Ellipse Gradient for Header

SecurityScorecard Integration Guide

Integrate SecurityScorecard with enterprise systems through authenticated REST API workflows for risk monitoring, score synchronization, findings management, and automation.

SecurityScorecard integration options at a glance

SecurityScorecard's primary integration mechanism is its authenticated REST API, which exposes company, score, factor, finding, portfolio, and score-history resources. Martini can call these endpoints from scheduled or request-driven workflows, process paginated JSON responses, apply risk and threshold rules, and write normalized results to databases, ticketing systems, risk platforms, or security operations tools. API-key authentication should be stored as a Martini secret and verified against the current account documentation. General-purpose webhooks, bulk APIs, file exchange, GraphQL, SOAP, and direct database access were not confirmed. Selected SecurityScorecard notifications may be usable where the account supports them, subject to feature validation.

Integration pointSupported by SecurityScorecard?Common use casesHow Martini supports it
REST APIsYesRetrieve Companies, Scores, Factors, Findings, Portfolios, score history, and related monitoring data through authenticated HTTP requests.Martini can consume the SecurityScorecard REST API, process JSON responses, paginate through results, apply business rules, and expose normalized results through a Martini API.
AuthenticationYesAuthenticate API requests with a SecurityScorecard API key using the authorization scheme required by the current account and API version.Martini can store the API key in secrets or environment configuration and apply it to outbound REST requests without embedding it in workflows or logs.
Webhooks / outbound callbacksLimitedSecurityScorecard may provide notifications or integrations for selected products or workflows, but universal webhook coverage for resource changes was not confirmed.Where a supported notification sends an HTTP request, Martini can receive it through an HTTP-triggered workflow and retrieve authoritative data from the REST API.
Bulk / asynchronous / batch APIsNot confirmedA general-purpose bulk or asynchronous API was not confirmed. Large portfolios should use pagination, scheduled retrieval, and controlled concurrency unless tenant documentation identifies another endpoint.Martini can orchestrate scheduled batches, pagination, checkpoints, throttling, and controlled retries in workflows.
File / attachment APIsNot confirmedNo general SecurityScorecard file import, export, or attachment API was confirmed; score and finding data should normally be exchanged through API responses.Martini can process files when another system supplies them, but the SecurityScorecard REST API remains the confirmed integration route.
Database / analytics accessNoDirect database access and separately documented analytics access were not confirmed for SecurityScorecard.Martini can persist API-derived data in supported SQL databases or other target systems without requiring direct access to SecurityScorecard databases.
SDKsNot confirmedNo official SDK was confirmed as the primary integration method.Martini can use standards-based HTTP REST requests directly, avoiding a dependency on an unconfirmed SDK.

How SecurityScorecard exposes data and business events

SecurityScorecard REST APIs

SecurityScorecard's confirmed integration model is authenticated REST API access to company, score, factor, finding, portfolio, and score-history resources. Responses and exact fields can vary by API version and account entitlement, so the current SecurityScorecard reference documentation should remain the schema authority.

Martini implementation pattern

Martini implementation pattern: A workflow sends an authenticated HTTP request, handles pagination and response validation, maps the JSON payload to a canonical model, applies business rules, and writes the result to a target system or exposes it through a Martini API.

Implementation sequence

Read the monitored company or portfolio scope
Retrieve the current SecurityScorecard resource
Follow pagination until the required result set is complete
Validate and map the JSON response
Apply risk, threshold, and lifecycle rules
Write the result and store synchronization metadata

Scheduled synchronization

Scheduled retrieval is the confirmed baseline for monitoring because a general-purpose event stream or universal webhook model was not confirmed. Schedules can retrieve current scores, factors, findings, portfolios, and historical observations.

Martini implementation pattern

Martini implementation pattern: A scheduler starts a workflow that processes companies in controlled batches, compares current results with stored observations, and routes only new or materially changed information to downstream systems.

Implementation sequence

Start the workflow on an approved schedule
Load the company or portfolio processing list
Retrieve resources with controlled concurrency
Compare results with the last successful observation
Persist changes and synchronization checkpoints
Retry transient failures and report persistent exceptions

Selected notifications or callbacks

SecurityScorecard may provide notifications or product-specific integrations for selected workflows, but general webhook coverage for all resource changes was not confirmed. Availability and event coverage must be validated for the account and use case.

