Threat & Vulnerability · Integration
Kenna Security
Add Kenna Security to your product for your customers, and give your AI agents governed access to it.
Embed a Kenna Security integration so your customers can bring their own vulnerability and asset findings into your product instead of exporting reports. Findings arrive through event delivery rather than polling, so your product reacts in near real time, and they are deduplicated per finding so a repeatedly reported issue does not create a queue of identical records for your users to sift through. Access is scoped per tenant and every call is logged.
In your product
Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.
Let customers read their own vulnerability findings into your product, ranked the way they already rank them.
Read the assets a finding affects so remediation work lands on the right owner.
Trigger your workflows when a new finding appears or an existing one changes status.
Update a finding's status from your product once remediation is confirmed.
For your AI agents
Governed, audited access for the agents you build, through the MCP server.
An agent reads open findings and the assets behind them before recommending what to fix first.
An agent updates a finding's status within governed permissions, with each change audited.
An agent reacts to a new high-risk finding and assembles the context an owner needs.
Example prompt
List the highest-risk open findings from the last week and show which assets each one affects.
Set up Kenna Security in 4 steps
- 01Open the Kenna Security connector from your fastn dashboard.
- 02Have each customer authenticate their own Kenna Security tenant with least-privilege credentials.
- 03Map the finding and asset fields your product uses, then enable actions and triggers.
- 04Call them from your product, or expose them to an agent through the MCP server.
Why teams use the Kenna Security integration
What you get by embedding it with fastn instead of building it yourself.
- Ship a Kenna Security integration without building it. Your customers connect their own Kenna Security account inside your product and work their findings, detections and assets there, with no per-customer code on your side.
- Handle the part that actually costs time: a rescan re-reports everything, so the same finding arriving twice must not read as two problems. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Kenna Security update is not your on-call problem.
- One integration serves your product and your agents. The same governed Kenna Security connection powers in-product features and gives AI agents scoped, audited access, so you get security findings in front of the people and systems that act on them without wiring it twice.
Used by these teams
Works well with
Often used alongside
Tools the same teams tend to run next to Kenna Security, across other categories.
Kenna Security integration FAQ
How do I add a Kenna Security integration to my product?
Enable the Kenna Security connector in your fastn dashboard, then let each customer authenticate their own Kenna Security account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Kenna Security client code in your app and no per-customer branch in your codebase. Setup is 4 steps.
Do my customers each connect their own Kenna Security account?
Yes. Every connection is scoped to the individual customer, so each authorises their own Kenna Security account and only ever sees their own findings, detections and assets. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.
Can AI agents use this Kenna Security integration?
Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent reads open findings and the assets behind them before recommending what to fix first.
Who maintains the Kenna Security integration?
fastn does. When Kenna Security changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.
How does a new Kenna Security finding reach my product?
Through event triggers rather than polling, delivered per tenant, so your product reacts when a finding is raised or its severity changes rather than on a schedule that is always slightly out of date.
How is Kenna Security finding noise kept manageable?
Findings are deduplicated per asset so a rescan does not re-raise what you already have, and you can filter by severity and status before anything reaches your product. That matters more here than in most integrations, because the volume is what stops teams acting on any of it.
What can I build with the Kenna Security integration?
A common starting point: read their own vulnerability findings into your product, ranked the way they already rank them. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.
How much does the Kenna Security integration cost?
It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Kenna Security does not change your per-connector cost. You can start free with 3 connected accounts.
Add Kenna Security to your product
Start free with 3 connected accounts. No sales call required, and no per-customer integration code.