- Available
Snyk
Find out which Snyk Open Source and Snyk Code findings are exploitable in your code, with the evidence behind each verdict.
- SCA
- SAST
- Container Security
- Available

Black Duck
Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.
- SCA
- SAST
- Available
Dependabot
Get an exploitability verdict for each Dependabot alert, and dismiss the false positives in GitHub with the evidence linked.
- SCA
- Available
GitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
- SAST
- SCA
- Ticketing & Messaging
- Available

Endor Labs
Add an exploitability verdict with evidence to Endor Labs SCA findings, on top of Endor's own reachability.
- SCA
- Available
CodeQL
Check whether each CodeQL security alert is exploitable, and dismiss the false positives in GitHub code scanning.
- SAST
- Available
GitLab
Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.
- SCA
- SAST
- Ticketing & Messaging
- Available
OWASP Dependency-Check
Send OWASP Dependency-Check results to Konvu through the API or CLI and find out which flagged dependencies are exploitable.
- SCA
- Available
OWASP Dependency-Track
Send OWASP Dependency-Track findings to Konvu through the API or CLI for an exploitability verdict on each component vulnerability.
- SCA
- Available
Semgrep
Find out which Semgrep Supply Chain and Semgrep Code findings are exploitable, with the evidence behind each verdict.
- SAST
- SCA
- Available
Checkmarx
Send Checkmarx One SCA and SAST results to Konvu for an exploitability verdict with evidence, through the Konvu API or a report upload.
- SAST
- SCA
- Available

Veracode
Send Veracode SCA and Static Analysis results to Konvu for an exploitability verdict with evidence, through the Konvu API or a report upload.
- SCA
- SAST
- Available
SonarQube
Upload SonarQube security issues to Konvu to have each one triaged and reproduced against your code.
- SAST
- Available
Trivy
Send Trivy repository scan results to Konvu through the API or CLI and get an exploitability verdict for each vulnerable dependency.
- SCA
- Container Security
- Available

Grype
Send Grype directory and SBOM scan results to Konvu through the API or CLI for an exploitability verdict on each vulnerable package.
- SCA
- Container Security
- Available

Wiz
Get an exploitability verdict for Wiz container image vulnerabilities, and optionally add it to the finding in Wiz as a note.
- Cloud Security
- Available
AWS Security Hub
Get exploitability verdicts for the AWS Inspector container findings in Security Hub, read directly from Inspector.
- Cloud Security
- Available
AWS Inspector
Check whether the vulnerabilities AWS Inspector finds in your ECR container images are exploitable.
- Cloud Security
- Available
Jira
Push triaged, exploitable vulnerabilities to Jira with full evidence trails.
- Ticketing & Messaging
- Available

Slack
Alert security and engineering channels when Konvu confirms exploitable vulnerabilities.
- Ticketing & Messaging
- Available

Arnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
- Available
Claude Code
Konvu Guardrails checks Claude Code-generated changes for business-logic vulnerabilities. Konvu Triage & Fix investigates existing scanner findings and opens fix pull requests.
- Developer Tools
- Available
Codex
Konvu Guardrails checks Codex-generated changes for business-logic vulnerabilities. Konvu Triage & Fix investigates existing scanner findings and opens fix pull requests.
- Developer Tools
- Available
Cursor
Konvu Guardrails checks Cursor-generated changes for business-logic vulnerabilities. Konvu Triage & Fix investigates existing scanner findings and opens fix pull requests.
- Developer Tools
- Available
VS Code
Ask Konvu about affected CVEs and triage recommendations in GitHub Copilot Chat. Use the CLI for full evidence and remediation from the integrated terminal.
- Developer Tools
- Available
Visual Studio
Ask Konvu about affected CVEs and triage recommendations in GitHub Copilot Agent. Use the CLI for full evidence and remediation from the terminal.
- Developer Tools
- Available
HackerOne
Reproduce and verify HackerOne bug bounty submissions automatically in a sandboxed environment.
- Bug Bounty
- Available
GitHub Advisory
Reproduce and verify GitHub Advisory submissions automatically in a sandboxed environment.
- Bug Bounty
- Coming soon

Mend
Focus Mend's license and vulnerability alerts on components that pose actual exploit risk.
- SCA
- Coming soon

Sonatype
Enrich Sonatype's component intelligence with environment-specific exploitability analysis.
- SCA
- Coming soon
JFrog Xray
Triage JFrog Xray artifact vulnerabilities based on exploitability in your environment.
- SCA
- Coming soon

OpenText Fortify
Add exploitability analysis to Fortify findings and prioritize based on environment-specific conditions.
- SAST
- Coming soon