Martini implementation pattern

Martini implementation pattern: Where a supported notification sends an HTTP request, Martini receives it through an HTTP-triggered workflow, validates the request according to the available SecurityScorecard feature, and retrieves the authoritative Company, Score, or Finding through the REST API rather than trusting a partial notification payload.

Implementation sequence

Receive the supported notification request
Validate the request and identify the affected resource
Retrieve authoritative data from the REST API
Apply change and deduplication rules
Write the result to the target system
Record processing status and errors

Common SecurityScorecard integration patterns

Pattern 1: Monitor supplier scores and factors

When to use this pattern

Use this pattern when security, procurement, or risk teams need recurring visibility into the SecurityScorecard posture of suppliers or partners. The workflow retrieves current scores and factors, compares them with stored observations, and escalates deterioration according to organizational thresholds.

Integration direction
SecurityScorecard
Martini
SQL database
RSA Archer
Example Mapping
SecurityScorecard FieldCanonical FieldTarget Field
company.idorganization.externalIdsupplier.externalId
company.domainorganization.domainsupplier.domain
score.gradesecurityRating.gradeassessment.grade
score.valuesecurityRating.valueassessment.score
Martini implementation pattern

A scheduled workflow loads the monitored portfolio, retrieves each Company and its Scores and Factors with pagination, normalizes the original grade and numeric values, compares them with the prior snapshot, and writes the result to a database or risk platform. Rate-limit responses are retried with backoff, while authorization and company-resolution failures are routed for review.

Martini capabilities used
  • workflows
  • scheduled execution
  • API consumption
  • pagination orchestration
  • data mapping
  • business rules
  • SQL database integration
  • error handling

Pattern 2: Convert findings into remediation tickets

When to use this pattern

Use this pattern when SecurityScorecard Findings must become accountable remediation work in ServiceNow or Jira. It is appropriate for creating new work, updating changed findings, and retaining a clear link between the vendor observation and destination ticket.

Integration direction
SecurityScorecard
Martini
ServiceNow
Example Mapping
SecurityScorecard FieldCanonical FieldTarget Field
finding.idriskFinding.externalIdu_securityscorecard_finding_id
company.idorganization.externalIdcompany
finding.statusriskFinding.statusstate
finding.descriptionriskFinding.descriptiondescription
Martini implementation pattern

Martini retrieves findings, constructs a stable composite key from company and finding identifiers, searches the target for an existing ticket, and creates or updates it idempotently. Business rules assign ownership based on factor or severity, and only an authoritative complete result should cause a finding ticket to close.

Martini capabilities used
  • workflows
  • API consumption
  • data mapping
  • idempotency rules
  • conditional routing
  • business rules
  • error handling
  • retry processing

Pattern 3: Enrich supplier onboarding with a scorecard

When to use this pattern

Use this pattern when an approved supplier or partner must be assessed before onboarding. The process resolves an internal supplier to a SecurityScorecard Company, retrieves the scorecard, and routes the supplier based on score, grade, factor, or finding thresholds.

Integration direction
Workday
Martini
SecurityScorecard
Example Mapping
SecurityScorecard FieldCanonical FieldTarget Field
supplier.domainorganization.domaincompany.domain
supplier.externalIdorganization.internalIdcorrelation.internalId
score.gradeassessment.gradesupplierRisk.grade
factorsassessment.factorssupplierRisk.factorResults
Martini implementation pattern

A Martini API or workflow receives approved supplier data, resolves the domain or company identifier, calls SecurityScorecard, and applies configurable approval rules. Passing suppliers continue automatically, while low scores, regulated-factor concerns, unknown companies, or incomplete responses route to manual review with an auditable result.

Martini capabilities used
  • API exposure
  • workflows
  • API consumption
  • data mapping
  • validation
  • business rules
  • conditional routing
  • audit logging

Pattern 4: Notify teams about material score changes

When to use this pattern

Use this pattern when security or procurement teams need timely notification of score deterioration, factor changes, newly observed findings, or companies entering or leaving a monitored portfolio.

