# Cantina Documentation ## Docs - [Apex overview](https://docs.cantina.security/apex.md): Guides and references for connecting code, scoping Apex scans, and running the CLI from developer workflows. - [Apex service API](https://docs.cantina.security/apex/api.md): Run Apex from serverless functions, cron jobs, and internal audit hubs with an organization-scoped service key and a REST/JSON workflow. - [Apex CLI guide](https://docs.cantina.security/apex/cli.md): Install Apex CLI, wire it into Claude Code, Codex CLI, or GitHub Copilot CLI, and run scans from the terminal or an agent. - [Client onboarding guide](https://docs.cantina.security/apex/onboarding.md): How repository access works, what Apex needs during setup, and what to send before the first scan. - [Apex scan manual](https://docs.cantina.security/apex/scan-manual.md): A practical guide to scoping scans, timing them well, and giving Apex enough context to return useful findings. - [Scheduled scans](https://docs.cantina.security/apex/scheduled-scans.md): Run recurring workspace scans or fix reviews on a fixed cadence so monitoring keeps up with the code without manual effort. - [Client API Reference](https://docs.cantina.security/api.md): REST endpoints available to client organizations - [MCP access](https://docs.cantina.security/api/mcp-access.md): Connect external MCP clients (Claude Code, Cursor, CI scripts) to your Clarion workspace. - [Welcome to Clarion](https://docs.cantina.security/clarion.md): One brain to orchestrate your entire security stack. - [Getting started](https://docs.cantina.security/clarion/getting-started.md): Set up your Clarion workspace, create your first agent, and start triaging alerts. - [1Password](https://docs.cantina.security/clarion/integrations/1password.md): Connect 1Password to Clarion to monitor audit events, sign-in attempts, and item usage events from your 1Password Business account. - [Apex](https://docs.cantina.security/clarion/integrations/apex.md): Connect Apex to Clarion to ingest security findings from your repositories and code scanning workflows. - [AWS](https://docs.cantina.security/clarion/integrations/aws.md): Connect your AWS account to Clarion for CloudTrail events, CloudWatch alarms, GuardDuty findings, and IAM agent tools. - [Cloudflare](https://docs.cantina.security/clarion/integrations/cloudflare.md): Connect Cloudflare to Clarion for Notifications webhooks, Logpush detection monitors, and optional API-powered DNS and analytics agent tools. - [CrowdStrike Falcon](https://docs.cantina.security/clarion/integrations/crowdstrike.md): Connect CrowdStrike Falcon to Clarion to poll detections and cases from your Falcon tenant and surface them as alerts. - [Custom MCP](https://docs.cantina.security/clarion/integrations/custom-mcp.md): Connect any MCP-compatible HTTP server to extend Clarion agents with your own tools. - [Generic Webhook](https://docs.cantina.security/clarion/integrations/generic-webhook.md): Send events from any service to Clarion via HTTP webhook for AI-powered triage and response. - [Google Cloud](https://docs.cantina.security/clarion/integrations/google-cloud.md): Connect Google Cloud monitors and runtime credentials for agent triage. - [Grafana](https://docs.cantina.security/clarion/integrations/grafana.md): Connect Grafana to Clarion to receive alerting notifications for AI-powered triage and response. - [Guardrail](https://docs.cantina.security/clarion/integrations/guardrail.md): Connect Guardrail to Clarion to receive Guard alerts for AI-powered triage and response. - [Hexagate](https://docs.cantina.security/clarion/integrations/hexagate.md): Connect Hexagate to Clarion to receive on-chain monitor alerts for AI-powered triage and response. - [Huntress](https://docs.cantina.security/clarion/integrations/huntress.md): Connect Huntress to Clarion for endpoint detection and response (EDR) data enrichment during alert triage. - [Hypernative](https://docs.cantina.security/clarion/integrations/hypernative.md): Connect Hypernative to Clarion for on-chain threat monitoring and AI-powered alert triage. - [Iru](https://docs.cantina.security/clarion/integrations/iru.md): Connect Iru to Clarion so agents can look up devices, users, applications, and vulnerabilities from your Iru tenant during alert triage. - [Jira](https://docs.cantina.security/clarion/integrations/jira.md): Connect Jira Cloud to Clarion with an Atlassian service account so agents can create, look up, and search issues during triage. - [JumpCloud](https://docs.cantina.security/clarion/integrations/jumpcloud.md): Connect JumpCloud to Clarion to ingest directory and identity events via Insights Rule webhooks and enable agent-driven investigation. - [Linear](https://docs.cantina.security/clarion/integrations/linear.md): Connect