Ecosystem and open API

Guardian fits the stack you already have — and never becomes the thing you cannot leave

400+ certified connectors, a fully documented REST and GraphQL API, four maintained SDKs and signed webhooks on every event. Every capability in the console is available over the API, because a platform that reserves features for its own UI is a platform you cannot automate.

400+ Certified connectors across ten integration categories
1,200 Typed response actions callable from playbooks or the API
6min Median time to configure and validate a first-party connector
OCSF Native schema on ingest and export, so data stays portable
99.99% API availability commitment, measured per region and published monthly

How it fits together

One connector bus, two directions, no bespoke middleware

Connectors are not scripts someone wrote once. Each is a versioned, monitored, rate-aware component with health telemetry, automatic backoff, replay on failure and a published schema contract. When a vendor changes an API, Guardian ships the fix — not you.

INBOUND SOURCES CONNECTOR BUS + DATA FABRIC OUTBOUND TARGETS Endpoint and EDR estate AWS, Azure, Google Cloud Entra ID, Okta, Ping, AD Microsoft 365, Workspace Firewalls, proxies, NDR SaaS applications agent, syslog, API CloudTrail, Activity Log, Audit sign-in, audit, risk events message trace, audit, Graph syslog, NetFlow, IPFIX SCIM, audit APIs, webhooks Connector bus Normalise to OCSF 1.3 Enrich: asset, identity, intel Rate-aware backoff and replay Sentinel fabric detection engine correlation graph AI Analyst response engine 1,200 typed actions SIEM and lake ITSM, ticketing Chat and paging GRC, reporting Response targets Your applications OCSF, CEF, JSON bi-directional sync interactive cards evidence exports isolate, revoke, block REST, GraphQL, webhook Every connector reports health, lag, error rate and quota consumption. Degraded connectors raise a platform alert rather than failing silently. Historical replay re-ingests up to 30 days from any source after an outage, preserving original event timestamps. Outbound data leaves in OCSF, CEF, LEEF or raw JSON, so nothing you send to Guardian becomes trapped in a proprietary shape.

Scroll horizontally to see the full diagram on a small screen.

Connector catalogue

A representative selection of the 400+ certified connectors

Every connector below is first-party, maintained by Guardian, covered by the platform SLA, and validated against each vendor release. Direction indicates whether Guardian reads, writes, or both.

SIEM, analytics and data platforms

Splunk Enterprise Security

Both

Streams OCSF-normalised detections and raw telemetry to indexers or Splunk Cloud; accepts notable-event updates back into the Guardian case.

Microsoft Sentinel

Both

Native data connector plus incident synchronisation, so a Guardian case and a Sentinel incident stay in lockstep with shared status and owner.

IBM QRadar

Outbound

LEEF and CEF over syslog or the REST offense API, with automatic mapping to QRadar's low- and high-level categories.

Elastic Security

Both

ECS-mapped documents via the Elasticsearch bulk API, with alert closure flowing back from Kibana into the Guardian timeline.

Google SecOps

Outbound

UDM-formatted events over the ingestion API, with entity context preserved so SecOps rules can join to Guardian assets.

Exabeam Fusion

Outbound

Detection and identity risk streaming into Exabeam's user and entity behaviour timelines.

Snowflake

Outbound

Continuous export to your own security data lake in OCSF, partitioned and compressed, with schema evolution handled automatically.

Databricks

Outbound

Delta Lake sink with an accompanying notebook library for hunting, enrichment and long-horizon analytics on retained telemetry.

ITSM, ticketing and on-call

ServiceNow ITSM & SecOps

Both

Creates security incidents and change records, reads CMDB for asset context, and binds approval gates to CAB governance.

Jira Service Management

Both

Two-way issue sync with custom field mapping, transition mirroring and comment threading into the Guardian case timeline.

PagerDuty

Both

Rota-aware paging with approval actions delivered as first-class incident responses and acknowledgement flowing back.

Atlassian Opsgenie

Both

Escalation policies honoured, with Guardian severity mapped to Opsgenie priority and auto-close on case resolution.

Zendesk

Outbound

Raises user-facing tickets for coaching workflows, such as a blocked transfer requiring a business justification.

Freshservice

Both

Incident and change creation with asset lookup, for teams standardised on the Freshworks suite.

Slack

Both

Interactive approval cards, case channels created on demand, and slash commands for triage without leaving the conversation.

Microsoft Teams

Both

Adaptive cards for approvals and briefings, plus automatic incident channel creation with the evidence bundle attached.

Cloud and infrastructure

Amazon Web Services

Both

CloudTrail, GuardDuty, VPC flow, Config and Security Hub ingest; response via IAM, EC2, Security Groups and Systems Manager.

Microsoft Azure

Both

Activity Log, Defender for Cloud and Arc ingest; response via NSG rules, VM isolation and role assignment removal.