Integration direction
SecurityScorecard
Martini
Slack
Example Mapping
SecurityScorecard FieldCanonical FieldTarget Field
company.nameorganization.namemessage.company
score.valuesecurityRating.currentValuemessage.currentScore
previousScore.valuesecurityRating.previousValuemessage.previousScore
finding.idriskFinding.externalIdmessage.findingId
Martini implementation pattern

A scheduled workflow retrieves current data, compares it with stored snapshots, filters changes using materiality rules, and sends a normalized message to Slack or another collaboration target. The workflow records notification keys to prevent duplicate alerts and retries transient target failures without repeating completed notifications.

Martini capabilities used
  • scheduled execution
  • API consumption
  • change detection
  • data transformation
  • business rules
  • messaging API integration
  • idempotency
  • retry handling

Applications commonly integrated with SecurityScorecard

SecurityScorecard data can be routed to risk, service management, security operations, collaboration, and supplier-management applications. The following are practical integration targets; any product-specific native integration or marketplace package should be validated separately.

Application Scenario Direction Martini Pattern
ServiceNow Create and update remediation or third-party-risk tickets from SecurityScorecard findings, score changes, and monitoring results. SecurityScorecard → Martini → ServiceNow A scheduled Martini workflow retrieves findings and scores, maps stable SecurityScorecard identifiers to ServiceNow records, applies ticketing rules, and updates existing items idempotently. Related status changes can be returned through a separate workflow when required.
Jira Assign SecurityScorecard findings to security or engineering teams and track remediation work through a work-management process. SecurityScorecard → Martini → Jira Martini polls selected company findings, builds a composite key from the company and finding identifiers, and creates or updates Jira issues while routing authentication, validation, and transient API failures separately.
RSA Archer Synchronize supplier risk information, assessments, and external security ratings with a broader governance, risk, and compliance program. SecurityScorecard → Martini → RSA Archer Martini retrieves score and factor data, maps it to the organization's Archer risk model, preserves original vendor identifiers, and writes results through the target system's supported API or import endpoint.
Splunk Ingest score changes, findings, and monitoring results for correlation with security operations data. SecurityScorecard → Martini → Splunk A scheduled workflow retrieves changed SecurityScorecard data, normalizes the JSON into security events, enriches each event with portfolio context, and forwards it using the supported Splunk ingestion route.
Microsoft Sentinel Enrich security operations workflows with third-party risk and supplier security observations. SecurityScorecard → Martini → Microsoft Sentinel Martini compares current and stored scores or findings, transforms material changes into the target event model, and sends them to the supported Sentinel ingestion interface with retry and duplicate controls.
Salesforce Add security-rating information to account or partner records and support risk-aware sales or supplier processes. SecurityScorecard → Martini → Salesforce Martini resolves SecurityScorecard Companies to Salesforce accounts using a controlled domain or identifier mapping, then updates score, grade, factor, and observation fields subject to business rules.
Slack Notify security and procurement teams about material score deterioration, new findings, or portfolio changes. SecurityScorecard → Martini → Slack A scheduled Martini workflow detects material changes, applies notification thresholds, formats a concise message with company and finding context, and sends it through Slack's supported API or endpoint.
Workday Associate supplier or organization information with external security ratings in procurement and vendor-risk workflows. Workday → Martini → SecurityScorecard Martini receives or retrieves approved supplier data, resolves the supplier to a SecurityScorecard company or domain, obtains the current scorecard, and returns normalized risk information to the appropriate Workday or risk workflow.

How to build a SecurityScorecard integration in Martini

Objective

Establish the SecurityScorecard API connection using the current account authentication requirements and environment-specific credentials.

Instructions in Martini

  • Confirm the current API base URL, resource paths, API version, and authorization header format.
  • Store the API key in Martini secrets or environment configuration.
  • Use separate development, test, and production credentials where possible.
  • Verify the credential has only the permissions required by the workflow.

Objective

Select the trigger that matches the integration's operating model, using scheduled retrieval as the confirmed baseline or a validated notification feature where available.

