Integration options
ThreatMap can supply intelligence to external security workflows through authenticated REST and MCP. A named vendor in an early product proposal is not evidence of a contractual partnership or a packaged connector.
Implemented integration surfaces
- REST enrichment and infrastructure pivots for application/playbook clients.
- Stdio and Streamable HTTP MCP for compatible AI clients.
- Configured monitor alert destinations: email, HTTPS webhook, and Slack.
- Licensed provider credentials through BYOK and source preferences.
Scope to confirm before integration
Confirm request/response schemas, provider licenses, plan gates, target authorization, and delivery configuration. Generic API access does not imply built-in SIEM/SOAR/EDR connectors, bidirectional event ingestion, OCSF push, or TAXII/STIX delivery. These require a specific implemented integration.
Contact your ThreatMap account team for partnership and connector scope. See implemented APIs.