Skip to main content

Integrations — GitHub & CI/CD for EU AI Act Compliance

Connect Scanara to your existing development workflow.

Built-in Compliance Features

Core capabilities included in every Scanara workspace — no separate integration required.

GitHub Merge Gates

Block or annotate pull requests based on live compliance scan results, with configurable enforcement modes and failure thresholds.

Monitoring Plans

Track post-market monitoring for deployed AI systems with review cadences, drift alerts, and on-track / review-due / overdue status.

Automated Risk Classification

Scan source code to classify each AI system against EU AI Act Annex III risk tiers — minimal, limited, high-risk, or prohibited.

Risk Classification via Assessments

Confirm and refine risk classification through structured assessments — AIRA, FRIA, DPIA, GPAI, Deployer, and Prohibited Screening — for evidence code scanning alone can't capture.

Team Organization & Roles

Manage your organization with fine-grained roles — Admin, Compliance Officer, AI Engineer, Auditor, and Viewer — so access matches responsibility.

Compliance Roadmaps

Every scan report includes a phased remediation roadmap — immediate, short-term, medium-term, and long-term actions — with priority, effort, and dependencies.

Risk-Based Document Enforcement

Required compliance documents are enforced by risk tier, so high-risk systems can't skip Annex IV technical documentation or the Declaration of Conformity.

Exports & APIs

Download compliance artifacts, rule bundles, and audit data directly from Scanara.

Compliance Dossier

Export ready-to-submit compliance dossiers in PDF, DOCX, or Markdown. Covers Annex IV, Annex XI, Declaration of Conformity, and FRIA notification.

Scan Result Export

Download scan results in PDF or JSON for integration with your own tooling, audit trail, or regulatory evidence package.

GDPR Data Export

Export a full ZIP archive of your organization's data (CSV + dossier PDFs) for portability, deletion requests, or regulatory audits.

Source Control & CI/CD

Connect your repositories and enforce compliance at the merge gate.

GitHub

Connect your GitHub repositories for automated scanning, merge gate enforcement, and pull request compliance checks.

Identity & Access

Secure your organization with enterprise single sign-on.

Single Sign-On (SSO)

Connect your identity provider. Supports Okta, Microsoft Entra ID, Google Workspace, and Keycloak via OIDC / SAML.

On the roadmap

Integrations planned for upcoming phases — no date commitments.

Article 62 Incident Report

Generate a pre-filled serious incident report PDF ready for submission to your national market surveillance authority.

GitHub Audit Log → S3

Forward GitHub audit logs to your S3 bucket daily. Compatible with any SIEM that reads from S3.

Slack

Receive compliance findings and scan alerts directly in your Slack channels via Block Kit notifications.

Jira

Automatically create Jira tickets from scan findings, with compliance context and remediation links attached.

PagerDuty

Escalate critical compliance findings to on-call rotations via PagerDuty events.

Outgoing Webhooks

Push scan events and compliance state changes to any HTTP endpoint with HMAC-signed payloads.

API Keys

Authenticate programmatic access to Scanara with user-scoped API keys. Available on Business and above.

GitLab

Connect GitLab repositories, enforce compliance at merge request gates, and run Scanara from GitLab CI pipelines.

Bitbucket

Connect Bitbucket repositories and trigger compliance scans from Bitbucket Pipelines.

Azure DevOps

Integrate with Azure Repos and enforce EU AI Act compliance checks in Azure Pipelines pull request builds.

Generic CI/CD Webhook

Trigger Scanara scans from any CI system by posting to a signed webhook endpoint — works with Jenkins, CircleCI, and others.

SCIM Provisioning

Automate user provisioning and deprovisioning from your identity provider using the SCIM 2.0 protocol.