one",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-10-06",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://docs.tenable.com/exposure-management/Content/getting-started/hexa-AI-MCP.htm"
   },
   {
    "type": "docs",
    "url": "https://developer.tenable.com/docs/api-basics"
   },
   {
    "type": "docs",
    "url": "https://www.tenable.com/products/tenable-one"
   }
  ]
 },
 "homepage": "https://www.tenable.com/products/tenable-one",
 "id": "tenable-one",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "x-apikeys"
   ],
   "coverage": "partial",
   "docs": "https://developer.tenable.com/docs/api-basics",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Tenable documents a hosted Hexa AI MCP server and cloud.tenable.com APIs for Tenable One. Several Tenable One domains use separate API documentation.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Tenable One",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "wiz",
   "crowdstrike-falcon",
   "snyk"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Tenable",
 "verdict": {
  "best_path": "mcp",
  "scores": {
   "api": 6,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 7,
   "overall": 7,
   "rpa": null
  },
  "search": {
   "description": "Tenable One agents can use the hosted Hexa AI MCP at cloud.tenable.com/mcp and the cloud.tenable.com API. The MCP needs a Foundation or Advanced license and confirms write actions.\n",
   "title": "Tenable One Hexa AI MCP and cloud API"
  },
  "summary": "Tenable One is automatable today through the Tenable-hosted Hexa AI MCP server and the cloud.tenable.com APIs that Tenable says include Tenable One. The MCP endpoint is https://cloud.tenable.com/mcp/. Tenable says it exposes 90 tools from the Exposure Data Fabric and that Tenable hosts the server without hosting the model. Use requires a Tenable One Foundation or Advanced license, the Hexa AI MCP toggle, and Vulnerability Management API keys in the X-ApiKeys header. Example workflows search assets, create tickets, tag assets, build dashboards, and launch scans, and write steps are presented for confirmation. The feature is not supported in Tenable FedRAMP Moderate environments. The API basics page says the cloud.tenable.com guidance covers Tenable One, Vulnerability Management, Web App Scanning, and Exposure Management, and does not cover Security Center, Cloud Exposure, Attack Surface Management, or OT Exposure. Requests use X-ApiKeys with an access key and a secret key. This pass did not inventory every API resource, and it did not open an SDK, CLI, or webhook contract. Connector catalogs were not opened. Computer-use viability is unassessed. MCP scores 7 and is the best path because the tool workflows are documented specifically. The API scores 6 because the shared cloud API is real and partial across the Tenable One domains.\n"
 }
}