Skip to content

Security & Compliance integrations

Ingests alerts, vulnerability findings, and compliance posture. Triggers containment, investigation, and remediation workflows across your security stack.

Containment in the first minutes

A compromised endpoint is isolated from the network straight from the incident, and connectivity is restored the same way once it is cleared.

Findings that arrive with their blast radius

A vulnerability finding is joined to the assets it affects, who owns them and what depends on them, so triage is a decision rather than an investigation.

Evidence collected as you go

Scans, tags, asset groups and the actions taken are recorded against the ticket, so an audit trail exists without assembling one afterwards.

Security & Compliance tools we connect to

Common questions

Does STLabs replace our EDR or vulnerability scanner?

No. It reads their findings and triggers their actions. They remain the detection and scanning engines.

Can it isolate a device without a human deciding?

That is your choice per action. Containment is commonly set to require approval, and both the request and the decision are recorded.

How is access to security actions controlled?

Through the same policy guardrails as everything else, so who can trigger containment is defined explicitly rather than inherited from a broad admin role.

See how it connects.Every tool, one live map.

All integrations