Google Cloud

Both

Cloud Audit Logs and Security Command Center ingest; response via IAM policy edits, firewall rules and instance quarantine.

Kubernetes

Both

Audit log ingest and admission control, with pod eviction, network policy application and namespace isolation as response actions.

HashiCorp Vault

Both

Secret rotation as a first-class response action, plus audit-device ingest to detect anomalous secret access.

Terraform Cloud

Both

Plan-time policy checks and automatic pull requests that fix the module responsible for a live misconfiguration.

GitHub & GitLab

Both

Audit-log ingest, secret-leak detection, and playbook-driven revocation of exposed tokens with an issue raised on the owning repository.

VMware vSphere

Both

Hypervisor event ingest plus guest snapshot, network detach and power-state response for virtualised estates.

Identity, access and privilege

Microsoft Entra ID

Both

Sign-in and audit ingest, risky-user publication, continuous access evaluation, token revocation and role removal.

Okta

Both

System log ingest, Risk Events API in both directions, session clear, factor reset and group membership changes.

Ping Identity

Both

PingOne risk predictor feed and PingFederate session termination tied to the Guardian identity risk score.

Active Directory

Both

Domain sensor telemetry plus account disable, Kerberos ticket purge, password reset and protected-group removal.

CyberArk

Both

Privileged session termination, just-in-time checkout revocation and vault audit ingest for privileged credential use.

SailPoint IdentityIQ

Both

Entitlement context on ingest, and certification campaigns triggered by Guardian shadow-admin findings.

Cisco Duo

Both

Authentication log ingest, push-fatigue detection, and factor suspension as a response action.

JumpCloud

Both

Directory insights ingest with account suspension and device policy enforcement for cloud-first estates.

Email, network and data security

Microsoft 365 Defender

Both

Message trace and Graph ingest, plus mailbox-wide message retraction and sender blocking as response actions.

Google Workspace

Both

Admin SDK and Gmail audit ingest, OAuth grant revocation, and Drive sharing policy enforcement.

Proofpoint

Both

Threat insight ingest correlated with endpoint detonation results, and campaign-wide retraction triggered from a Guardian case.

Mimecast

Both

Message and attachment telemetry ingest with blocked-sender list management as a response action.

Palo Alto Networks NGFW

Both

Traffic and threat log ingest, dynamic address group updates, and policy-based blocking of command-and-control destinations.

Zscaler

Both

Web and private access log ingest, with URL category and destination blocking applied directly from a playbook.

Fortinet FortiGate

Both

Syslog ingest and address-object updates for rapid egress blocking across distributed sites.

Cloudflare

Both

Logpush ingest plus WAF rule and firewall list management for edge-level containment.

Integration detail

Direction, authentication, latency and supported actions

The specifics that decide whether an integration survives an architecture review. Latency figures are p50 measured across the fleet in the trailing 30 days.

SHARE OF DAILY INGEST VOLUME p50 LATENCY 0% 10% 20% 30% 40% Cloud Endpoint Network Identity Email SaaS and other 41% 27% 14% 9% 6% 3% 4.6 s 0.3 s 0.7 s 1.3 s 6.8 s 40 s provider API bound agent local syslog stream event hooks tenant API quota polling interval Fleet health: 99.7% healthy · 0.2% degraded · 0.1% failed

Scroll horizontally to see the full chart on a small screen.

A representative extract. The complete matrix for all 400+ connectors ships in the product and in the integration datasheet.
Integration Category Direction Authentication Delivery p50 latency Response actions
Splunk Enterprise Security SIEM Bidirectional HEC token Streaming 1.2 s 4
Microsoft Sentinel SIEM Bidirectional Entra app (OAuth 2.0) Streaming 2.4 s 6
ServiceNow SecOps ITSM Bidirectional OAuth 2.0 + mutual TLS Webhook + poll 3.1 s 11
PagerDuty On-call Bidirectional Events API v2 key Webhook 0.9 s 5
Amazon Web Services Cloud Bidirectional IAM role assumption EventBridge + API 4.6 s 38
Microsoft Entra ID Identity Bidirectional Entra app (certificate) Streaming + API 1.4 s 14
Okta Identity Bidirectional OAuth 2.0 private key JWT Event hook + API 1.1 s 12
Microsoft 365 Defender Email Bidirectional Entra app (certificate) Streaming API 6.8 s 9
Palo Alto Networks NGFW Network Bidirectional API key + mutual TLS Syslog + XML API 0.7 s 7
Kubernetes Cloud Bidirectional Service account token Audit webhook 0.4 s 10
HashiCorp Vault Secrets Bidirectional AppRole Audit device + API 1.8 s 6
Snowflake Data lake Outbound Key pair Batch (5 min) 5 min 0

Scroll horizontally to see all columns.

