Interoperability

Our products, or yours. No lock-in.

We ship a complete, integrated security line of our own, but we never lock you in. Every product is built on open standards and works alongside the tools you already run, from any vendor. When an integration needs customer-specific work, we handle it as a tailored project.

How we stay open

Open by standard

Ingest over standard syslog and open agents (NXLog, Filebeat, Fluentd), normalized by the open-source Vector Remap Language (VRL). Export over CSV/JSON and REST API tokens. Standards-based sources are straightforward to connect; unusual formats can be mapped during onboarding.

Your AI, not just ours

SDefender can connect to commercial or self-hosted large language models through its own MCP (Model Context Protocol) server. Identifiers such as IP addresses, hostnames and usernames are obfuscated before leaving your perimeter and restored only inside your environment.

Not locked to one stack

SDefender works across heterogeneous estates and is not tied to a single vendor’s ecosystem. On-prem and cloud, your data stays in your environment. ISO 27001 & 27701 certified and GDPR-aligned.

Built to your stack, as a tailored project

Don’t see the integration you need? Tell us. Actions exposed over a remote connection or API can usually be automated, and we handle customer-specific connectors as tailored projects.

Platforms we already speak

Firewalls and cloud are auto-detected natively; SIEM, EDR and Service Desk platforms connect both ways over the standards they already speak — syslog, CEF/LEEF, Splunk HEC, REST APIs and webhooks. The names here are examples, not limits — don’t see yours? We’ll handle it as a tailored project.

Firewalls & cloud

FortiGate Palo Alto PAN-OS Cisco ASA Cisco IOS / IOS-XE Check Point Juniper SRX Sophos Firewall SonicWall WatchGuard MikroTik RouterOS pfSense OPNsense AWS Security Groups Azure NSG GCP VPC Firewall

SIEM & log platforms

Splunk Microsoft Sentinel IBM QRadar Elastic Security Wazuh Graylog LogRhythm Sumo Logic Rapid7 InsightIDR ArcSight FortiSIEM Google Security Operations

EDR & endpoint

CrowdStrike Falcon Microsoft Defender for Endpoint SentinelOne Cynet Palo Alto Cortex XDR Sophos Intercept X Trend Micro Vision One Trellix Bitdefender GravityZone

Service Desk & ITSM

ServiceNow Jira Jira Service Management Freshservice ManageEngine ServiceDesk Plus Zendesk SDefender Desk

All product names and logos are trademarks of their respective owners and are shown for identification only; no affiliation, endorsement or partnership is implied. Trademark notice →

Connect your existing stack

If a tool you rely on is not named here, it almost certainly still fits. And if it does not, we will add it.

SIEM & log sources

Ingest from SIEMs and log sources over syslog or open agents (NXLog, Filebeat, Fluentd), and forward SDefender's own detections back into your SIEM: Splunk via HEC, QRadar via LEEF, Microsoft Sentinel, Elastic and more over syslog or CEF. VRL normalizes many standard and customer-specific formats without requiring a proprietary agent.

Firewalls & cloud

15 firewall and cloud-firewall platforms auto-detected: FortiGate, Palo Alto, Cisco, Check Point and more, plus AWS, Azure and GCP.

Learn more →

Service Desk & ITSM

Raise incidents into your existing ticketing system — such as Freshservice, Jira, Jira Service Management, ServiceDesk Plus, ServiceNow and Zendesk — or, once released, into SDefender’s own shared Service Desk (will be available soon).

AI models

Commercial or self-hosted large language models through SDefender’s MCP server, with perimeter-side data obfuscation.

Alerts & notifications

Operational alerts over email, Microsoft Teams and Telegram, alongside the in-console timeline.

Automation & export

REST API tokens, CSV/JSON export, RBAC and a full audit log. Actions exposed over a remote connection or API can usually be automated.

Tell us what you run

Bring your firewalls, your SIEM, your ticketing and your AI. We’ll show you how SDefender fits alongside them, and build whatever is missing.