The Trust Operations Platform — demonstrate the compliance diligence your stakeholders expect, beyond SOC 2. See how it works →
Platform · Integrations

Verisq lives where your team already works.

Microsoft Teams Adaptive Cards, Outlook vendor risk cards, Slack notifications, ServiceNow ticketing, Jira and GitHub Issues, PagerDuty paging, HMAC-signed webhooks to any SIEM. Risk intelligence arrives at the point of decision.

Capabilities

Integrations — what's in the box.

+

Microsoft 365

Teams Adaptive Cards, Outlook vendor risk cards, SharePoint evidence libraries, Power Platform connector, Power BI dashboards.

+

Ticketing systems

ServiceNow (mapped per risk type), Jira, GitHub Issues with bi-directional status sync via integration_finding_refs.

+

On-call paging

PagerDuty incidents for critical risks and breach alerts. Acknowledgement reflected back in Verisq.

+

HMAC webhooks + SIEM

HMAC-SHA256 signed webhooks to Microsoft Sentinel, Splunk HEC, QRadar, Elastic SIEM, or any HTTPS endpoint.

Microsoft & Azure

Native across the Microsoft stack.

+

Teams notifications

Adaptive Cards delivered to Teams channels and users via Power Automate workflow webhooks — breach alerts, critical-risk creation, assessment completion, SLA countdowns and renewal alerts, routed to the right channel.

+

Outlook add-in

A vendor-risk card appears in the Outlook reading pane when a known vendor's domain is detected — live risk score, breach alerts, assessment and contract status, and quick actions — reading only the sender address, no email content.

+

Power Platform connector

A certified Power Platform custom connector exposes operations like GetVendorRiskScore, GetOpenRisks and CreateTask, with OAuth via Azure AD and event triggers for no-code/low-code automation.

+

Power BI dashboards

A live Power BI connector feeds vendor portfolio, risk register and DSAR SLA data into executive dashboards — no CSV export, always current — with a pre-built executive risk report template.

+

SharePoint evidence

Certificates, SOC reports, DPAs and DSAR evidence packages optionally sync to a tenant-controlled SharePoint library with metadata tags and version-history audit trail.

+

Azure AD identity

Federated SSO (OIDC/SAML 2.0) across all portals, Conditional Access support, SCIM provisioning, group-based role mapping, tenant-ID validation and PIM-compatible just-in-time admin access.

Ticketing & orchestration

Findings land where teams already work.

+

ServiceNow

Risk types route to the right module — SBOM CVEs to Application Vulnerable Items, breach alerts to Security Incidents, assessment findings to GRC Issues — with priority-ordered routing, fan-out, templated close notes and bidirectional status sync.

+

Jira

Assessment findings and TPRM risks auto-create Jira issues in the configured project and issue type, with status changes syncing back to the Verisq risk lifecycle; SBOM CVEs land in the engineering backlog with CVSS and fix version.

+

GitHub Issues

Software vulnerabilities from SBOM monitoring create GitHub Issues in the relevant repository, routed by affected component, with severity mapped to issue labels for existing triage workflows.

+

PagerDuty

Critical risks and breach alerts trigger PagerDuty incidents with severity mapping and acknowledgement sync; renewal-deadline paging can alert on-call before a DPA or contract lapses.

Webhooks & marketplace

Open, signed, and procurement-ready.

+

HMAC-signed webhooks

Any risk event fires a signed outbound webhook to any HTTPS endpoint — SIEM, SOAR, data lake — HMAC-SHA256 signed so receivers reject tampered payloads, with a versioned JSON schema and a 90-day deprecation window on breaking changes.

+

SIEM integration

Event types like FindingCreated, BreachAlertReceived and SBOMCveMatched deliver to Microsoft Sentinel, Splunk and others via the same signed-webhook mechanism.

+

Azure Marketplace

Purchase directly through Azure Marketplace against committed spend, MACC-credit eligible, with active ISV enrollment enabling Microsoft co-sell.

+

Standards-based

Every integration is built on open, documented standards — OAuth 2.0, OIDC/SAML, SCIM, OData, signed webhooks — no proprietary lock-in.

Stop running this in spreadsheets.

Verisq's Integrations is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.

See pricing Back to home