Instructions in Martini

  • Use a Scheduler Trigger for recurring score, factor, finding, or portfolio synchronization.
  • Use an HTTP-triggered workflow only when the relevant SecurityScorecard notification or callback is confirmed.
  • Define the monitored company or portfolio scope before processing begins.

Objective

Call the relevant SecurityScorecard REST resources and obtain complete, authoritative result sets.

Instructions in Martini

  • Retrieve Companies, Scores, Factors, Findings, Portfolios, or score history as required.
  • Handle pagination metadata rather than assuming a single response contains all results.
  • Use controlled concurrency and response-aware throttling for large portfolios.
  • Persist checkpoints where a long-running synchronization could be interrupted.

Objective

Coordinate resource retrieval, enrichment, comparison, routing, and target-system writes in a maintainable Martini workflow.

Instructions in Martini

  • Separate vendor payload handling from the internal canonical model.
  • Load prior observations or destination mappings before creating updates.
  • Route validation, authorization, rate-limit, and transient server failures differently.
  • Use reusable workflow logic for common retrieval and normalization operations.

Objective

Convert SecurityScorecard JSON into target-specific models while preserving vendor identifiers and original values.

Instructions in Martini

  • Map Companies, Scores, Factors, Findings, Portfolios, and score history to canonical fields.
  • Store numeric scores and letter grades as distinct values.
  • Preserve unknown fields where practical for forward compatibility.
  • Create target-specific payloads only after canonical transformation.

Objective

Apply organization-specific risk, materiality, lifecycle, and ownership rules before writing downstream results.

Instructions in Martini

  • Define thresholds for automatic approval, escalation, and manual review.
  • Compare current and previous observations to identify material changes.
  • Use stable company and finding identifiers for idempotency.
  • Do not close finding tickets merely because a finding is absent from an incomplete response.

Common SecurityScorecard data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
CompaniesRepresent organizations identified by domains or SecurityScorecard company identifiers.ServiceNow, Salesforce, RSA Archer, Workday, SQL databasesMartini resolves internal supplier or customer identifiers to Companies, preserves the vendor identifier, and maps company metadata into a canonical organization model.
ScoresRepresent an organization's current security rating, grade, numeric score, or related assessment values.Risk platforms, Salesforce, Splunk, Microsoft Sentinel, data warehousesMartini stores original score and grade values separately, compares them with prior observations, and applies configurable thresholds without assuming the values are interchangeable.
FactorsRepresent security-risk categories contributing to a company's score.RSA Archer, ServiceNow, reporting databases, security operations platformsMartini maps factor-level values into a normalized risk structure, identifies deterioration, and routes material changes according to business rules.
FindingsRepresent identified security issues or observations associated with a company, factor, or asset.ServiceNow, Jira, Splunk, Microsoft SentinelMartini uses stable company and finding identifiers for idempotent creation and updates, tracks lifecycle state, and avoids closing tickets solely because an item is absent from an incomplete response.
PortfoliosGroup Companies monitored together by a SecurityScorecard organization.SQL databases, risk applications, Workday, reporting systemsMartini retrieves portfolio membership, controls monitoring scope, and uses portfolio context to schedule and route company-level processing.
Score historyProvide historical score observations for trend analysis and change detection.Data warehouses, SQL databases, risk dashboards, notification systemsMartini persists timestamped observations, compares current and previous values, and retains vendor identifiers for reconciliation and auditability.

Authentication and security considerations

API-key authentication

SecurityScorecard documents API-key authentication for API access. Confirm the current authorization header format, API version, account scope, and permissions before deployment.

Credential protection

  • Store API keys in Martini secrets or environment-specific configuration.
  • Use separate credentials for development, testing, and production where possible.
  • Restrict credentials to the minimum required permissions and rotate long-lived keys through configuration.
  • Do not place credentials in workflow payloads, mappings, logs, or error messages.

Transport and target security

Use HTTPS for API communication and apply the authentication and authorization controls required by downstream systems. OAuth 2.0 and JWT-based authentication were not confirmed as general SecurityScorecard requirements.

Operational considerations for SecurityScorecard integrations

Pagination and rate limits

Portfolio, finding, and historical responses may span multiple pages. Read the vendor's pagination metadata, process pages to completion, and use controlled concurrency. Confirm plan-specific rate limits and apply response-aware throttling and retry backoff.

