Shadow Warden AI — Gateway v7.1 — Explore the API Reference
Home / Business Community / Integrations

Integrations

14 features

IN-01

Obsidian Plugin v4.19

✅ Shipped

Auto-scan notes on save. Share via SEP UECIID. XAI pipeline visualization. Offline publish queue. Sidebar view.

Community Business+ v4.19
IN-02

Slack Integration

✅ Shipped

Slash command handler with HMAC-SHA256 verification. HIGH/BLOCK + share alerts via webhook.

Pro+ v4.17
IN-03

LangChain Callback

✅ Shipped

Duck-typed WardenCallback for seamless LangChain pipeline integration. Zero config change required.

All v2.0
IN-04

SIEM Integration

✅ Shipped

Splunk HEC + Elastic ECS format. Custom field mappings. SOC 2 Type II evidence ingestion.

Pro+ v3.5
IN-05

GitHub Actions CI

✅ Shipped

Test matrix (3.11/3.12) + lint + Docker smoke + mutation testing. Coverage gate ≥75%.

All v2.0
IN-14

VS Code extension — inline risk annotation on selected text

✅ Shipped

5 commands (Ctrl+Shift+W scan selection, scan file concurrent, scan clipboard, clear, settings). 4 decoration tiers (LOW/MEDIUM/HIGH/BLOCK) with coloured gutter, background tint, and inline after-text verdict. Code Lens above HIGH/BLOCK lines. Concurrent file scan (configurable 1–16 workers). Rich hover: flags + secrets found + request ID. Output channel log. Auto-scan on save. v5.2.0.

Individual+ v5.2
IN-15

GitHub Actions integration — pre-commit hook that scans commit message + diff

📋 Planned

Automatically scan every commit message and diff for secrets, injection patterns, and policy violations before code is merged, using a Shadow Warden GitHub Actions workflow.

Pro+
IN-16

Jira integration — auto-create security tickets on HIGH/BLOCK verdicts

📋 Planned

Automatically create Jira issues for HIGH/BLOCK verdicts with full XAI causal chain and remediation guidance embedded directly in the ticket.

Pro+
IN-17

Microsoft Teams slash command — /warden equivalent for Teams channels

📋 Planned

Bring Shadow Warden into Microsoft Teams with a /warden slash command that scans text, shows verdicts, and lets teams respond to security incidents without leaving the conversation.

Pro+
IN-18

Notion integration — scan Notion pages via API, write risk tags as properties

📋 Planned

Automatically scan Notion pages for secrets, injection patterns, and policy violations, then write risk verdicts back as page properties for easy triage.

Community+
IN-19

STIX/TAXII feed consumer — ingest external threat intel from any TAXII 2.1 server

📋 Planned

Consume threat intelligence from any TAXII 2.1 server, automatically ingesting STIX indicators and observables into Shadow Warden's detection pipeline for enhanced threat correlation.

Enterprise
IN-21

OpenTelemetry SDK library — WardenSpanProcessor for any OTel-enabled app

✅ Shipped

WardenSpanProcessor (sync ThreadPoolExecutor) + WardenAsyncSpanProcessor (asyncio tasks). Extracts span name, string/numeric attributes, event messages — forwarded to /filter. Bounded queue (max 512), shutdown drain, force_flush(), on_finding callback, configurable min_risk + skip_span_names. REST: GET /sdk/status, GET /sdk/stats, POST /sdk/ping. Tier: Pro+.

Pro+ v5.2
IN-22

MISP syslog bridge — route MISP ZMQ feed into Shadow Warden syslog sink

✅ Shipped

Bridge MISP's ZMQ event feed directly into Shadow Warden's syslog sink. ZMQ subscriber (pyzmq, multipart frame support) + HTTP pull fallback. Domain IoCs forwarded as dnsmasq-style syslog lines to UDP 5514 for real-time correlation with passive DNS telemetry. Stats at GET /misp/stats. One-shot sync via POST /misp/sync. Auto-starts in lifespan when MISP_ZMQ_URL or MISP_API_URL+KEY is set.

Pro+ v5.2
IN-25

SMB AI Governance Suite

✅ Shipped

Single-wizard provisioning of all 7 SMB modules. SMBProvisionResult with UECIID + STIX chain ID. get_suite_health() aggregates all module stats. 3 endpoints at /smb-suite/*. Streamlit 6-tab dashboard at page 10.

Community Business+ v4.29