Product/Integrations

Built into the platform.
Not a marketplace promise.

Every connector on this page ships in the code base today. They feed the same ontology, obey the same trust rules and report their own health.

Source control & CI/CD
GitHubGitLabBitbucketAzure DevOpsJenkinsAWS CodePipeline
Webhooks for pushes and pull requests, PR scans with supersede logic, SARIF upload, gate results and rate-limited annotated comments, CI OIDC principals, pipeline templates.
Cloud providers
AWSMicrosoft AzureGoogle Cloud
Agentless collectors for posture, identity and entitlements, serverless, drift and attack paths. Account onboarding with least-privilege roles you control.
Kubernetes
EKSGKEAKSAny conformant cluster
Register clusters for inventory, topology and admission checks, run the eBPF sensor, or mark a trusted cluster as an execution target so scans run inside your network.
Container registries
Amazon ECRAzure ACRGoogle Artifact RegistryJFrog ArtifactoryHarborSonatype NexusAny OCI registry
Registry watchers bind image digests to repositories and workloads; each digest carries its own scan results and base-image recommendation.
Ticketing
Jira CloudJira ServerServiceNowLinearZendeskAzure DevOps BoardsGeneric webhook
Two-way sync. Inbound webhooks are HMAC-verified with a per-organisation, per-provider key and a replay guard.
Chat & on-call
SlackMicrosoft TeamsPagerDuty
Bots and slash commands for Slack and Teams, escalation policies and schedules for PagerDuty.
SIEM & logging
Splunk HECMicrosoft SentinelGoogle ChronicleIBM QRadarElasticsearchSyslog
Findings, audit events and security events streamed in the SIEM's native format.
Identity
OktaMicrosoft Entra IDGoogle WorkspaceCyberArkSCIM 2.0
Single sign-on, group sync, provisioning and de-provisioning, privileged-account context for attack paths.
Security platforms
CrowdStrike FalconMicrosoft DefenderSentinelOneWizPrisma CloudTenableRapid7 InsightVM
Import findings and asset context from platforms you already run; they corroborate native results instead of duplicating them.
OT security
ClarotyNozomi NetworksTenable OT
Operational-technology asset context joins the same graph as IT findings.
Developer platforms
Argo CDBackstageStatus page feed
Deployment provenance from Argo CD, service ownership from Backstage, status publication for your operators.
How connectors behave

Every connector, the same contract.

01

Health is an event

Connector health changes emit connector.health.changed@v1. A silent integration shows up on the dashboard and in alerts, not in a support ticket three weeks later.

02

Credentials at rest

Provider credentials are encrypted at rest and decrypted only inside the worker that needs them. Rotation is a first-class API with version tracking.

03

Least privilege

Cloud onboarding produces the minimum role for the collectors you enable. Registry and SCM tokens are scoped to read, plus write only for PR comments and gate status.

04

Inbound verified

Every inbound webhook is verified with the provider's HMAC scheme in constant time, with a five-minute timestamp window where the provider supplies one. Malformed input is a reject, never an exception.

05

Outbound signed

The generic webhook signs the payload with HMAC-SHA256 over canonical JSON so receivers can verify and de-duplicate.

06

Imported findings corroborate

Findings from Wiz, Prisma, Tenable or Rapid7 resolve into the same ontology as native results and become corroborates edges rather than duplicates.

Missing a connector?

Tell us what you run.

Connectors are added against real customer stacks. If yours is not here, the conversation starts with what you would need it to do.