Linear to Clarion so agents can create issues authored by the Clarion app, not by a person on your team. - [Microsoft Entra ID](https://docs.cantina.security/clarion/integrations/microsoft-entra-id.md): Connect Microsoft Entra ID (Azure AD) to Clarion to enforce enterprise single sign-on for your organization. - [Microsoft Sentinel](https://docs.cantina.security/clarion/integrations/microsoft-sentinel.md): Connect Microsoft Sentinel to Clarion to poll incidents as alerts and give triage agents Sentinel and Defender investigation tools. - [Microsoft Teams](https://docs.cantina.security/clarion/integrations/microsoft-teams.md): Connect Microsoft Teams to Clarion so agents can post alerts to channels and chats and request approvals via Adaptive Cards during incidents. - [Okta](https://docs.cantina.security/clarion/integrations/okta.md): Install the Clarion Okta app from the Okta Integration Network to connect your Okta org to Clarion for identity and access threat detection. - [PagerDuty](https://docs.cantina.security/clarion/integrations/pagerduty.md): Connect PagerDuty to Clarion so agents can page your on-call rotation through PagerDuty's Events API v2 during triage. - [SentinelOne](https://docs.cantina.security/clarion/integrations/sentinelone.md): Forward Singularity Endpoint threat detections from SentinelOne into Clarion as alerts. - [Slack](https://docs.cantina.security/clarion/integrations/slack.md): Install the Clarion app for Slack and learn what Clarion does, how it works inside Slack, and how your data is handled. - [Splunk](https://docs.cantina.security/clarion/integrations/splunk.md): Connect Splunk to Clarion so agents can forward an alert's details and original payload to your Splunk HTTP Event Collector (HEC) during triage. - [Tailscale](https://docs.cantina.security/clarion/integrations/tailscale.md): Connect Tailscale to Clarion to receive network and identity events such as device approvals, key expiry, policy changes, and user lifecycle as alerts. - [Tenderly](https://docs.cantina.security/clarion/integrations/tenderly.md): Connect Tenderly to Clarion to receive smart contract monitoring alerts for AI-powered triage and response. - [Threat Intel](https://docs.cantina.security/clarion/integrations/threat-intel.md): Bring vulnerability advisories, supply chain threats, and security feeds into Clarion for AI-powered triage and response. - [Introduction](https://docs.cantina.security/clarion/knowledge-base.md): A collection of answers to frequently asked questions. - [Getting started](https://docs.cantina.security/clarion/knowledge-base/getting-started.md): Set up your Clarion workspace, create your first agent, and start triaging alerts. - [Introduction](https://docs.cantina.security/clarion/learn.md): An overview of how Clarion's core concepts fit together, from incoming events to incidents to response. - [Agents](https://docs.cantina.security/clarion/learn/agents.md): Learn how agents triage alerts, investigate incidents, and execute response actions in your security stack. - [Alerts](https://docs.cantina.security/clarion/learn/alerts.md): Learn how alerts are created, deduplicated, and triaged across all your connected integrations. - [Issues](https://docs.cantina.security/clarion/learn/issues.md): Learn how to manage issues, the consolidated security events that track response from discovery to closure. - [Notifications](https://docs.cantina.security/clarion/learn/notifications.md): Stay in the loop and respond when an agent needs your input across Slack, Teams, SMS, email, and more. - [Settings](https://docs.cantina.security/clarion/learn/settings.md): Configure your workspace, manage members and access, and customize how your team works in Clarion. - [Skills](https://docs.cantina.security/clarion/learn/skills.md): Reusable playbooks that teach agents how to handle specific classes of tasks to a known standard. - [Tasks](https://docs.cantina.security/clarion/learn/tasks.md): Track follow-up work, agent improvements, and operational actions across your team. - [Tools](https://docs.cantina.security/clarion/learn/tools.md): The integrations agents use to take action: send messages, change DNS, file tickets, and more. - [How Cantina works: the loop](https://docs.cantina.security/how-it-works.md): How Cantina runs security work as a single loop: find, prioritize, remediate, and prove every issue closed with evidence. - [Welcome to Cantina](https://docs.cantina.security/introduction.md): Cantina is an agentic security platform that finds the issues that matter, prioritizes them against real exposure, remediates them, and proves the loop is closed. - [Platform overview](https://docs.cantina.security/platform/overview.md): One