CI and CD pipelines
Trigger scans automatically on every build, block risky releases before they ship and surface results next to the rest of your pipeline status.
- Run scans from common CI systems, including hosted and self-managed runners
- Fail the build on policy violations you define
- Attach scan results and links to the pipeline run for audit trail
- Support for mono-repos and multi-module Android and iOS projects
Ticketing and issue tracking
Turn findings into tickets in the system your engineers already use, with consistent titles, severity and remediation context.
- Create tickets in popular issue trackers directly from a finding
- Two-way status sync so closing a ticket updates the finding
- Project, component and assignee mapping per application
- Configurable templates for titles, labels and acceptance criteria
SIEM and log pipelines
Stream scan events, findings and policy decisions into your SIEM so security operations sees the same signal as the platform UI.
- Structured event stream for every scan and finding lifecycle change
- Standard outbound formats suitable for common SIEM platforms
- Configurable filtering so only the events you care about leave the platform
- Delivery with retries and per-destination authentication
Identity and single sign-on
Authentication that fits into the identity stack your organisation already runs, with central control over who can do what.
- SSO via SAML 2.0 and OpenID Connect
- SCIM-based user provisioning and deprovisioning
- Role-based access control with least-privilege defaults
- Audit log of user and admin activity
Collaboration and chat
Keep the people who need to know in the loop with notifications that go to the channels they already watch.
- Notifications for scan completion, new criticals and policy violations
- Per-project routing to the right channel or group
- Mute, digest and severity-based filtering
Reporting and evidence export
Everything a scan produces can leave the platform in a form that is easy to archive, review and share with auditors.
- PDF reports for executives and auditors
- Structured JSON and CSV exports for analysts and data teams
- SBOM export in common open formats
- Stable URLs for long-lived references in your own systems
APIs and webhooks
If an integration is not on the list, you can almost certainly build it yourself in an afternoon.
- REST API covering projects, scans, findings and reports
- Webhooks for every major lifecycle event
- Scoped API tokens with audit trail
- Rate limits and pagination suitable for automation at scale
Do not see your tool?
Tell us what you use. If an integration is on our roadmap we will say so, and if it is not we will help you get there through the API or webhooks.
Contact us
Start Free Trial