# Cantina Documentation - [Welcome to Cantina](https://docs.cantina.security/introduction.md): Cantina is an agentic security platform that finds the issues that matter, prioritizes them against real exposure, remediates them, and proves the loop is closed. - [How Cantina works: the loop](https://docs.cantina.security/how-it-works.md): How Cantina runs security work as a single loop: find, prioritize, remediate, and prove every issue closed with evidence. - [Vision and approach](https://docs.cantina.security/vision-and-approach.md): Cantina's approach to security: machine intelligence paired with world-class human expertise, with the human always in the driver's seat. - [Platform overview](https://docs.cantina.security/platform/overview.md): One agentic security platform with two products, Apex and Clarion, and a network of human expertise, all running the same loop. - [The security loop](https://docs.cantina.security/platform/the-loop.md): The core model behind Cantina: how a security issue moves from first signal to verified closure across find, prioritize, remediate, and prove. - [Products at a glance](https://docs.cantina.security/platform/products.md): Apex for code security and Clarion for security operations, two products sharing one platform, one loop, and one record. - [Trust, auditability, and human control](https://docs.cantina.security/platform/trust.md): How Cantina keeps autonomous security work under the team's control and on the record with human approval, verified closure, and full audit trails. - [Apex application security documentation](https://docs.cantina.security/apex.md): Set up Apex to scan repositories and pull requests for exploitable vulnerabilities, verify findings, and run scans through the app, CLI, or API. - [Client onboarding guide](https://docs.cantina.security/apex/onboarding.md): How repository access works, what Apex needs during setup, and what to send before the first scan. - [Apex scan manual](https://docs.cantina.security/apex/scan-manual.md): A practical guide to scoping scans, timing them well, and giving Apex enough context to return useful findings. - [Scheduled scans](https://docs.cantina.security/apex/scheduled-scans.md): Run recurring workspace scans or fix reviews on a fixed cadence so monitoring keeps up with the code without manual effort. - [Apex CLI guide](https://docs.cantina.security/apex/cli.md): Install Apex CLI, wire it into Claude Code, Codex CLI, or GitHub Copilot CLI, and run scans from the terminal or an agent. - [Apex service API](https://docs.cantina.security/apex/api.md): Run Apex from serverless functions, CI, and internal audit hubs with an organization service key and a REST/JSON workflow. - [Apex API agent environment](https://docs.cantina.security/apex/api-agent-environment.md): A copyable REST-only prompt that selects a source and starts a Standard Apex scan, then returns handoff links immediately. - [Clarion security operations documentation](https://docs.cantina.security/clarion.md): Set up Clarion to connect security tools, correlate alerts, preserve business context, and run governed response with security agents. - [Getting started](https://docs.cantina.security/clarion/getting-started.md): Set up your Clarion workspace, create your first agent, and start triaging alerts. - [Knowledge base](https://docs.cantina.security/clarion/knowledge-base.md): A collection of answers to frequently asked questions. - [Introduction](https://docs.cantina.security/clarion/learn.md): An overview of how Clarion's core concepts fit together, from incoming events to incidents to response. - [Issues](https://docs.cantina.security/clarion/learn/issues.md): Learn how to manage incidents, the consolidated security events that track response from discovery to closure. - [Alerts](https://docs.cantina.security/clarion/learn/alerts.md): Learn how alerts are created, deduplicated, and triaged across all your connected integrations. - [Tasks](https://docs.cantina.security/clarion/learn/tasks.md): Track follow-up work, agent improvements, and operational actions across your team. - [Agents](https://docs.cantina.security/clarion/learn/agents.md): Learn how agents triage alerts, investigate incidents, and execute response actions in your security stack. - [Skills](https://docs.cantina.security/clarion/learn/skills.md): Reusable playbooks that teach agents how to handle specific classes of tasks