Integrations
Connected Tools
Findings, delivered where the work already happens
A scan is only useful once the right person sees it. Connect the places your team already works and Sensagraph announces every finished scan in your channel, and turns any single finding into a ticket in your tracker — with the severity, the evidence and the recommended fix already written in.
Two Kinds
One tells you. The other assigns it.
Integrations come in two families, and they behave differently on purpose. Knowing which one you are setting up saves a lot of confusion later.
Notifications
Set up once. Every scan that finishes is announced in the channel you chose, without anyone asking for it.
Issue trackers
Nothing is filed automatically. You read a finding, decide it needs doing, and press the button that turns it into a ticket.
Notifications
The scan finishes. Your channel knows.
Pick one channel per workspace and leave it. When a scan completes, the message arrives with the finding counts for every tool that ran and a link straight to the full report.
- Sent the moment a scan reaches a final state — completed, failed or partial.
- Severity counts per tool, the target that was scanned, and a link to the report.
- One destination per workspace, shared by everyone on the team.
What arrives in the channel
- Target
- The domain or URL the scan ran against.
- Outcome
- Completed, failed, or partial when some tools finished and others did not.
- Findings
- Counts by severity — critical, high, medium, low, info — for every tool that ran.
- Report
- A link straight to the full result, for whoever opens it first.
Slack
Install from the Slack directory, pick the channel, done. Results land there from the next scan onwards.
Read the Slack pageMicrosoft Teams
Paste an incoming webhook from the channel you want the results in. No admin consent, no app to publish.
Issue Trackers
A finding becomes a ticket someone owns
Findings that need work belong in the same backlog as everything else your team is doing. Open a finding, choose where it should go, and the issue is created with the title, the severity, what was found and the recommended fix already filled in.
- Nothing is filed on its own — a person decides, every time.
- The repository, project or board is chosen when you file, not locked in at setup.
- The finding keeps a link to the issue, so you can see what has already been raised.
What is written into the issue
- Title
- The finding, worded the same as it is on your board.
- Severity
- Critical, high, medium, low or info — carried across, not re-graded.
- Location
- The port, URL, host or check the finding is about.
- Description
- What was actually found on your host.
- Fix
- The recommended way to close it.
GitHub
Files into any repository the connected account can write to.
GitLab
Works with project access tokens as well as personal ones.
Jira
Pick the project, then the issue type your team files bugs as.
Setup
Connected in a few minutes
Every integration follows the same three steps, whichever one you are adding.
Open the integrations page
Everything lives on one screen in your board, grouped by what it does: channels at the top, trackers below.
Authorise the account
Install the app, or paste the token or webhook the provider gives you. We call the provider once to prove it works.
Use it
Notifications start with the next finished scan. Trackers appear as a button on every finding, ready when you are.
What We Do With It
A connection is a narrow one
An integration is a credential you hand us. Here is exactly what happens to it.
Proven before it is stored
A credential that does not work is never written down. We call the provider first and only save it once the call comes back.
Encrypted at rest
Tokens and webhook URLs are encrypted in the database and never sent back to the browser. The settings page shows the account name and nothing else.
Owned by the team
A connection belongs to the team, not to whoever added it. It survives that person leaving, and only a team admin can add or remove one.
Disconnected in one click
Remove a connection and the credential goes with it. Nothing further is sent, and nothing further is filed.
Wire it into your week
Connect a channel, run a scan, and see the results land where your team is already looking.