Integrations

Works Where You Already Work

Maps To What You Already Report.

Connect an AI agent with one sign-in, or run Sekura on your own GitHub Actions runner so source never leaves your repo — and every finding maps to the frameworks you already report against.

Sekura — owl-in-shield mark

Integrations and compliance

Works where you already work. Maps to what you already report.

Works with

AI agents

  • Meta Muse
  • REST API with OpenAPI 3.1

CI/CD

  • GitHub Actions
  • Self-hosted runners

LLM providers

  • Anthropic Claude
  • OpenAI GPT
  • Private endpoints (Enterprise)

Notifications + fixes

  • Slack
  • Outlook
  • Teams
  • Jira
  • Confluence

Maps to

Findings auto-mapped to 14 compliance frameworks. Audit prep as a byproduct of every scan.

  • SOC 2
  • ISO 27001
  • HIPAA
  • PCI DSS
  • NIST CSF
  • NIST 800-53
  • GDPR
  • CCPA
  • FedRAMP
  • HITRUST
  • FFIEC
  • CIS
  • GLBA
  • CMMC

Use Sekura from your AI agent.

Meta Muse connects to Sekura’s API with one sign-in, through a link it opens; there is no key to copy. Scans run on Sekura’s infrastructure; the agent reads your results and starts a scan once you agree to it.

curl https://sekura.ai/api/muse/v1/openapi.json

The OpenAPI 3.1 document for the API Meta Muse uses, readable without a key.

Connect your agent

  1. 1Ask Meta Muse to connect Sekura.
  2. 2On the page Muse opens, sign in with GitHub, install the Sekura GitHub App on the repositories to scan, and approve. There is no key to copy.
  3. 3Ask it to scan a repository. It shows you what you are authorizing and the price, and nothing runs or is charged until you agree.

Sekura runs on your GitHub Actions runner.

Source code never leaves your repo. We dispatch a workflow, the runner executes the scan, and we receive only the findings. SARIF flows back into the GitHub Security tab; PR review comments arrive inline on the lines we found issues on.

What gets installed

name: Sekura Security Scan

on:
  push:
    branches: [main, master]
  pull_request:
  workflow_dispatch:

permissions:
  contents: read
  pull-requests: write
  security-events: write

jobs:
  sekura:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: sekuraai/sekura-scan-action@v1
        with:
          scan-type: sast
          sekura-token: ${{ secrets.SEKURA_TOKEN }}

The SEKURA_TOKEN secret is provisioned automatically, encrypted with the repo’s public key. You never paste a token by hand.