Security Ecosystem
Application Security
Surf AI correlates SAST/DAST findings to the developer, repo, and service owner and drives each issue to completion through automated follow up, escalation to managers, and ticket lifecycle management.
Snyk
Checkmarx

Veracode

Fortify
Cloud Security
Surf AI ingests CSPM and CNAPP findings and overlays identity, code, and HR context to turn unowned cloud risks into assigned, evidence-backed remediation workflows.

Wiz

Orca Security

Upwind

Crowdstrike Falcon Cloud

Prisma Cloud
Sysdig

Microsoft Defender for Cloud

Aqua Security
Data Security
Surf AI unifies DSPM classifications with identity, HR, and access signals to help understand how data is stored, who has access to it, and to drive the responsible party to remediate the finding.

Cyera

Varonis

BigID

Microsoft Purview

Securiti
Email Security
Surf AI enriches high-risk recipients from the email security system to enrich the context graph and improve security hygiene for these users. The platform ensures that email threats are augmented with user role, manager chain, and recent activity so issues get prioritized response and containment.

Proofpoint

Mimecast

Abnormal Security

Barracuda Networks
Endpoint Security / XDR
Surf AI takes action on EDR/XDR/EPP by notifying device owner and other stakeholders with a custom remediation plan while alerting Security and IT admins during the process.

CrowdStrike

SentinelOne

MS Defender

Tanium

Jamf

Kandji

Sophos
Identity and Access Management
Surf AI ingests data from IdPs, IGA, and PAM platforms and combines configuration with actual usage signals (logins, activity, access patterns) making identity the connective tissue that ties every asset, alert, and remediation workflow back to a real owner.

Microsoft Entra
Okta

SailPoint

Saviynt

Ping Identity

CyberArk

BeyondTrust

Google Workspace

JumpCloud

OneLogin

Delinea

Silverfort
Auth0
Network & SSE
Surf AI correlates SSE policy violations and traffic anomalies with identity and application ownership so network events become actionable cases tied to a person and a system, and helps clean up stale or overly permissive network policies in the process.

Zscaler

Netskope
Cloudflare

Illumio

Cato Networks
Observability
Surf AI ties observability alerts to service ownership, on-call status, and downstream dependencies so signals become assigned cases that get resolved instead of acknowledged.
Datadog
Dynatrace
SIEM
Surf AI feeds SIEMs the ownership and business context they're missing, turning raw alerts into cases that already know who owns the asset, who the user reports to, and what the asset does.
Splunk

Microsoft Sentinel
Elastic
Sumo Logic

Palo Alto Cortex XSIAM

Exabeam

Crowdstrike Falcon Next Gen SIEM
Vulnerability Management
Surf AI takes vulnerability findings and enriches them with ownership context pulled from cloud, code, HR, and ITSM systems, removing the ownership gap that keeps vulnerability management programs from being operationalized at scale.

Tenable
Qualys

Rapid7

Brinqa

Nucleus
WAF & API Security
Surf AI links WAF and API events to the service owner and source repository so blocked attacks and exposed endpoints get routed to the team that ships the affected code.
Cloudflare WAF
Akamai

F5 Networks
AI & Agent Platforms
Surf AI inventories the AI providers, models, and agents in use across the business, maps each to its owner and the systems it can access, and flags excessive permissions or shadow usage for cleanup.

OpenAI
Anthropic
AWS Bedrock
Google Gemini
Cursor
Business Applications
CRM
Surf AI uses CRM data as an authoritative source of customer-facing system ownership and account context, enriching incidents tied to revenue-bearing applications.

Salesforce
HubSpot
Project Management / Issue Tracking
Surf AI links code repositories, CI/CD, and issue trackers to security findings so vulnerabilities resolve as native PRs and tickets owned by the engineer who wrote the code.
GitHub
GitLab
Linear
Asana
ERP
Surf AI pulls ERP-managed business hierarchy, cost center, and vendor data and combines it with usage and access signals to attribute risk to the right business unit, budget owner, and system users.
SAP
Data Systems & Governance
Surf AI connects to data warehouses, lakehouses, and content stores to map data assets, dataset owners, and access patterns into the same graph that powers remediation.
Snowflake
Databricks
Box
Dropbox

Tableau
Notion
HR Systems
Surf AI uses HCM as the authoritative source for employment status, manager chain, and org structure, which is what makes ownership mapping and lifecycle automation actually trustworthy.

Workday

BambooHR
HiBob

Dayforce

Rippling
ADP
Hyperscaler Cloud Platform (IaaS)
Surf AI ingests cloud control plane, tagging, IAM, and usage data to build the asset-to-owner backbone and the access context every cloud security workflow depends on, including who has access, who is using it, and who should not.
AWS
Azure
GCP
Oracle Cloud
IBM Cloud
Ticketing & Communication Apps
Collaboration
Surf AI runs remediation conversations directly inside the collaboration tools, so owners can acknowledge, reassign, or close items without leaving the channel they already work in.

MS Teams

Slack
Zoom
Ticketing
Surf AI orchestrates remediation through ITSM platforms with full context attached to every ticket. The platform drives existing ticket queues to completion through automated follow up and escalation.

ServiceNow
Atlassian Jira
Zendesk

ClickUp
PagerDuty

NinjaOne

Freshservice