Microsoft Teams Adaptive Cards, Outlook vendor risk cards, Slack notifications, ServiceNow ticketing, Jira and GitHub Issues, PagerDuty paging, HMAC-signed webhooks to any SIEM. Risk intelligence arrives at the point of decision.
Teams Adaptive Cards, Outlook vendor risk cards, SharePoint evidence libraries, Power Platform connector, Power BI dashboards.
ServiceNow (mapped per risk type), Jira, GitHub Issues with bi-directional status sync via integration_finding_refs.
PagerDuty incidents for critical risks and breach alerts. Acknowledgement reflected back in Verisq.
HMAC-SHA256 signed webhooks to Microsoft Sentinel, Splunk HEC, QRadar, Elastic SIEM, or any HTTPS endpoint.
Adaptive Cards delivered to Teams channels and users via Power Automate workflow webhooks — breach alerts, critical-risk creation, assessment completion, SLA countdowns and renewal alerts, routed to the right channel.
A vendor-risk card appears in the Outlook reading pane when a known vendor's domain is detected — live risk score, breach alerts, assessment and contract status, and quick actions — reading only the sender address, no email content.
A certified Power Platform custom connector exposes operations like GetVendorRiskScore, GetOpenRisks and CreateTask, with OAuth via Azure AD and event triggers for no-code/low-code automation.
A live Power BI connector feeds vendor portfolio, risk register and DSAR SLA data into executive dashboards — no CSV export, always current — with a pre-built executive risk report template.
Certificates, SOC reports, DPAs and DSAR evidence packages optionally sync to a tenant-controlled SharePoint library with metadata tags and version-history audit trail.
Federated SSO (OIDC/SAML 2.0) across all portals, Conditional Access support, SCIM provisioning, group-based role mapping, tenant-ID validation and PIM-compatible just-in-time admin access.
Risk types route to the right module — SBOM CVEs to Application Vulnerable Items, breach alerts to Security Incidents, assessment findings to GRC Issues — with priority-ordered routing, fan-out, templated close notes and bidirectional status sync.
Assessment findings and TPRM risks auto-create Jira issues in the configured project and issue type, with status changes syncing back to the Verisq risk lifecycle; SBOM CVEs land in the engineering backlog with CVSS and fix version.
Software vulnerabilities from SBOM monitoring create GitHub Issues in the relevant repository, routed by affected component, with severity mapped to issue labels for existing triage workflows.
Critical risks and breach alerts trigger PagerDuty incidents with severity mapping and acknowledgement sync; renewal-deadline paging can alert on-call before a DPA or contract lapses.
Any risk event fires a signed outbound webhook to any HTTPS endpoint — SIEM, SOAR, data lake — HMAC-SHA256 signed so receivers reject tampered payloads, with a versioned JSON schema and a 90-day deprecation window on breaking changes.
Event types like FindingCreated, BreachAlertReceived and SBOMCveMatched deliver to Microsoft Sentinel, Splunk and others via the same signed-webhook mechanism.
Purchase directly through Azure Marketplace against committed spend, MACC-credit eligible, with active ISV enrollment enabling Microsoft co-sell.
Every integration is built on open, documented standards — OAuth 2.0, OIDC/SAML, SCIM, OData, signed webhooks — no proprietary lock-in.
Verisq's Integrations is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.