No connector requires an inbound firewall rule to your network. All communication is initiated outbound from the Guardian collector or directly from the vendor's cloud API.

API and SDKs

Everything the console does, the API does first

The Guardian console is built on the same public API you get. There is no privileged internal endpoint, no undocumented capability and no feature that requires clicking. Versioned, rate-documented, and supported for 24 months after a version is superseded.

Resource-oriented, cursor-paginated, and consistent across every object type. Rate limits are returned on every response so a client can back off gracefully rather than guess.

# List open critical cases and isolate the affected host
curl -s "https://api.guardian.com/v3/cases?severity=critical&status=open&limit=50" \
     -H "Authorization: Bearer $GDN_TOKEN"

curl -s -X POST "https://api.guardian.com/v3/actions" \
     -H "Authorization: Bearer $GDN_TOKEN" \
     -H "Content-Type: application/json" \
     -d '{
           "action": "endpoint.isolate",
           "target": { "asset_id": "ast_7f31c9" },
           "params": { "keep_agent": true },
           "reason": "INC-88214 confirmed ransomware behaviour",
           "reversible": true
         }'

# 202 Accepted
# X-RateLimit-Limit: 600   X-RateLimit-Remaining: 587
# { "action_id": "act_92bd41", "status": "executing",
#   "rollback_token": "rbk_1f88ce", "eta_ms": 1800 }

One round trip for the whole investigation graph. Useful when you are building a custom dashboard and do not want eleven REST calls per case.

query CaseContext($id: ID!) {
  case(id: $id) {
    id severity status openedAt narrative
    detections { id technique { id name tactic } confidence }
    assets     { id hostname criticality owner { team } }
    identities { id displayName riskScore privilegeTier }
    dataTouched { classification recordCount }
    actions    { id type status reversible executedAt actor }
    intel      { adversary { name motivation confidence } }
  }
}

# POST https://api.guardian.com/v3/graphql
# Depth limit 12 · complexity budget 5,000 points per query

Maintained SDKs for Python, TypeScript, Go and Java. Typed models, automatic retry with jitter, cursor iteration and streaming support built in.

from guardian import Client

gdn = Client(token=os.environ["GDN_TOKEN"], region="eu-west")

# Stream detections as they happen
for det in gdn.detections.stream(min_confidence=0.85):
    if det.technique.id == "T1003.001" and det.asset.criticality >= 3:
        action = gdn.actions.run(
            "identity.revoke_sessions",
            target=det.identity,
            reason=f"credential access on {det.asset.hostname}",
        )
        action.wait(timeout=30)
        print(action.status, action.rollback_token)

# Retro-hunt across retained telemetry
hits = gdn.hunt.query(
    "process.name = 'rundll32.exe' and network.destination.asn = 209242",
    since="90d",
)

The CLI is how playbooks, detections and policies move between environments. It is the same binary used by the Guardian CI action.

# Validate and promote a playbook from staging to production
gdn playbook lint      ./playbooks/contain-credential-theft.gdn
gdn playbook test      ./playbooks/contain-credential-theft.gdn --fixtures ./fixtures
gdn playbook diff      ./playbooks/contain-credential-theft.gdn --env prod
gdn playbook promote   ./playbooks/contain-credential-theft.gdn --env prod --tier 2

# Export everything for a compliance evidence request
gdn export cases --since 2026-01-01 --format ocsf --out ./evidence
gdn export audit --since 2026-01-01 --verify-chain

Scoped tokens

OAuth 2.0 client credentials with fine-grained scopes, per-token rate limits, IP allow lists and a maximum lifetime you set. Every call is attributed in the immutable audit log.

Versioned and deprecated slowly

Major versions are supported for 24 months after supersession. Breaking changes are announced twelve months ahead with a migration guide and a compatibility shim.

OpenAPI and sandbox

A complete OpenAPI 3.1 specification, a public Postman collection, and a free sandbox tenant with synthetic incident data so you can build before you buy.

Bulk export, always

Every event, case, action and audit record is exportable in OCSF, CEF or JSON at any time, with no export fee and no throttling penalty. Your data remains yours.

Webhooks

Signed, replayable, and idempotent by design

Subscribe to any of 64 event types with a JSONPath filter, receive an HMAC-SHA256 signature on every delivery, and replay the last 30 days from the console if your endpoint was down. Deliveries carry an idempotency key so a retry never double-executes.