to a known standard. - [Tools](https://docs.cantina.security/clarion/learn/tools.md): The integrations agents use to take action: send messages, change DNS, file tickets, and more. - [Notifications](https://docs.cantina.security/clarion/learn/notifications.md): Stay in the loop and respond when an agent needs your input across Slack, Teams, SMS, email, and more. - [Settings](https://docs.cantina.security/clarion/learn/settings.md): Configure your workspace, manage members and access, and customize how your team works in Clarion. - [AWS](https://docs.cantina.security/clarion/integrations/aws.md): Connect your AWS account to Clarion for CloudTrail events, CloudWatch alarms, GuardDuty findings, and IAM agent tools. - [EventBridge and SNS](https://docs.cantina.security/clarion/integrations/aws/eventbridge.md): Connect your AWS account to Clarion for CloudTrail events, CloudWatch alarms, GuardDuty findings, and IAM agent tools. - [CloudTrail via existing S3 bucket](https://docs.cantina.security/clarion/integrations/aws/cloudtrail-s3.md): Ingest CloudTrail events into Clarion from an existing S3 bucket using S3 event notifications and SNS — ideal for centralized, organization-wide logging. - [Google Cloud](https://docs.cantina.security/clarion/integrations/google-cloud.md): Connect Google Cloud monitors and runtime credentials for agent triage. - [Cloud Logging](https://docs.cantina.security/clarion/integrations/google-cloud/cloud-logging.md): Send Google Cloud audit logs to Clarion with one monitor per GCP project. - [Cloud Monitoring](https://docs.cantina.security/clarion/integrations/google-cloud/cloud-monitoring.md): Send Google Cloud Monitoring incidents to Clarion from selected alert policies. - [Security Command Center](https://docs.cantina.security/clarion/integrations/google-cloud/security-command-center.md): Send active Google Security Command Center findings to Clarion. - [Cloudflare](https://docs.cantina.security/clarion/integrations/cloudflare.md): Connect Cloudflare to Clarion for Cloudflare Notifications webhooks, Logpush detection monitors, and optional API-powered DNS and analytics agent tools. - [Logpush](https://docs.cantina.security/clarion/integrations/cloudflare/logpush.md): Send Cloudflare firewall_events Logpush batches to Clarion for L7 DDoS-like detection windows. - [Threat Intel](https://docs.cantina.security/clarion/integrations/threat-intel.md): Bring vulnerability advisories, supply chain threats, and security feeds into Clarion for AI-powered triage and response. - [Webhook](https://docs.cantina.security/clarion/integrations/threat-intel/webhook.md): Send structured vulnerability advisories and supply chain threats to Clarion via a signed webhook for AI-powered triage. - [RSS Feed](https://docs.cantina.security/clarion/integrations/threat-intel/rss-feed.md): Subscribe Clarion to an RSS or Atom feed — security blogs, CERT/CSIRT bulletins, advisory feeds — and raise an alert for each newly-published item. - [Okta](https://docs.cantina.security/clarion/integrations/okta.md): Clarion is a security operations platform that helps teams detect, investigate, and respond to identity and access threats. Install the Clarion Okta app from the Okta Integration Network to connect your Okta org to Clarion. - [Microsoft Entra ID](https://docs.cantina.security/clarion/integrations/microsoft-entra-id.md): Connect Microsoft Entra ID (Azure AD) to Clarion to enforce enterprise single sign-on for your organization. - [Microsoft Sentinel](https://docs.cantina.security/clarion/integrations/microsoft-sentinel.md): Connect Microsoft Sentinel to Clarion to poll incidents as alerts and give triage agents Sentinel and Defender investigation tools. - [Microsoft Teams](https://docs.cantina.security/clarion/integrations/microsoft-teams.md): Connect Microsoft Teams to Clarion so agents can post alerts to channels and chats, request approvals via Adaptive Cards, and reach the right people during incidents. - [Google Workspace](https://docs.cantina.security/clarion/integrations/google-workspace.md): Connect Google Workspace Alert Center to Clarion for real-time security alert ingestion and AI-powered triage. - [JumpCloud](https://docs.cantina.security/clarion/integrations/jumpcloud.md): Connect JumpCloud to Clarion to ingest directory and identity events via Insights Rule webhooks and enable agent-driven investigation and response using a