Integrations

Connect SecurityAlert to the tools your team already uses.

Send alerts, move threat intelligence into your SIEM or TIP, and bring account-level evidence into SecurityAlert. Every connection is labeled by how it works and whether it is available today.

Slack, Teams, email, and webhooksOperational alert delivery
STIX 2.1 and TAXII 2.1Threat intelligence exchange
OpenAPI 3.1 and MCPDeveloper and agent workflows
Scoped ingestion APIsIdentity and SIEM evidence

All integrations

Every available and planned connection is shown below by default. Category links jump to a section; they do not hide the rest.

30 integrations in 6 categories

Send alerts where your team works

Choose where new findings and operational alerts should go. Each destination below is available today.

6 connections
Integration Connection method Availability Plan Action

Email

Choose the alert categories you want and receive readable HTML and plain-text messages.

Email delivery
Available now
Free+

Slack

Send high-signal brand alerts to a Slack channel and test the connection from the brand settings drawer.

Incoming webhook
Available now
Pro+

Microsoft Teams

Send the same operational alerts to a Teams channel as a readable Microsoft MessageCard.

Incoming webhook
Available now
Pro+

Signed webhook

Post selected events to your own intake endpoint with an optional HMAC signature over the raw JSON body.

HTTPS webhook
Available now
Pro+

Discord

Send a formatted alert embed to a Discord channel.

Incoming webhook
Available now
Pro+

Google Chat

Send a compact alert card to a Google Chat space.

Incoming webhook
Available now
Pro+

Send intelligence to your security stack

Move reviewed intelligence and findings into a SIEM, TIP, analyst workflow, or internal application through documented standards and APIs.

7 connections
Integration Connection method Availability Plan Action

STIX 2.1 and TAXII 2.1

Poll the public actor catalog or authenticated tenant collections with a standard TAXII 2.1 client.

Standards-based feed
Available now
Public / Business+

MISP-shaped events

Retrieve brand-protection and dark-web findings as MISP-shaped JSON for your own import workflow.

API import
Available now
Business+

REST API v1

Pull findings and indicator lookups with scoped Bearer keys and a documented 120 request-per-minute limit.

OpenAPI 3.1
Available now
Business+

Vendor advisory RSS

Follow all official vendor advisories or narrow the feed by vendor, severity, product, CVE, or advisory ID.

Filterable public RSS
Available now
Free+

Security news RSS

Follow the publisher reporting shown in the Security News hub, or narrow the feed by publisher, topic, CVE, product, or actor.

Filterable public RSS
Available now
Free+

Ransomware RSS

Follow the 25 most recent ransomware leak-site posts through a lightweight public feed.

Public RSS
Available now
Free+

Release notes RSS

Subscribe to product updates and major rollout notes without watching the changelog manually.

Public RSS
Available now
Free+

Bring identity and SIEM evidence into SecurityAlert

Add customer-owned account context without handing SecurityAlert your directory or SIEM credentials. Directory inventory adds context; only account-level evidence creates a case.

6 connections
Integration Connection method Availability Plan Action

Microsoft Entra ID

Correlate display name, account status, department, role, and high-value context with real evidence.

Directory snapshot
Available now
Business+

Google Workspace

Import an authorized account inventory for ownership and status context without creating findings from inventory alone.

Directory snapshot
Available now
Business+

Okta and other directories

Use the normalized directory contract for customer-controlled account inventory.

CSV or API
Available now
Business+

Entra ID Protection

Send normalized risky-user and identity detections with the account, event type, risk state, service, and date.

Ingestion API
Available now
Business+

Microsoft Sentinel and Defender

Forward normalized account-level events while raw logs and authentication material remain outside SecurityAlert.

Ingestion API
Available now
Business+

Splunk and Elastic Security

Send normalized identity evidence with a write-scoped key while source credentials stay in your environment.

Ingestion API
Available now
Business+

Build and automate your own workflows

Use scoped interfaces for internal tools, analyst assistants, deployment checks, and custom dashboards.

3 connections
Integration Connection method Availability Plan Action

MCP server

Query findings, pending proposals, exposure, threat actors, and infrastructure from an MCP client or internal agent.

Streamable HTTP
Available now
Business+

REST API and OpenAPI

Build with scoped Bearer keys, explicit rate limits, OpenAPI 3.1, and an interactive API reference.

JSON over HTTPS
Available now
Business+

Scoped API keys

Mint per-user keys, restrict their permissions, and revoke them without changing a user account.

Bearer authentication
Available now
Business+

Connect access and governance

Control how people sign in, what they can change, and how sensitive actions are recorded.

4 connections
Integration Connection method Availability Plan Action

Auth0 sign-in

Support standard email, Google, and GitHub sign-in through the SecurityAlert identity boundary.

OIDC
Available now
Free+
No setup needed

Role-based access

Give each person view or manage access across eleven product areas through built-in or custom roles.

RBAC
Available now
Business+

Organization SSO

Connect an organization identity provider for federated sign-in and centralized access control.

SAML or OIDC
Available now
Enterprise

Audit logs

Review brand changes, takedown submissions, role changes, and integration updates.

Recorded actions
Available now
Business+

Connections we are preparing next

The delivery code exists, but these destinations are not available in the product yet. They stay separate from integrations you can configure today.

4 connections
Integration Connection method Availability Plan Action

Jira

Create an issue from a reviewed finding and keep the SecurityAlert link with it.

Issue creation
Coming next
Planned
Not yet available

PagerDuty

Open an incident from an actionable alert and resolve it when the workflow closes.

Events API v2
Coming next
Planned
Not yet available

Opsgenie

Create an operational alert with severity and source context.

Alert API
Coming next
Planned
Not yet available

SMS

Reserve text messages for urgent alerts and verified recipients.

Verified phone
Coming next
Planned
Not yet available

Connect the first workflow without a sales call.

Start with email or a public feed. Business adds API keys, MCP, identity ingestion, tenant feeds, and alert routing. Enterprise adds organization SSO and custom integration work.

Start free Request an integration

Product names and logos belong to their respective owners. They are shown only to identify supported or planned connections.