Back to home
Integrations

Works with the security stack you already run.

SentriScope connects to your existing tools through governed connectors, not passive pipes. Every ingestion path preserves evidence, respects tenant isolation, tracks connector health, and normalizes data into the canonical model for investigation and risk decisions.

15+
Connector types in the platform registry: live count, not a marketing claim
Governed
Every connector session is tenant-scoped, audited, and health-monitored
Normalized
All sources map into one canonical data model with provenance
Connector philosophy

Integrations are governed, not passive

SentriScope treats every external connection as a governed operation, with lifecycle management, authentication boundaries, synchronization controls, and full auditability.

Canonical normalization

Many products, one canonical spine

Data from disparate security tools is normalized into common canonical entities, so context compounds instead of fragmenting across vendor silos.

  1. 1 · Ingest Multiple products Vulnerability scanners, EDR, identity directories, cloud posture tools, and CMDB sources.
  2. 2 · Normalize Canonical entities Assets, vulnerabilities, identities, and findings with provenance and confidence on every record.
  3. 3 · Decide Risk decisions Deterministic prioritization across normalized signals with auditable lineage.
  4. 4 · Investigate Analyst workflow Investigation sessions connect enriched context to analyst decisions.

Product capability catalog

Connector governance

Safe, auditable, tenant-scoped operations

Governance is not a marketing label. It describes how connector sessions behave in production.

Tenant-scoped sessions

Every connector session operates within strict tenant boundaries. No cross-tenant data access.

Idempotent synchronization

Safe retries and idempotent patterns prevent duplicate or conflicting records during synchronization.

Audited operations

Connector and governance events are recorded in the tamper-evident audit chain.

Health monitoring

Operational state and connector health visibility for your security team.

Session history

Versioned connector behavior with session history for operational traceability.

No autonomous remediation

Connectors ingest and normalize. They do not autonomously remediate findings or execute unsupervised changes.

Connector catalog

Grouped by integration domain

The catalog below is live from the platform registry, not a static logo wall. Each category explains why that domain matters for canonical risk intelligence.

  • Vulnerability Scanners
    Normalize vulnerability findings from multiple scanners into one prioritization spine, beyond raw severity from any single vendor.

    Tenable Vulnerability Management (Tenable.io)

  • EDR / XDR / Endpoint
    Endpoint detection and response context linked to assets, identities, and exposure in the canonical model.

    CrowdStrike Falcon · Microsoft Defender for Endpoint · Palo Alto Cortex XDR · SentinelOne Singularity · Trellix Endpoint Security (ENS / ePO)

  • Identity & Access
    Directory and privilege context for identity risk aggregation and credential intelligence correlation.

    Microsoft Entra ID

  • Cloud & Security Posture
    Cloud exposure and security posture findings normalized alongside on-premises and hybrid assets.

    Palo Alto Cortex Cloud (Prisma Cloud) · Qualys Vulnerability Management (VMDR / VM) · SecurityScorecard

  • OT & Industrial Security
    Industrial and OT asset context for network segmentation and operational technology risk visibility.

    Nozomi Networks Vantage

  • CMDB & ITSM
    Asset inventory and service management context to enrich canonical assets with business and ownership metadata.

    Jira Service Management Assets (CMDB) · ServiceNow CMDB

  • Risk, Threat Intel & MDR
    Threat intelligence feeds, risk ratings, and managed detection context for CTI correlation and enrichment.

    Akamai Guardicore Segmentation · Tempest Prospero (DRP Monitoring API v2)

Threat intelligence enrichment

CTI providers configured per tenant

IOC enrichment runs through configured providers with encrypted credentials, separate from ingestion connectors and governed under the same tenant isolation model.

Extensibility

Structured extension for custom integrations

New connector types can be added through the governed provider framework, with the same lifecycle, audit, and tenant isolation requirements as built-in integrations.

Explore further

How integrations connect to the platform

Platform

Three-surface architecture, connector governance, and operator foundations.

Product

Capability catalog: what normalized data enables for analysts.

Intelligence

Analyst workflows that consume connected context.

Security

Isolation, audit chain, and connector security depth.

Documentation

Certified public documentation, not internal repository exposure.

Contact

Integration requirements, custom connectors, and deployment questions.

See how your stack connects

Review tenant architecture, ask about specific connector requirements, or talk to our team about governed integration for your environment.