Integrations

A finding only counts once it reaches the person who can fix it. Topscan pushes findings into the chat your team already has open and starts scans from the pipeline you already run — with the affected host, the severity and the fix attached.

14 days of the full Advanced plan · no card required · first results in 5–10 minutes

  • Slack
  • Email
  • GitHub
  • GitLab
  • AWS
  • CI/CD webhook

what connects today — nothing on this page is a plan

Topscan: the integrations marketplace

Security Challenges
Every Team Faces

What happens in practice

  • Findings sit in a scanner dashboard that nobody opens between audits

  • A critical result waits for the next status meeting to reach an engineer

  • Security checks depend on someone remembering to run them

  • The repository and the scanner live in different worlds

  • Audit prep turns into re-assembling a history nobody recorded

How Topscan handles it

  • New findings arrive in your Slack channel the moment a scan finds them

  • Scans start from your own pipeline, so checks run on deploys

  • GitHub and GitLab connect directly for code scanning

  • An AWS account feeds discovery without anyone maintaining a list

  • The record of what was found and what was fixed stays readable for auditors

How Integrations Works

  1. Step 1

    Connect what your team already uses

    Slack for the interruption, email for everyone who isn't in that channel, GitHub or GitLab for the code, AWS for the cloud footprint. One setup each, from Settings → Integrations.

    • Slack
    • Email
    • GitHub & GitLab
    • AWS
    Topscan: the integrations marketplace
  2. Step 2

    Start scans from your pipeline

    Your CI/CD pipeline calls a webhook and the scan starts — so the check runs on deploys instead of when somebody remembers. It's one line in the workflow you already have and there's no agent to install.

    Any CI system
    # the URL is the credential — keep it in a masked secret
    curl -fsS -X POST "$TOPSCAN_WEBHOOK"

    Your webhook looks like https://hooks.topscan.me/scans/notify/<your-scan-id>. Ready-made steps for GitHub Actions and GitLab CI are on the CI/CD Security Scanning page.

    • One line in the pipeline
    • No agent
    • Runs on every deploy
    Topscan: the event link that starts a scan from a pipeline
  3. Step 3

    Get the finding, not a link to it

    Every message carries what an engineer needs to act without opening another tool: the affected host and URL, what answered, the severity, the recommended fix and the remediation deadline.

    • Affected host & URL
    • Severity
    • Recommended fix
    • Deadline
    Topscan: an expired-certificate alert delivered by email
  4. Step 4

    Keep the record where auditors can read it

    Remediation status and deadlines travel with the finding, and the history stays readable — a reviewer gets a free read-only seat rather than a folder of screenshots.

    • Remediation status
    • SLA tracking
    • Free auditor seats
    Topscan: dated history of findings
Features

Features & Capabilities
in one workflow

  • Chat alerts on new findings

    A new result reaches the team channel when the scan finds it, not at the next status meeting. Slack connects with one OAuth click.

  • Scans triggered from your pipeline

    The check runs as a step in your deployment workflow, so every deploy gets tested from the outside. Details on the CI/CD Security Scanning page.

  • Findings become tracker tasks

    A finding turns into a Jira task without retyping it: project, issue type and assignee are yours to pick, the summary and the description come filled in with the severity, the affected targets and what the exposure means.

  • Repositories connected directly

    GitHub and GitLab, including self-managed GitLab, connect with a read-only access token for code scanning.

  • Cloud that feeds itself

    A connected AWS account keeps discovery current without anyone maintaining a list of hosts.

Who Topscan Is Built For

  • Head of DevOps

    Put findings in the channel your team already reads, instead of adding one more place to check.

  • Senior DevOps / Platform Engineer

    Wire scans into the pipeline so the check runs on every deploy.

  • CTO

    Know that a finding reaches an owner without a weekly meeting to move it there.

  • Teams preparing for an audit

    Keep a readable record of what was found, when, and what was fixed. Your auditor should confirm applicability.

Connect Topscan to the tools you already use

Everything on this list works today. We would rather show a short list than a long one with asterisks.

