Skip to main content

The next chapter of Cantina

Your surfaces

Point it at what you run

Choose the surfaces you own. Cantina handles discovery, triage, and remediation across every one of them.

Signals in

AWS · CrowdStrike · GitHub

Cantina agent layer

Correlates context, chooses the approved response, and records the outcome.

Actions out

Slack · Jira · Datadog

Connection model

One connection.
Three possible roles

An integration can supply a signal, add context, carry out an action, or do all three.

  1. 01

    Signals in

    Sources that raise alerts, like CrowdStrike detections, GuardDuty findings, or Dependabot alerts.

  2. 02

    Context

    What agents read to make sense of an alert: asset ownership, runbooks, logs, and history.

  3. 03

    Actions out

    Where agents act next, like containing an endpoint in CrowdStrike, merging a GitHub PR, or paging on-call in PagerDuty.

Native + open

Where teams plug in

A sample across the stack, not the full catalog. Anything missing can connect through a webhook or MCP.

  • 01

    Cloud & infra

    • AWS
    • Google Cloud
    • Vercel
    • Cloudflare
  • 02

    Identity

    • Okta
    • Entra ID
    • 1Password
    • JumpCloud
  • 03

    Endpoint & XDR

    • CrowdStrike
    • SentinelOne
    • Defender
    • Huntress
  • 04

    Code & AppSec

    • GitHub
    • Dependabot
    • Apex
    • Cantina
  • 05

    Observability

    • Datadog
    • Grafana
    • Splunk
    • Better Stack
  • 06

    Knowledge & tickets

    • Notion
    • Confluence
    • Jira
    • Slack
Beyond native

You're never limited to the catalog

Three open paths mean almost anything can feed Clarion, act through it, or drive it as code.

  1. 01

    Generic webhook

    Any JSON POST becomes a triaged alert, including tools that have no connector.

  2. 02

    Custom MCP

    Connect an MCP server and agents can call your own tools during investigation and response.

  3. 03

    MCP access

    Drive the whole workspace as code, from any external MCP client.

Every connection uses encrypted credentials and scoped, revocable, audited access, and you connect only the servers you trust. Trust, governance & safety →

Shape the roadmap

Don't see the tool your team depends on?

Our roadmap follows what customers actually run. Tell us what's in your stack and we'll build for it.

Request an integration