JumpCloud service account. - [1Password](https://docs.cantina.security/clarion/integrations/1password.md): Connect 1Password to Clarion to monitor audit events, sign-in attempts, and item usage events from your 1Password Business account. - [CrowdStrike Falcon](https://docs.cantina.security/clarion/integrations/crowdstrike.md): Connect CrowdStrike Falcon to Clarion to poll detections and cases from your Falcon tenant and surface them as signals and issues. - [SentinelOne](https://docs.cantina.security/clarion/integrations/sentinelone.md): Forward Singularity Endpoint threat detections from SentinelOne into Clarion as alerts. - [Huntress](https://docs.cantina.security/clarion/integrations/huntress.md): Connect Huntress to Clarion for endpoint detection and response (EDR) data enrichment during alert triage. - [Splunk](https://docs.cantina.security/clarion/integrations/splunk.md): Connect Splunk to Clarion so agents can forward an alert's details and original payload to your Splunk HTTP Event Collector (HEC) during triage. - [Datadog](https://docs.cantina.security/clarion/integrations/datadog.md): Connect Datadog so agents can query your logs, APM, events, and service catalog — and manage Datadog cases — during triage. - [Grafana](https://docs.cantina.security/clarion/integrations/grafana.md): Connect Grafana to Clarion to receive alerting notifications for AI-powered triage and response. - [Hypernative](https://docs.cantina.security/clarion/integrations/hypernative.md): Connect Hypernative to Clarion for on-chain threat monitoring and AI-powered alert triage. - [Hexagate](https://docs.cantina.security/clarion/integrations/hexagate.md): Connect Hexagate to Clarion to receive on-chain monitor alerts for AI-powered triage and response. - [Tenderly](https://docs.cantina.security/clarion/integrations/tenderly.md): Connect Tenderly to Clarion to receive smart contract monitoring alerts for AI-powered triage and response. - [Guardrail](https://docs.cantina.security/clarion/integrations/guardrail.md): Connect Guardrail to Clarion to receive Guard alerts for AI-powered triage and response. - [Iru](https://docs.cantina.security/clarion/integrations/iru.md): Connect Iru to Clarion so agents can look up devices, users, applications, and vulnerabilities from your Iru tenant during alert triage. - [Apex](https://docs.cantina.security/clarion/integrations/apex.md): Connect Apex to Clarion to ingest security findings from your repositories and code scanning workflows. - [Jira](https://docs.cantina.security/clarion/integrations/jira.md): Connect Jira Cloud to Clarion with an Atlassian service account so agents can create, look up, and search issues during triage. - [Linear](https://docs.cantina.security/clarion/integrations/linear.md): Connect Linear to Clarion so agents can create issues authored by the Clarion app, not by a person on your team. - [Notion](https://docs.cantina.security/clarion/integrations/notion.md): Connect Notion to Clarion with a connection token so agents can search and read your docs, runbooks, and databases for context during triage. - [Confluence](https://docs.cantina.security/clarion/integrations/confluence.md): Connect Confluence Cloud to Clarion with an Atlassian service account so agents can read and search documentation for context during triage. - [Slack](https://docs.cantina.security/clarion/integrations/slack.md): Install the Clarion app for Slack — what Clarion does, how it works inside Slack, where to find the Add to Slack button, and how your data is handled. - [PagerDuty](https://docs.cantina.security/clarion/integrations/pagerduty.md): Connect PagerDuty to Clarion so agents can page your on-call rotation through PagerDuty's Events API v2 during triage. - [incident.io](https://docs.cantina.security/clarion/integrations/incident-io.md): Connect incident.io to Clarion so agents can create alerts in incident.io and use its incident-management tools during triage. - [Halo](https://docs.cantina.security/clarion/integrations/halo.md): Connect Halo (HaloPSA) to Clarion so agents can search and create Halo tickets during alert triage. - [Tailscale](https://docs.cantina.security/clarion/integrations/tailscale.md): Connect Tailscale to Clarion to receive network and identity events — device approvals, key expiry, policy changes, and user lifecycle — as alerts. - [Generic Webhook](https://docs.cantina.security/clarion/integrations/generic-webhook.md): Send