Integrations — GitHub & CI/CD for EU AI Act Compliance
Connect Scanara to your existing development workflow.
Built-in Compliance Features
Core capabilities included in every Scanara workspace — no separate integration required.
GitHub Merge Gates
Block or annotate pull requests based on live compliance scan results, with configurable enforcement modes and failure thresholds.
Monitoring Plans
Track post-market monitoring for deployed AI systems with review cadences, drift alerts, and on-track / review-due / overdue status.
Automated Risk Classification
Scan source code to classify each AI system against EU AI Act Annex III risk tiers — minimal, limited, high-risk, or prohibited.
Risk Classification via Assessments
Confirm and refine risk classification through structured assessments — AIRA, FRIA, DPIA, GPAI, Deployer, and Prohibited Screening — for evidence code scanning alone can't capture.
Team Organization & Roles
Manage your organization with fine-grained roles — Admin, Compliance Officer, AI Engineer, Auditor, and Viewer — so access matches responsibility.
Compliance Roadmaps
Every scan report includes a phased remediation roadmap — immediate, short-term, medium-term, and long-term actions — with priority, effort, and dependencies.
Risk-Based Document Enforcement
Required compliance documents are enforced by risk tier, so high-risk systems can't skip Annex IV technical documentation or the Declaration of Conformity.
Exports & APIs
Download compliance artifacts, rule bundles, and audit data directly from Scanara.
Compliance Dossier
Export ready-to-submit compliance dossiers in PDF, DOCX, or Markdown. Covers Annex IV, Annex XI, Declaration of Conformity, and FRIA notification.
Scan Result Export
Download scan results in PDF or JSON for integration with your own tooling, audit trail, or regulatory evidence package.
GDPR Data Export
Export a full ZIP archive of your organization's data (CSV + dossier PDFs) for portability, deletion requests, or regulatory audits.
Source Control & CI/CD
Connect your repositories and enforce compliance at the merge gate.
GitHub
Connect your GitHub repositories for automated scanning, merge gate enforcement, and pull request compliance checks.
Identity & Access
Secure your organization with enterprise single sign-on.
Single Sign-On (SSO)
Connect your identity provider. Supports Okta, Microsoft Entra ID, Google Workspace, and Keycloak via OIDC / SAML.
On the roadmap
Integrations planned for upcoming phases — no date commitments.
Article 62 Incident Report
Generate a pre-filled serious incident report PDF ready for submission to your national market surveillance authority.
GitHub Audit Log → S3
Forward GitHub audit logs to your S3 bucket daily. Compatible with any SIEM that reads from S3.
Slack
Receive compliance findings and scan alerts directly in your Slack channels via Block Kit notifications.
Jira
Automatically create Jira tickets from scan findings, with compliance context and remediation links attached.
PagerDuty
Escalate critical compliance findings to on-call rotations via PagerDuty events.
Outgoing Webhooks
Push scan events and compliance state changes to any HTTP endpoint with HMAC-signed payloads.
API Keys
Authenticate programmatic access to Scanara with user-scoped API keys. Available on Business and above.
GitLab
Connect GitLab repositories, enforce compliance at merge request gates, and run Scanara from GitLab CI pipelines.
Bitbucket
Connect Bitbucket repositories and trigger compliance scans from Bitbucket Pipelines.
Azure DevOps
Integrate with Azure Repos and enforce EU AI Act compliance checks in Azure Pipelines pull request builds.
Generic CI/CD Webhook
Trigger Scanara scans from any CI system by posting to a signed webhook endpoint — works with Jenkins, CircleCI, and others.
SCIM Provisioning
Automate user provisioning and deprovisioning from your identity provider using the SCIM 2.0 protocol.