Jira integration
Prioritised findings become Jira tickets; ticket status flows back. The sync is deliberately conservative: Sinterly never silently changes what your findings say happened.
Connecting
Integrations → Ticketing → Jira → Connect. You provide your Jira site URL, account email, API token and project key. The connection is tested against your Jira before it can be saved, then stored encrypted (AES-256-GCM) and never displayed again.
Outbound: findings to tickets
Scored, open findings without a ticket are created in your Jira project, structured for mixed audiences: a business-impact section for managers, the technical detail and reproduction guidance for the engineer, and effort estimates for sprint planning.
Inbound: status changes need a human
When a ticket's status changes in Jira, Sinterly does not auto-update the finding. The change enters a confirmation queue where the AppSec Lead approves or rejects it. A closed ticket does not automatically mean a fixed vulnerability — someone accountable confirms that, and the confirmation is audited. A daily reconciliation pass catches anything a webhook missed.