Platform · Integrations

The Agency, in your existing stack.

API, webhooks and an MCP server. Pre-built connections into your SIEM, ITSM, GRC, data warehouse and identity layer. The agents work where your team already works — not in a tab nobody opens.

How does RiskXchange integrate with other systems?

Through four mechanisms, chosen according to which direction the data needs to move and how quickly.

A REST API for reading vendor records, scores, findings and assessment state, and for creating or updating vendors programmatically — the route for anything that needs to pull data on its own schedule. Webhooks for the reverse direction, pushing events as they happen — a score change crossing a threshold, a new breach signal, an assessment completing, a remediation deadline missed — so downstream systems react rather than poll. Pre-built connectors into the systems teams already work in: SIEM, ITSM and ticketing, GRC platforms, chat, identity providers and the data warehouse. And an MCP server, which exposes the same capabilities to AI assistants and agents through the Model Context Protocol, so a question about a vendor can be answered in whatever tool someone is already using.

The design intent behind all four is the same: risk signal is only useful where the decision is made. A finding that requires someone to open a separate dashboard to discover it will be discovered late, which is why alerts belong in the chat tool, remediation in the ticketing system, and reporting in the warehouse alongside everything else the business reports on.

The numbers your team already knows.

Most TPRM platforms expect to be the centre of your day. The reality is that your team lives in Slack, Teams, ServiceNow, Jira and your SIEM — and a tool that doesn't push and pull from those is a tool that gets checked once a week.

API + MCP
First-class machine interfaces, not an afterthought
< 1 day
Typical webhook integration into a SIEM or ITSM
5 leads
Agents you can pipe into your stack — NOVA, REX, ARIA, TARA, VANCE

Three pipes into your stack.

REX pipes signal out, TARA pipes remediation tickets in, VANCE pipes reports to the warehouse — every agent has an integration shape that fits how your team actually works.

REX avatar
REX
Risk & Breach Intelligence

Signal where your team will see it. REX's findings — breach alerts, attack-surface changes, dark-web hits — push into your SIEM, your ticketing system or your chat tools the moment they're ranked.

What you get
  • Webhooks for breach alerts and material rating drops
  • SIEM connectors — Splunk, Sentinel, Elastic, Chronicle
  • Slack / Teams / WhatsApp delivery for vendor-relevant signal
TARA avatar
TARA
Tiering & Remediation

Remediation in the system your team actually uses. TARA opens, owns and closes remediation in your ITSM — ServiceNow, Jira, Asana — with SLA timers, evidence links and tier-aware routing.

What you get
  • ServiceNow, Jira and Asana connectors
  • SLA-driven ticket routing with tier-based escalation
  • Evidence and audit trail linked back to the originating finding
VANCE avatar
VANCE
Vendor Analysis & Compliance

Reports where your reporting tools live. VANCE outputs land in the data warehouse, the GRC platform or the BI layer — so board packs, audit bundles and regulator reports compose against the same source of truth your finance and compliance teams already use.

What you get
  • Snowflake, BigQuery and Databricks connectors
  • GRC integration — Archer, ServiceNow IRM, OneTrust
  • Scheduled report delivery to email, SharePoint and Drive

From a tool you check to a workforce in your stack.

The integration shape decides whether agents are a side-quest or a teammate. Done right, the agents disappear into the systems your team already opens every day.

Alerts arrive in the chat tool, not the dashboard

Slack, Teams and WhatsApp delivery for ranked, vendor-attributed signal — so the right person sees the right alert without logging in.

Tickets open in your ITSM

TARA owns the remediation lifecycle in ServiceNow, Jira or Asana. Your team works in the queue they already work — the agent is just a participant.

Reports land in the warehouse

VANCE outputs flow into Snowflake, BigQuery or Databricks. Board packs and audit bundles compose against the same data your finance team trusts.

Build once with API + MCP

Full REST API, webhooks and an MCP server for AI-native workflows. Custom integrations are a day, not a quarter.

We piped REX into Sentinel, TARA into Jira and VANCE into Snowflake in a day each. The agents stopped being a separate tool — they became part of the way the team works.

RJ
Head of Security Engineering
Top-25 European bank

What teams ask about integrations.

APIs, events, single sign-on and getting risk data into the tools you already run.

Is there a public API?
Yes — a REST API covering vendor records, scores and score history, findings, assessment state and remediation, with programmatic vendor creation and update. Full API access is included from the Professional tier upward; see the platform pricing page for what each tier includes. It is the right mechanism when a system needs to pull on its own schedule or backfill history; for reacting to change as it happens, webhooks are the better fit.
What is an MCP server, and why does RiskXchange have one?
The Model Context Protocol is an open standard for connecting AI assistants to external tools and data sources. An MCP server exposes a system's capabilities in a form an assistant can call directly, so someone can ask a question in the assistant they already use — what is this vendor's current posture, what is outstanding against them, which of our critical vendors deteriorated this month — and get an answer from live data rather than switching tools to look it up. It is the same principle as the other integrations applied to a newer surface.
Which events can trigger a webhook?
The changes worth reacting to: a security rating crossing a threshold you set, a new breach or credential exposure affecting a vendor, an assessment being completed or a response submitted, a finding opened or closed, a remediation SLA approaching or missed, and changes to a vendor's tier or status. The intended pattern is that a material change opens a ticket or posts to a channel automatically, so the first person to know is not whoever happened to open the dashboard.
Do you support single sign-on?
Yes, via SAML and OIDC against the usual identity providers — Microsoft Entra ID, Okta, and others. SSO is an Enterprise tier feature. All tiers include unlimited user seats, so licensing does not discourage giving access to everyone who needs it, which matters more than it sounds: risk data that only three people can see gets routed through those three people.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.