All integrations
SECURITY INTEGRATION

Nova AI Ops + Trivy.

Open-source container + IaC scan ingest, Basic tier for OSS-first shops.

What you get

Once connected, Trivy telemetry flows into Nova's observability stack: signals join the service map, alerts route through Nova's correlation engine, and incidents tie back to the underlying Trivy resources for root-cause analysis.

How to connect

Two paths depending on your setup:

OAuth (recommended). Click connect in the Nova admin UI, sign in with your Trivy account, scope down to read-only, done. Token rotation is handled automatically.

API key. For Trivy accounts that don't support OAuth or for service-account workflows. Generate the key in Trivy, paste it into Nova's integrations settings, and Nova validates the connection.

What we ingest

Read-only by default: events, metrics, logs, audit data. We do not modify your Trivy configuration without explicit approval through Nova's policy envelope. Write actions (when enabled) go through the agent fleet with a full audit trail.