events from any service to Clarion via HTTP webhook for AI-powered triage and response. - [Custom MCP](https://docs.cantina.security/clarion/integrations/custom-mcp.md): Connect any MCP-compatible HTTP server to extend Clarion agents with your own tools. - [Getting Started with Cantina](https://docs.cantina.security/security-teams/getting-started.md): Your guide to setting up and using Cantina as an organization - [API Access](https://docs.cantina.security/security-teams/getting-started/api-access.md): Programmatic access to Cantina for client organizations - [SSO Configuration](https://docs.cantina.security/security-teams/getting-started/sso.md): Learn how to configure SSO enforcement for your Cantina organization - [Security solutions](https://docs.cantina.security/security-teams/services.md): Human-delivered security services powered by the Spearbit network, each plugging into the same find, prioritize, remediate, and prove-closure loop. - [Smart Contract Security Audits](https://docs.cantina.security/security-teams/services/smart-contract-audits.md): Comprehensive security audits by Spearbit and Cantina - [Application Security Audits](https://docs.cantina.security/security-teams/services/application-security-audits.md): Comprehensive application infrastructure and application security assessments - [Competitions](https://docs.cantina.security/security-teams/services/competitions.md): Collaborative security audit competitions with expert validation - [Bug Bounty](https://docs.cantina.security/security-teams/services/bug-bounty.md): Managed bug bounty programs for ongoing vulnerability discovery - [Penetration Testing](https://docs.cantina.security/security-teams/services/penetration-testing.md): Comprehensive penetration testing for on-chain and off-chain infrastructure - [Managed Detection and Response](https://docs.cantina.security/security-teams/services/managed-detection-and-response.md): 24/7 incident response and security monitoring - [Advisory](https://docs.cantina.security/security-teams/services/advisory.md): Strategic security advisory and executive-level guidance - [Multisig Security](https://docs.cantina.security/security-teams/services/multisig-security.md): Multi-signature wallet protection and key management solutions - [How Cantina Audits Work](https://docs.cantina.security/security-teams/services/how-audits-work.md): Structured, expert-led reviews of your codebase conducted by vetted security researchers - [Cantina Code for Companies](https://docs.cantina.security/security-teams/cantina-code.md): See findings submitted in real time and collaborate with security researchers through Cantina Code. - [Managing Findings](https://docs.cantina.security/security-teams/cantina-code/managing-findings.md): Efficiently manage and prioritize security findings - [Working with Reports](https://docs.cantina.security/security-teams/cantina-code/working-with-reports.md): Understand and act on security reports - [Building agents on the platform](https://docs.cantina.security/security-teams/community/building-agents.md): Build your own security agents and skills on top of the platform, within guardrails your team controls. - [Sharing and reusing](https://docs.cantina.security/security-teams/community/sharing.md): Publish agents and skills, and draw on what the community has already shared. - [Community guidelines](https://docs.cantina.security/security-teams/community/guidelines.md): Contribution standards that keep shared agents and skills safe, clear, and useful for everyone. - [Joining Cantina](https://docs.cantina.security/researchers/joining.md): Get started as a security researcher on Cantina - [KYC and Payments](https://docs.cantina.security/researchers/joining/kyc.md): Set up your payment information to receive rewards - [Payout Schedule & Process](https://docs.cantina.security/researchers/joining/payout-schedule.md): Understand when and how you'll receive your earnings from competitions, security reviews, and bug bounty programs. - [Participation Guides](https://docs.cantina.security/researchers/participation.md): Essential guidelines for participating in Cantina engagements - [Bug Bounty](https://docs.cantina.security/researchers/participation/bounties.md): Overview of Cantina bug bounty programs - getting started, statuses, payouts, deposits, and mediation - [Bug Bounty