SSL Certificate Analysis Open Port Detection Web Application Scanning DNS Security Audit HTTP Header Analysis Misconfiguration Detection Software Fingerprinting Subdomain Enumeration Vulnerability Prioritization Continuous Monitoring Credential Exposure Checks OWASP-Aligned Scanning
SSL Certificate Analysis Open Port Detection Web Application Scanning DNS Security Audit HTTP Header Analysis Misconfiguration Detection Software Fingerprinting Subdomain Enumeration Vulnerability Prioritization Continuous Monitoring Credential Exposure Checks OWASP-Aligned Scanning

Connected Tools

Findings, delivered where the work already happens

A scan is only useful once the right person sees it. Connect the places your team already works and Sensagraph announces every finished scan in your channel, and turns any single finding into a ticket in your tracker — with the severity, the evidence and the recommended fix already written in.

Notification channels
Slack Microsoft Teams
Issue trackers
GitHub GitLab Jira

Two Kinds

One tells you. The other assigns it.

Integrations come in two families, and they behave differently on purpose. Knowing which one you are setting up saves a lot of confusion later.

Automatic

Notifications

Set up once. Every scan that finishes is announced in the channel you chose, without anyone asking for it.

On demand

Issue trackers

Nothing is filed automatically. You read a finding, decide it needs doing, and press the button that turns it into a ticket.

Notifications

The scan finishes. Your channel knows.

Pick one channel per workspace and leave it. When a scan completes, the message arrives with the finding counts for every tool that ran and a link straight to the full report.

  • Sent the moment a scan reaches a final state — completed, failed or partial.
  • Severity counts per tool, the target that was scanned, and a link to the report.
  • One destination per workspace, shared by everyone on the team.

What arrives in the channel

Target
The domain or URL the scan ran against.
Outcome
Completed, failed, or partial when some tools finished and others did not.
Findings
Counts by severity — critical, high, medium, low, info — for every tool that ran.
Report
A link straight to the full result, for whoever opens it first.

Slack

Install from the Slack directory, pick the channel, done. Results land there from the next scan onwards.

Read the Slack page

Microsoft Teams

Paste an incoming webhook from the channel you want the results in. No admin consent, no app to publish.

Issue Trackers

A finding becomes a ticket someone owns

Findings that need work belong in the same backlog as everything else your team is doing. Open a finding, choose where it should go, and the issue is created with the title, the severity, what was found and the recommended fix already filled in.

  • Nothing is filed on its own — a person decides, every time.
  • The repository, project or board is chosen when you file, not locked in at setup.
  • The finding keeps a link to the issue, so you can see what has already been raised.

What is written into the issue

Title
The finding, worded the same as it is on your board.
Severity
Critical, high, medium, low or info — carried across, not re-graded.
Location
The port, URL, host or check the finding is about.
Description
What was actually found on your host.
Fix
The recommended way to close it.

GitHub

Files into any repository the connected account can write to.

GitLab

Works with project access tokens as well as personal ones.

Jira

Pick the project, then the issue type your team files bugs as.

Setup

Connected in a few minutes

Every integration follows the same three steps, whichever one you are adding.

01

Open the integrations page

Everything lives on one screen in your board, grouped by what it does: channels at the top, trackers below.

02

Authorise the account

Install the app, or paste the token or webhook the provider gives you. We call the provider once to prove it works.

03

Use it

Notifications start with the next finished scan. Trackers appear as a button on every finding, ready when you are.

What We Do With It

A connection is a narrow one

An integration is a credential you hand us. Here is exactly what happens to it.

Proven before it is stored

A credential that does not work is never written down. We call the provider first and only save it once the call comes back.

Encrypted at rest

Tokens and webhook URLs are encrypted in the database and never sent back to the browser. The settings page shows the account name and nothing else.

Owned by the team

A connection belongs to the team, not to whoever added it. It survives that person leaving, and only a team admin can add or remove one.

Disconnected in one click

Remove a connection and the credential goes with it. Nothing further is sent, and nothing further is filed.

Wire it into your week

Connect a channel, run a scan, and see the results land where your team is already looking.