Sinterly documentation
Sinterly is a security finding intelligence platform — the Security ETL Engine. It takes the output your scanners and threat-modelling tools already produce, normalises it into one finding model, removes the duplicates, scores what remains with an explainable five-component formula, and routes the result to your dashboard and your ticketing.
The name of the discipline is deliberate. Data teams stopped hand-wrangling spreadsheets when ETL pipelines made extraction, transformation and loading repeatable and auditable. Security findings deserve the same treatment: every finding in one place, one severity language, one priority order, and a clear record of why each number is what it is.
Who it is for
Teams that already run scanners — SAST, SCA, secrets, container, DAST — and drown in their combined output. Sinterly is hosted and opinionated: you bring findings, it brings order. It does not scan your code and it does not modify your code.
Where to start
- Quickstart — from trial request to a prioritised backlog.
- Ingesting findings — SARIF, CSV, threat models, and the GitHub connector.
- How scoring works — the five components and why every score is auditable.
- Security architecture — every trust claim, with its mechanism.