Close

API and Integrations

API and integrations

Scan output has to reach the systems your security operation already runs: the SIEM, the ticket queue, the warehouse. Cyprob opens its data over a REST API and leaves the integration under your control.

What the API exposes

Asset inventory, scan state and findings are read over the REST API. Starting a scan and pulling its result use the same calls the console itself makes, so every value you see in the console is available over the API. Authentication goes through the same permission model as console users.

Asset detail view: every value shown in the console is readable over the API
Asset detail view: every value shown in the console is readable over the API

Where the integration is built

On your side. Your institution decides which system receives findings, in what format and how often. The transfer into a SIEM, a ticketing system or a warehouse is written in your own integration layer. Which systems may hold vulnerability data is a question of your security policy, and the product leaves that decision with you.

The API on a closed network

The API runs where the product runs, and it stays fully functional in an installation with no internet access. A scheduler or automation tool inside your network can open a scan and collect the result without any traffic leaving your infrastructure.

Common questions

Is there a separate permission model for the API?

No. API calls go through the same authorisation model as console users, and everything visible in the console can be read over the API.

Can a scan be started over the API?

Yes. Starting a scan and collecting its results are the same calls the console makes. A scheduler inside your network can run the whole cycle without touching the internet.

Does Cyprob ship SIEM connectors?

It does not force one on you. Findings and the asset inventory are read over the REST API, and you build the export into your SIEM, ticket queue or warehouse on your own side.


Request a demo See reporting

← Cyprob home