Where your team already works.

Each finding reaches the team that owns it, once, not once per scan.

SlackAvailable
Alerts in a channel through the Cordon app, or an incoming webhook
Microsoft TeamsAvailable
Alerts as cards in a channel
@cordon in chatAvailable
Ask questions from Slack and Teams, answered privately as you
PagerDutyAvailable
One incident per finding, resolved when the fix is proved
OpsgenieAvailable
One alert per finding, closed when the fix is proved
JiraAvailable
One issue per finding, moved to Done when a scan proves the fix
GitHub IssuesAvailable
One issue per finding, closed as completed when fixed
GitLab IssuesAvailable
One issue per finding, closed when fixed
LinearAvailable
One issue per finding, moved to a completed state when fixed
ClickUpAvailable
One task per finding, moved to the list's closed status when fixed
Azure DevOps BoardsAvailable
One work item per finding, completed when fixed
AsanaAvailable
One task per finding, marked complete when fixed
Pull requestsAvailable
A check and one comment per pull request on GitHub and GitLab, and a dependency review of what the update adds
SplunkAvailable
Every routed event through the HTTP Event Collector
Microsoft SentinelAvailable
Every routed event into a custom table (Logs Ingestion API)
Signed webhooksAvailable
Every event, HMAC-signed, for your own systems
EmailAvailable
A weekly digest for each person who wants one
Audit exportAvailable
The full trail as CSV, for your SIEM or auditor
Routes

Every event, to the right place.

Match by event, severity, category, repository or team. A failed delivery is retried, then kept where you can see and resend it.

Delivered as it happens

Every event reaches its owner.

A failed delivery is retried and stays visible until it lands. Every webhook is signed.

14:02:11 finding.created payments-api MALWARE.DEPENDENCY.KNOWN.001
to PagerDuty security-oncall delivered 212 ms
to Slack #payments-dev delivered 188 ms
to Jira PAY ticket PAY-412 created
14:05:40 scan.completed ledger gate failed (block mode)
to GitHub check run Cordon failure merge refused
14:06:02 intel.match [email protected] 3 repositories
to Slack #sec-alerts delivered
to Webhook hooks.acme.internal 503, retry in 1 minute
14:07:03 Webhook retried delivered signed, HMAC
14:09:15 firewall.blocked npm left-pad (blocked by your organisation)
to Slack #platform delivered
12 signed events

Build on every change.

scan.completedfinding.createdfinding.updatedfinding.fixedfinding.reopenedintel.matchfirewall.blockedcoverage.gapsuppression.requestedsuppression.approvedpolicy.changedevidence.sealed
Ask @cordon

Questions, answered from your records.

In the console, Slack and Teams. Each person connects their own account once; @cordon answers with their permissions, about their organisation only, privately, cites every record, and never changes anything.

Connect your first destination.