Coverity
Prioritize Coverity's deep static analysis defects based on exploitability.
- SAST
- Coming soon
Aqua Security
Triage Aqua image CVEs and vulnerability findings with exploitability analysis.
- Container Security
- Coming soon

Sysdig
Prioritize Sysdig vulnerability findings with environment-specific exploitability analysis.
- Container Security
- Coming soon
Prisma Cloud
Triage Prisma Cloud alerts with environment-specific exploitability analysis.
- Cloud Security
- Coming soon

Lacework
Focus Lacework anomaly alerts on hosts with exploitable vulnerabilities.
- Cloud Security
- Coming soon

Anchore
Triage Anchore policy violations and SBOM vulnerabilities with exploitability analysis.
- Container Security
- Coming soon
Docker Scout
Focus Docker Scout recommendations on vulnerabilities exploitable in your environment.
- Container Security
- Coming soon

Orca Security
Prioritize Orca's agentless findings using environment-specific exploitability analysis.
- Cloud Security
- Coming soon

Check Point CloudGuard
Filter CloudGuard posture findings to focus on exploitable security gaps.
- Cloud Security
- Coming soon
Microsoft Defender
Triage Defender for Cloud alerts with exploit context across Azure and multi-cloud.
- Cloud Security
- Coming soon
Google Cloud Security Command Center
Triage SCC findings with exploit data across GCP assets and vulnerabilities.
- Cloud Security
- Coming soon
Datadog Cloud Security
Prioritize Datadog CSM findings with environment-specific exploitability analysis.
- Cloud Security
- Coming soon

Tenable
Focus Tenable/Nessus scans on vulnerabilities exploitable in your environment.
- Infra Security
- Coming soon
Qualys
Triage Qualys VMDR findings using environment-specific exploitability analysis.
- Infra Security
- Coming soon

Rapid7
Prioritize InsightVM findings with environment-specific exploitability analysis.
- Infra Security
- Coming soon
Cisco Vulnerability Management
Focus Cisco risk scores on vulnerabilities with confirmed exploitability.
- Infra Security
- Coming soon

CrowdStrike
Triage Falcon Spotlight vulnerabilities with exploit context and endpoint telemetry.
- Infra Security
- Coming soon

Tanium
Focus Tanium vulnerability findings on exploitable CVEs across endpoint fleet.
- Infra Security
- Coming soon

ServiceNow
Route verified vulnerabilities into ServiceNow incidents with evidence for change management.
- Ticketing & Messaging
- Coming soon
Azure DevOps
Create Azure DevOps work items for exploitable findings with evidence.
- Ticketing & Messaging
- Coming soon
Linear
Send triaged vulnerabilities to Linear with exploit context for fast engineering cycles.
- Ticketing & Messaging
- Coming soon

Microsoft Teams
Notify Microsoft Teams channels when exploitable vulnerabilities require attention.
- Ticketing & Messaging
- Coming soon
PagerDuty
Trigger PagerDuty incidents for critical, exploitable vulnerabilities requiring on-call response.
- Ticketing & Messaging
- Coming soon

ArmorCode
Enrich ArmorCode's aggregated findings with Konvu's exploitability analysis.
- ASPM
- Coming soon

Apiiro
Layer exploitability evidence onto Apiiro's risk-based code-to-cloud findings.
- ASPM
- Coming soon

Cycode
Augment Cycode's pipeline and posture findings with exploitability analysis.
- ASPM
- Coming soon

JupiterOne
Connect JupiterOne asset relationships with Konvu's vulnerability exploitability analysis.
- ASPM
- Coming soon

DefectDojo
Send Konvu's triaged findings to DefectDojo with exploitability evidence.
- ASPM
- Coming soon
Bugcrowd
Verify Bugcrowd vulnerability submissions with automated sandbox reproduction.
- Bug Bounty
- Coming soon
Intigriti
Automate reproduction of Intigriti bug bounty reports with sandboxed exploitation and evidence.
- Bug Bounty
- Coming soon
YesWeHack
Verify YesWeHack vulnerability reports with automated sandbox reproduction.
- Bug Bounty
- Coming soon
ModSecurity
Optional compensating rules in ModSecurity, for cover while the pull request that fixes the finding ships.
- WAF
- Coming soon
AWS WAF
Optional compensating rules in AWS WAF, for cover while the pull request that fixes the finding ships.
- WAF
- Coming soon
Cloudflare WAF
Optional compensating rules in Cloudflare WAF, for cover while the pull request that fixes the finding ships.
- WAF