Participation](https://docs.cantina.security/researchers/participation/bug-bounty.md): Guidelines for participating in Cantina bug bounty programs - [Bug Bounty Finding Statuses](https://docs.cantina.security/researchers/participation/bug-bounty-statuses.md): Understanding finding statuses for bug bounty programs - from submission to resolution - [Bug Bounty Payout](https://docs.cantina.security/researchers/participation/bug-bounty-payouts.md): Prerequisites and schedule for receiving bug bounty payouts on Cantina - [Deposits for Bounty Submissions](https://docs.cantina.security/researchers/participation/deposits.md): Learn about deposit requirements for bounty submissions on Cantina - [Competition Participation](https://docs.cantina.security/researchers/participation/competitions.md): Rules and guidelines for participating in Cantina competitions - [Submission Guidelines](https://docs.cantina.security/researchers/participation/submission-guidelines.md): Best practices for submitting high-quality findings, including PoC requirements, validity criteria, and competition submission rules. - [Finding Submission Examples](https://docs.cantina.security/researchers/participation/examples.md): Real examples of good and bad security findings including Proof of Concept (PoC) code for smart contract audits. - [Security Review Process](https://docs.cantina.security/researchers/participation/security-review-process.md): Guide for researchers conducting security reviews on Cantina - [Cantina Tools](https://docs.cantina.security/researchers/tools.md): Tools available to security researchers on Cantina - [Communication Features](https://docs.cantina.security/researchers/tools/features.md): Communication tools for security researchers on Cantina Code - [Cantina Code Usage](https://docs.cantina.security/researchers/tools/cantina-code.md): How to use Cantina Code for security research - [Researcher Resources](https://docs.cantina.security/researchers/resources.md): Resources for growing your career on Cantina - [Competitions](https://docs.cantina.security/researchers/competitions.md): Quick links for Cantina security competition participation, teams, and payments. - [Evaluations and Standards](https://docs.cantina.security/standards.md): How we ensure fairness, clarity, and consistency - [Severity Classifications](https://docs.cantina.security/standards/severity.md): Standardized framework for vulnerability classification - [Bug Bounty Severity Classification](https://docs.cantina.security/standards/severity/bug-bounty.md): Cantina's bug bounty severity classification for smart contract vulnerabilities. Learn what's in scope vs out of scope for vulnerability rewards. - [Competition Finding Severity Criteria](https://docs.cantina.security/standards/severity/competition.md): Competition finding severity criteria including the mandatory PoC rule. Learn when Proof of Concept is required for high and medium severity submissions. - [Finding Labels and Status](https://docs.cantina.security/standards/severity/finding-categorization.md): Understanding finding statuses and labels - [Judging Processes](https://docs.cantina.security/standards/judging.md): How findings are evaluated, escalated, and scored - [Referral Program](https://docs.cantina.security/referrals.md): Earn rewards for growing the Cantina ecosystem - [FAQ](https://docs.cantina.security/resources/faq.md): Frequently asked questions about Cantina security audits, competitions, bounties, and researcher programs. - [Public Reports](https://docs.cantina.security/resources/public-reports.md): Browse published security reports from Cantina and Spearbit audits and competitions. - [Links](https://docs.cantina.security/resources/links.md): Official Cantina and Spearbit resources - [Clarion Privacy & Legal Disclosures](https://docs.cantina.security/resources/legal.md): Clarion-specific privacy and legal disclosures. - [Support](https://docs.cantina.security/resources/support.md): How to get help with Cantina and Clarion. - [Client API Reference](https://docs.cantina.security/api.md): REST endpoints available to client organizations - [MCP access](https://docs.cantina.security/api/mcp-access.md): Connect external MCP clients (Claude Code, Cursor, CI scripts) to your Clarion workspace. ## OpenAPI Specs - [openapi-client](/api-reference/openapi-client.yaml) - [openapi](/api-reference/openapi.json) - [openapi](/api-reference/openapi.yaml)