agentic security platform with two products, Apex and Clarion, and a network of human expertise, all running the same loop. - [Products at a glance](https://docs.cantina.security/platform/products.md): Apex for code security and Clarion for security operations, two products sharing one platform, one loop, and one record. - [The security loop](https://docs.cantina.security/platform/the-loop.md): The core model behind Cantina: how a security issue moves from first signal to verified closure across find, prioritize, remediate, and prove. - [Trust, auditability, and human control](https://docs.cantina.security/platform/trust.md): How Cantina keeps autonomous security work under the team's control and on the record with human approval, verified closure, and full audit trails. - [Referral Program](https://docs.cantina.security/referrals.md): Earn rewards for growing the Cantina ecosystem - [Competitions](https://docs.cantina.security/researchers/competitions.md): Finding labels, statuses, payments, and teams in Cantina security competitions. - [Joining Cantina](https://docs.cantina.security/researchers/joining.md): Get started as a security researcher on Cantina - [KYC and Payments](https://docs.cantina.security/researchers/joining/kyc.md): Set up your payment information to receive rewards - [Payout Schedule & Process](https://docs.cantina.security/researchers/joining/payout-schedule.md): Understand when and how you'll receive your earnings from competitions, security reviews, and bug bounty programs. - [Participation Guides](https://docs.cantina.security/researchers/participation.md): Essential guidelines for participating in Cantina engagements - [Bug Bounty](https://docs.cantina.security/researchers/participation/bounties.md): Overview of Cantina bug bounty programs - getting started, statuses, payouts, deposits, and mediation - [Bug Bounty Participation](https://docs.cantina.security/researchers/participation/bug-bounty.md): Guidelines for participating in Cantina bug bounty programs - [Bug Bounty Payout](https://docs.cantina.security/researchers/participation/bug-bounty-payouts.md): Prerequisites and schedule for receiving bug bounty payouts on Cantina - [Bug Bounty Finding Statuses](https://docs.cantina.security/researchers/participation/bug-bounty-statuses.md): Understanding finding statuses for bug bounty programs - from submission to resolution - [Competition Participation](https://docs.cantina.security/researchers/participation/competitions.md): Rules and guidelines for participating in Cantina competitions - [Deposits for Bounty Submissions](https://docs.cantina.security/researchers/participation/deposits.md): Learn about deposit requirements for bounty submissions on Cantina - [Finding Submission Examples](https://docs.cantina.security/researchers/participation/examples.md): Real examples of good and bad security findings including Proof of Concept (PoC) code for smart contract audits. - [Fellowship Program](https://docs.cantina.security/researchers/participation/fellowship-program.md): Cantina's tiered reward program for top security researchers - [Security Review Process](https://docs.cantina.security/researchers/participation/security-review-process.md): Guide for researchers conducting security reviews on Cantina - [Submission Guidelines](https://docs.cantina.security/researchers/participation/submission-guidelines.md): Best practices for submitting high-quality findings, including PoC requirements, validity criteria, and competition submission rules. - [Researcher Resources](https://docs.cantina.security/researchers/resources.md): Resources for growing your career on Cantina - [Cantina Tools](https://docs.cantina.security/researchers/tools.md): Tools available to security researchers on Cantina - [Cantina Code Usage](https://docs.cantina.security/researchers/tools/cantina-code.md): How to use Cantina Code for security research - [Communication Features](https://docs.cantina.security/researchers/tools/features.md): Communication tools for security researchers on Cantina Code - [FAQ](https://docs.cantina.security/resources/faq.md): Frequently asked questions about Cantina security audits, competitions, bounties, and researcher programs. - [Clarion Privacy & Legal Disclosures](https://docs.cantina.security/resources/legal.md): Clarion-specific privacy and legal disclosures. - [Links](https://docs.cantina.security/resources/links.md): Official Cantina and Spearbit resources - [Public Reports](https://docs.cantina.security/resources/public-reports.md): Browse published security reports from Cantina and Spearbit audits and competitions. - [Support](https://docs.cantina.security/resources/support.md): How to reach the Clarion team when you run