Connect SecurityAlert to the tools your team already uses.
Send alerts, move threat intelligence into your SIEM or TIP, and bring account-level evidence into SecurityAlert. Every connection is labeled by how it works and whether it is available today.
All integrations
Every available and planned connection is shown below by default. Category links jump to a section; they do not hide the rest.
Send alerts where your team works
Choose where new findings and operational alerts should go. Each destination below is available today.
Choose the alert categories you want and receive readable HTML and plain-text messages.
Slack
Send high-signal brand alerts to a Slack channel and test the connection from the brand settings drawer.
Microsoft Teams
Send the same operational alerts to a Teams channel as a readable Microsoft MessageCard.
Signed webhook
Post selected events to your own intake endpoint with an optional HMAC signature over the raw JSON body.
Discord
Send a formatted alert embed to a Discord channel.
Google Chat
Send a compact alert card to a Google Chat space.
Send intelligence to your security stack
Move reviewed intelligence and findings into a SIEM, TIP, analyst workflow, or internal application through documented standards and APIs.
STIX 2.1 and TAXII 2.1
Poll the public actor catalog or authenticated tenant collections with a standard TAXII 2.1 client.
MISP-shaped events
Retrieve brand-protection and dark-web findings as MISP-shaped JSON for your own import workflow.
REST API v1
Pull findings and indicator lookups with scoped Bearer keys and a documented 120 request-per-minute limit.
Vendor advisory RSS
Follow all official vendor advisories or narrow the feed by vendor, severity, product, CVE, or advisory ID.
Security news RSS
Follow the publisher reporting shown in the Security News hub, or narrow the feed by publisher, topic, CVE, product, or actor.
Ransomware RSS
Follow the 25 most recent ransomware leak-site posts through a lightweight public feed.
Release notes RSS
Subscribe to product updates and major rollout notes without watching the changelog manually.
Bring identity and SIEM evidence into SecurityAlert
Add customer-owned account context without handing SecurityAlert your directory or SIEM credentials. Directory inventory adds context; only account-level evidence creates a case.
Microsoft Entra ID
Correlate display name, account status, department, role, and high-value context with real evidence.
Google Workspace
Import an authorized account inventory for ownership and status context without creating findings from inventory alone.
Okta and other directories
Use the normalized directory contract for customer-controlled account inventory.
Entra ID Protection
Send normalized risky-user and identity detections with the account, event type, risk state, service, and date.
Microsoft Sentinel and Defender
Forward normalized account-level events while raw logs and authentication material remain outside SecurityAlert.
Splunk and Elastic Security
Send normalized identity evidence with a write-scoped key while source credentials stay in your environment.
Build and automate your own workflows
Use scoped interfaces for internal tools, analyst assistants, deployment checks, and custom dashboards.
MCP server
Query findings, pending proposals, exposure, threat actors, and infrastructure from an MCP client or internal agent.
REST API and OpenAPI
Build with scoped Bearer keys, explicit rate limits, OpenAPI 3.1, and an interactive API reference.
Scoped API keys
Mint per-user keys, restrict their permissions, and revoke them without changing a user account.
Connect access and governance
Control how people sign in, what they can change, and how sensitive actions are recorded.
Auth0 sign-in
Support standard email, Google, and GitHub sign-in through the SecurityAlert identity boundary.
Role-based access
Give each person view or manage access across eleven product areas through built-in or custom roles.
Organization SSO
Connect an organization identity provider for federated sign-in and centralized access control.
Audit logs
Review brand changes, takedown submissions, role changes, and integration updates.
Connections we are preparing next
The delivery code exists, but these destinations are not available in the product yet. They stay separate from integrations you can configure today.
Jira
Create an issue from a reviewed finding and keep the SecurityAlert link with it.
PagerDuty
Open an incident from an actionable alert and resolve it when the workflow closes.
Opsgenie
Create an operational alert with severity and source context.
SMS
Reserve text messages for urgent alerts and verified recipients.
Connect the first workflow without a sales call.
Start with email or a public feed. Business adds API keys, MCP, identity ingestion, tenant feeds, and alert routing. Enterprise adds organization SSO and custom integration work.
Product names and logos belong to their respective owners. They are shown only to identify supported or planned connections.