Idempotency and lifecycle

Persist Company and Finding identifiers with destination identifiers, last observed state, and synchronization timestamps. Do not automatically close a finding because it is absent from an incomplete response; use a complete authoritative result and documented lifecycle semantics.

Schema and score handling

Keep vendor payloads separate from canonical models and tolerate new fields where practical. Store original numeric scores and letter grades separately. Validate domains, company resolution, account entitlements, and response completeness before downstream updates.

Testing and monitoring

Test authentication failures, authorization errors, rate limiting, unknown companies, malformed domains, pagination, changed findings, and partial target failures. Monitor workflow logs, checkpoints, retries, and reconciliation results across environments.

Why use Martini instead of scripts or point-to-point integrations?

Orchestration instead of isolated scripts

Martini provides a maintainable workflow layer for scheduled retrieval, pagination, enrichment, change detection, target updates, and exception routing. This avoids duplicating authentication, retry, and mapping logic across independent scripts.

Reusable integration assets

Martini can consume the SecurityScorecard REST API, expose normalized APIs, and reuse mappings, validation, business rules, and error-handling patterns across supplier, risk, ticketing, and security operations processes.

Operational control

Environment-specific secrets, checkpoints, workflow logs, retries, and controlled concurrency support safer production operation than point-to-point code that lacks centralized monitoring and governance.

Frequently asked questions

How can SecurityScorecard be integrated with enterprise systems?

SecurityScorecard can be integrated primarily through its authenticated REST API. Enterprise workflows can retrieve Companies, Scores, Factors, Findings, Portfolios, and score history, then map and synchronize the data with risk, ticketing, security operations, supplier-management, or database systems. Scheduled polling is the confirmed baseline; selected notifications or callbacks may be available for particular products or plans and should be validated before use.

Can Martini integrate with SecurityScorecard?

Yes. Martini can integrate with SecurityScorecard by consuming its authenticated REST API from workflows and APIs, transforming JSON responses, applying business rules, and writing results to supported target systems. Where a specific SecurityScorecard feature provides a supported notification or callback, Martini can receive it through an HTTP-triggered workflow and retrieve authoritative resource data.

Do I need a connector to integrate SecurityScorecard with Martini?

No. A dedicated SecurityScorecard connector is not required. Martini can use SecurityScorecard's confirmed native integration mechanism—the authenticated REST API—and can also work with a validated notification or callback through an HTTP-triggered workflow.

Is there any extra Lonti cost to integrate SecurityScorecard with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate SecurityScorecard with Martini. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from SecurityScorecard, cloud infrastructure, databases, target applications, or other third-party systems depending on subscription, usage, and deployment model.

Which SecurityScorecard integration method should be used?

Use the SecurityScorecard REST API as the primary method for retrieving Companies, Scores, Factors, Findings, Portfolios, and score history. API-key authentication is confirmed. GraphQL and SOAP APIs were not confirmed, and a general-purpose bulk or asynchronous API was not confirmed, so large synchronizations should use pagination, scheduling, and controlled concurrency.

Can Martini receive SecurityScorecard webhooks or events?

General-purpose webhook coverage for all SecurityScorecard resource changes was not confirmed. SecurityScorecard may provide selected notifications or product-specific integrations. If the required feature is available, Martini can receive the HTTP request, validate it, and retrieve the authoritative resource through the REST API. Otherwise, scheduled polling with change detection is the supported baseline.

How does synchronization and data mapping work?

Martini retrieves paginated JSON responses, maps vendor objects to a canonical model, preserves SecurityScorecard identifiers, and writes target-specific payloads. Stable Company and Finding identifiers support reconciliation and idempotency. Numeric scores and letter grades should remain separate, and score history should be persisted when trend analysis or auditability is required.

How are SecurityScorecard errors, retries, and duplicates handled?

Martini can distinguish authentication, authorization, validation, rate-limit, transient server, and target-system failures. Transient failures can be retried with backoff, while persistent failures can be routed for review. Stored company and finding mappings, checkpoints, and notification keys help make retries safe and prevent duplicate tickets or alerts.