into a problem or need help. - [Cantina Code for Companies](https://docs.cantina.security/security-teams/cantina-code.md): See findings submitted in real time and collaborate with security researchers through Cantina Code. - [Managing Findings](https://docs.cantina.security/security-teams/cantina-code/managing-findings.md): Efficiently manage and prioritize security findings - [Working with Reports](https://docs.cantina.security/security-teams/cantina-code/working-with-reports.md): Understand and act on security reports - [Building agents on the platform](https://docs.cantina.security/security-teams/community/building-agents.md): Build your own security agents and skills on top of the platform, within guardrails your team controls. - [Community guidelines](https://docs.cantina.security/security-teams/community/guidelines.md): Contribution standards that keep shared agents and skills safe, clear, and useful for everyone. - [Sharing and reusing](https://docs.cantina.security/security-teams/community/sharing.md): Publish agents and skills, and draw on what the community has already shared. - [Getting Started with Cantina](https://docs.cantina.security/security-teams/getting-started.md): Your guide to setting up and using Cantina as an organization - [API Access](https://docs.cantina.security/security-teams/getting-started/api-access.md): Programmatic access to Cantina for client organizations - [SSO Configuration](https://docs.cantina.security/security-teams/getting-started/sso.md): Learn how to configure SSO enforcement for your Cantina organization - [Security solutions](https://docs.cantina.security/security-teams/services.md): Human-delivered security services powered by the Spearbit network, each plugging into the same find, prioritize, remediate, and prove-closure loop. - [Advisory](https://docs.cantina.security/security-teams/services/advisory.md): Strategic security advisory and executive-level guidance - [Application Security Audits](https://docs.cantina.security/security-teams/services/application-security-audits.md): Comprehensive application infrastructure and application security assessments - [Bug Bounty](https://docs.cantina.security/security-teams/services/bug-bounty.md): Managed bug bounty programs for ongoing vulnerability discovery - [Competitions](https://docs.cantina.security/security-teams/services/competitions.md): Collaborative security audit competitions with expert validation - [How Cantina Audits Work](https://docs.cantina.security/security-teams/services/how-audits-work.md): Structured, expert-led reviews of your codebase conducted by vetted security researchers - [Managed Detection and Response](https://docs.cantina.security/security-teams/services/managed-detection-and-response.md): 24/7 incident response and security monitoring - [Multisig Security](https://docs.cantina.security/security-teams/services/multisig-security.md): Multi-signature wallet protection and key management solutions - [Penetration Testing](https://docs.cantina.security/security-teams/services/penetration-testing.md): Comprehensive penetration testing for on-chain and off-chain infrastructure - [Smart Contract Security Audits](https://docs.cantina.security/security-teams/services/smart-contract-audits.md): Comprehensive security audits by Spearbit and Cantina - [Evaluations and Standards](https://docs.cantina.security/standards.md): How we ensure fairness, clarity, and consistency - [Judging Processes](https://docs.cantina.security/standards/judging.md): How findings are evaluated, escalated, and scored - [Severity Classifications](https://docs.cantina.security/standards/severity.md): Standardized framework for vulnerability classification - [Bug Bounty Severity Classification](https://docs.cantina.security/standards/severity/bug-bounty.md): Cantina's bug bounty severity classification for smart contract vulnerabilities. Learn what's in scope vs out of scope for vulnerability rewards. - [Competition Finding Severity Criteria](https://docs.cantina.security/standards/severity/competition.md): Competition finding severity criteria including the mandatory PoC rule. Learn when Proof of Concept is required for high and medium severity submissions. - [Finding Labels and Status](https://docs.cantina.security/standards/severity/finding-categorization.md): Understanding finding statuses and labels - [Vision and approach](https://docs.cantina.security/vision-and-approach.md): Cantina's approach to security: machine intelligence paired with world-class human expertise, with the human always in the driver's seat. ## OpenAPI Specs - [openapi](https://docs.cantina.security/api-reference/openapi.yaml) - [openapi-client](https://docs.cantina.security/api-reference/openapi-client.yaml)