POST /hooks/guardian HTTP/1.1
Content-Type: application/json
X-Guardian-Event: case.action.executed
X-Guardian-Delivery: dlv_4c2e91a7
X-Guardian-Idempotency-Key: idm_88214_act_92bd41
X-Guardian-Signature: t=1786109041,v1=6d1a...c93f

{
  "event": "case.action.executed",
  "occurred_at": "2026-07-31T09:18:12.418Z",
  "tenant": "acme-global",
  "case": { "id": "INC-88214", "severity": "critical" },
  "action": {
    "id": "act_92bd41",
    "type": "identity.revoke_sessions",
    "status": "succeeded",
    "reversible": true,
    "rollback_token": "rbk_1f88ce",
    "actor": "playbook:[email protected]"
  },
  "target": { "identity_id": "idn_2f7a10", "tier": 1 }
}

Verify with HMAC-SHA256(secret, t + "." + body) and reject any delivery whose timestamp is more than five minutes old. Reference implementations for Python, Node, Go and Java are in the developer documentation.

64 event types

Detections, case lifecycle, action execution and rollback, approval requests and decisions, connector health, policy changes, intelligence publication and audit events. Subscribe to all of them or filter to one.

Delivery guarantees

At-least-once delivery with exponential backoff over 24 hours, a dead-letter queue you can inspect, and per-endpoint health metrics. Consistently failing endpoints raise a platform alert rather than being silently disabled.

Mutual TLS available

Present a client certificate for delivery, pin the Guardian certificate on your side, or route webhooks through a private link so nothing traverses the public internet.

Read the developer documentation

Custom connectors

Something missing? Build it in an afternoon.

The connector SDK gives you the same primitives Guardian engineers use: schema mapping, pagination, rate limiting, secret handling, health reporting and replay. You write the vendor-specific part and nothing else.

  1. Declare the source

    Describe the endpoint, authentication method, pagination style and rate limits in a manifest. The SDK generates the polling loop, backoff behaviour and credential storage for you.

  2. Map to OCSF

    Write field mappings against the OCSF 1.3 schema with a visual mapper or a declarative file. Unmapped fields are preserved verbatim so nothing is lost, and validation runs on every build.

  3. Declare actions

    Type each outbound action with its parameters, side effects, reversibility and required permission. Typed actions become available to every playbook and to the API automatically.

  4. Test and publish

    Run against recorded fixtures, publish privately to your tenant, or submit to Guardian for certification and inclusion in the public catalogue with joint support.

Technology alliance programme

Co-engineering, joint certification, shared support runbooks and listing in the Guardian catalogue. 140 vendors are in the programme today.

Partner with Guardian

MSSP multi-tenancy

Tenant-scoped API keys, cross-tenant querying with explicit consent, per-client rate pools and consolidated billing. Built for service providers, not retrofitted.

MSSP programme

Migration assistance

Guardian engineers convert your existing SOAR playbooks, SIEM content and detection rules as part of onboarding. Median conversion for a mature SOC: three weeks.

Talk to consulting

We were sceptical about the open API claim, so we rebuilt our entire executive dashboard against it in a week without opening a support ticket. That has never happened to us with a security vendor.

Priya Lakhani
Principal Security Engineer, global SaaS platform

Questions

What platform teams ask us first

Do connectors cost extra?

No. Every certified connector, the full API, all four SDKs and unlimited webhooks are included in every Guardian Sentinel plan. There is no per-connector fee, no ingest surcharge for third-party sources and no charge for exporting your own data. Pricing is per protected asset — see the pricing page.

What if a connector we depend on breaks after a vendor update?

Guardian monitors every certified connector against vendor release channels and pre-production environments. Connector health, lag and error rate are visible in your console, and a degraded connector raises a platform alert rather than silently dropping data. Certified connectors carry a four-hour response commitment for a total failure, and fixes ship as platform updates with no action required from you.

Can Guardian coexist with our existing SIEM rather than replacing it?

Yes, and most customers run both for at least a year. Guardian streams OCSF-normalised detections and, if you want it, raw telemetry into Splunk, Sentinel, QRadar, Elastic or your own lake. Many teams reduce SIEM licence cost by routing high-volume telemetry to Guardian for detection and forwarding only the enriched output for retention and compliance search.

What network access does a connector require?

None inbound. On-premises collectors initiate outbound TLS 1.3 to a published set of hostnames on port 443, and cloud connectors call vendor APIs directly. Private connectivity is available through AWS PrivateLink, Azure Private Link and Google Private Service Connect for customers who require it.

How are credentials for our third-party systems stored?

In a per-tenant envelope-encrypted secret store with keys held in a FIPS 140-3 validated HSM, optionally your own through bring-your-own-key. Credentials are never written to logs, never visible in the console after entry, and are accessible only to the specific connector runtime that needs them. Certificate and workload-identity authentication is preferred wherever the vendor supports it.

What are the API rate limits?

600 requests per minute per token by default for read operations and 120 per minute for actions, with burst allowances and per-tenant pools that scale with your plan. Every response carries the current limit, remaining quota and reset time. Streaming endpoints and bulk export are not counted against the request budget.

Build against it before you buy it

Request a free sandbox tenant with synthetic incident data, full API access and every connector enabled. No sales conversation required to get the credentials.