  • GitHub
  • GitLab
  • Slack
  • Jira
  • Email
  • AWS
  • CI/CD webhook

Fair pricing for your workflow

Email alerts are on every plan and the CI/CD trigger on every paid plan, including Basic. Slack routing and Jira tickets start on Advanced at $269 a month.

  • Basic

    $129/ month

    For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.


    • 3 infrastructure hosts — an IP, a hostname or a subdomain
    • 1 web application tested while it’s running
    • 10 repositories scanned by SAST
  • Advanced

    14 days free trialBest value

    $269/ month

    For companies of 20–60 with AWS infrastructure and active CI/CD.


    • 8 infrastructure hosts, 2 web applications, 20 repositories
    • AWS integration — cloud assets discovered automatically
    • Slack routing and Jira tickets for findings
  • Pro

    $449/ month

    For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.


    • 15 infrastructure hosts, 4 web applications, 40 repositories
    • Custom SLA by severity and per target, Severity Override with an audit trail
    • Two-way CI/CD webhook and Attack Surface change tracking with alerts

You pay for what you monitor — not for seats, scans or findings

Discovery costs nothing: it maps your whole footprint and a licence is used only when you put a host under monitoring. Scans are never billed, so a weekly schedule costs the same as a monthly one, and the whole team reads findings on any paid plan — developers, whoever tracks remediation, and read-only seats for auditors.

In every paid plan

  • External infrastructure scanning
  • Static code analysis, all supported languages
  • Remediation history with dates
  • Role-based access control
  • Attack Surface and Security Score
  • Dependency scanning (SCA)
  • CI/CD webhook to trigger a scan
  • Unlimited scans and users
  • Web application scanning
  • Statuses, SLA and snooze on every finding
  • Email alerts
  • Free read-only seats for auditors
Need more than your plan includes? Extra licences are $4 per infrastructure host, $45 per web application and $9 per repository — the same rate on every paid plan, with no volume pricing to negotiate. The 14-day trial gives you the full Advanced plan and needs no card.

Walk through it before you sign up

Five clicks through the real product. No form, no demo call.

Topscan: the integrations marketplace

Step 1 · Open Integrations

One marketplace, Enabled and Available.

Step 1 of 5 — click the highlighted spot

FAQ

Topscan builds on the best in class scanning engines

Still have questions?

Contact us
Add a domain while you sign up and discovery answers within five to ten minutes — that is your first map of what faces the internet, before anything is scanned. Scanning comes after you confirm what to monitor: a fast check finishes in five to fifteen minutes, a full infrastructure audit in thirty to ninety, and a deep web application scan can run up to a few hours. Those are typical times, not guarantees — the real duration depends on the target: how many hosts answer, how large the application is and how quickly it responds.
Slack, Jira, email, GitHub and GitLab (including self-managed), AWS, and an inbound webhook that lets your pipeline start a scan.
Not yet. The webhook we have today is inbound only: your pipeline calls Topscan to start a scan, and results come back through Slack, email and the app. An outbound integration API is something we're building, but we won't put it on this page until it exists.
Yes. One call from your workflow starts the scan. That part has its own page: CI/CD Security Scanning.
Email alerts and the CI/CD trigger are on every plan. Slack routing and Jira tickets start on Advanced at $269 a month, which is also where AWS integration begins.
No, and that's deliberate: Topscan is the source of truth for vulnerabilities. Where Jira is connected, Topscan reads the task status and shows it next to the finding, and can close the Jira task when you resolve the finding — but a closed ticket never silently closes a finding.
Customer data is stored in the Hetzner cloud in Ashburn, Virginia, US. None of the developers have access to the production environment — only the Head of DevOps does, and every action he takes is logged. No customer data leaves our infrastructure or is passed to third-party systems, including third-party AI services: everything happens inside a closed environment. We are currently going through a SOC 2 audit and track our processes in Drata. If you delete your account, all data is permanently removed from our servers within 180 days.

Put findings where the work already happens

Connect one tool and add one domain. The first scan takes about five minutes.

14 days of the full Advanced plan · no card required