Integrations

Safeguard plugs into the toolchain you already run.

SCM, CI/CD, identity, observability, comms, cloud runtime, and frontier AI models — first-class connectors out of the box, REST and webhooks for everything else.

Seven categories

First-class connectors, not afterthoughts.

Source / SCM

Where the code lives — Safeguard reads, scans, and writes auto-fix PRs.

GitHub
GitLab
Bitbucket
Azure DevOps
Gerrit

CI/CD

Drop-in steps for the pipeline you already run.

GitHub Actions
GitLab CI
Jenkins
CircleCI
Buildkite
Tekton
Argo CD

Issue trackers + comms

Findings, fix PRs, and policy breaches routed where humans already work.

Jira
ServiceNow
Linear
Slack
Microsoft Teams
PagerDuty
Opsgenie

Observability / SIEM

Stream the audit trail and detection events into your existing platform.

Splunk
Datadog
Elastic
Grafana
Sumo Logic
Sentry

Identity

SAML / OIDC plus SCIM for hands-off lifecycle.

Okta
Azure AD / Entra
Google Workspace
Ping
OneLogin

SAML / OIDC for sign-in, SCIM for provisioning and de-provisioning.

Cloud / runtime

Container registries, orchestrators, and admission controllers.

AWS (ECR, ECS, Lambda)
Azure (ACR, AKS, Functions)
GCP (GCR, GKE, Cloud Run)
Kubernetes
Docker
Open Policy Agent admission

AI models / frontier AI

Run Safeguard's agentic security on the frontier model of your choice — or bring your own. Safeguard is also available as a connector inside Claude.

Anthropic — Claude
OpenAI — GPT
Google — Gemini
Microsoft — Phi / Azure OpenAI
Meta — Llama
Mistral
Cohere
Safeguard — Griffin (security-only)
Package managers

Every major ecosystem.

Reachability, version-aware symbol resolution, and SBOM generation across the ecosystems your services actually run on.

Supported package ecosystems

npm
pypi
maven
gradle
go modules
cargo
rubygems
composer
nuget
hex
Build a custom integration

Open by default, standards-based.

The platform that does not own you back. Every Safeguard signal can leave the platform in a standard format.

REST API + webhooks

Every entity in Safeguard is reachable over the REST API. Subscribe to webhooks for findings, policy decisions, and SBOM lifecycle events to drive your own automations.

CycloneDX / SPDX import + export

Ingest third-party SBOMs, export your own. Both directions support the latest spec versions, signed attestations, and VEX statements.

OPA / Rego policy export

Export Safeguard policy definitions as OPA / Rego for use in admission controllers and CI gates outside the platform. Single source of truth, multiple enforcement points.

Want a connector we have not built yet?

Tell us the system you live in. Most integrations are a webhook and a mapping away — we will scope it with you.