Orithos pushes every finding — with lifecycle status — to any CNAPP, SIEM, or webhook endpoint you designate. HMAC-signed delivery, 50-finding batches, rotating secrets. If your platform can ingest a signed webhook, it can graph agent-security findings.
Dashboard → Settings → Integrations → Findings Feed. Each destination is a name, a URL, and a signing secret (16+ chars). Secrets are encrypted at rest and never appear in any API response — you see the value once at creation time.
Every request carries X-Orithos-Signature-256: the HMAC-SHA256 hex digest of the raw JSON body, keyed with your destination secret.
Failed deliveries are parked with an audit event (visible in your audit log) — the feed never blocks a scan and never silently drops data. A destination that 500s shows up in Settings with its last-failure timestamp; retry via the fanout endpoint or disable the destination without losing audit history.
Need SARIF instead of JSON? Every scan exports SARIF 2.1.0 directly (GET /v1/scans/{id}/report/download?format=sarif) — poll the scan API on your own schedule and pull, or use the push feed for lifecycle updates. Both formats carry the same finding IDs, so you can merge them on your side.