---
title: "SecurityScorecard Integration"
description: "Connect AI agents to SecurityScorecard. Agents assess any company's cyber posture by domain, pull grades, factor scores, and issue findings, benchmark against industry peers, manage portfolios, and generate reports."
url: https://flowrunner.ai/integrations/securityscorecard
date_modified: 2026-08-01T02:40:32-07:00
---

# SecurityScorecard

[Identity & Security](https://flowrunner.ai/integrations/category/identity-security)

Connect AI agents to SecurityScorecard. Agents assess any company's cyber posture by domain, pull grades, factor scores, and issue findings, benchmark against industry peers, manage portfolios, and generate reports.

[Verified](https://flowrunner.ai/integrations/verified "What does verified mean?") · 15 actions · API key · available

[SecurityScorecard website](https://securityscorecard.com/) · [Platform Documentation](https://securityscorecard.readme.io/reference) · Capability data verified 2026-07-14

1.  A scheduled vendor-monitoring run starts against a portfolio
2.  Get Portfolio Companies returns each vendor's current grade and score
3.  Agent compares each grade against the alert threshold
4.  Get Company Issues by Type pulls findings for any vendor below threshold
5.  Agent confirms the drop is sustained, not a single-day blip
6.  The risk team receives the vendor, grade, and critical findings
7.  The risk owner decides whether to escalate the vendor for review

## What This Integration Enables

Agents continuously monitor a vendor's or partner's security grade and alert the team when it drops, enrich a new-vendor onboarding flow with an automated third-party risk assessment, benchmark a company's factor scores (patching cadence, network security, DNS health) against its industry, build and maintain portfolios of monitored companies for ongoing supply-chain risk reporting, and generate detailed or summary security reports and prioritized remediation plans on a schedule. A company carries an overall grade and score plus scores across ten risk factors, and Get Company Factor Scores reveals which issue types apply so Get Company Issues by Type can pull detailed findings. Report generation is asynchronous and returns a report id for later download. The connector covers the company, portfolio, industry, and reporting surface; the surrounding flow decides which monitoring runs automatically and where a risk owner decides what a score drop should trigger.

### Without FlowRunner

**Point-in-time assessments**: A vendor's security is checked once at onboarding and rarely revisited

**Manual grade pulls**: Someone logs into the rating tool to read each vendor's current grade by hand

**No industry context**: A vendor's factor scores are read in isolation, with no peer benchmark

### With FlowRunner

**Continuous monitoring**: Get Portfolio Companies reads every vendor's current grade on a routine

**Threshold alerts**: A grade that drops below the threshold surfaces the vendor and its findings automatically

**Peer benchmarking**: Get Industry Factor Scores puts a vendor's factor scores in industry context

## Use Case Scenarios

### Continuous vendor monitoring with threshold alerts

On a schedule, the agent calls Get Portfolio Companies to read every monitored vendor's current grade, compares each against a threshold, and for any vendor that falls below it, calls Get Company Issues by Type to pull the critical findings. It alerts the security team with the domain, current grade, and affected assets through [Slack](https://flowrunner.ai/integrations/slack). The team learns about a vendor's posture slipping when it happens, not at the next annual review.

### New-vendor risk assessment at onboarding

When a new vendor enters the onboarding flow, the agent calls Get Company Score and Get Company Factor Scores for the vendor's domain, then Get Industry Factor Scores to benchmark those factors against the vendor's industry. The onboarding record carries an automated third-party risk assessment with peer context, so the vendor is evaluated on evidence rather than a reputation guess.

### Supply-chain risk reporting

On a routine, the agent calls Get Portfolio Companies and logs each company's current grade and score into a vendor-risk tracking sheet with [Google Sheets](https://flowrunner.ai/integrations/google-sheets). The risk team gets a standing, dated record of the portfolio's posture, and a vendor trending downward over several runs surfaces as an exception rather than a one-day reading.

## Human-in-Loop Highlight

Deciding what a grade drop should trigger is the judgment call that belongs to a person, because pausing a vendor or opening a formal risk review has contractual and operational consequences a score does not settle on its own. The agent does the monitoring on its own: it reads the portfolio's grades, detects a drop below threshold, confirms the drop is sustained across runs, and pulls the critical findings. Before anything escalates, it stops and asks the risk owner through Slack: "Vendor \[domain\] dropped from \[grade\] to \[grade\] over \[period\], with \[count\] critical findings in \[factor\]. Open a formal risk review, request remediation, or note and continue monitoring?" The risk owner decides. The agent watches the posture; the person owns the response.

Agent processes routinely

Detects drop below threshold

Clear match Continues automatically

Ambiguous Routes to human via Slack

Human decides

Agent resumes with decision

## Agent Capabilities

15 actions

### Company Posture

6

-   **Get Company Score** Retrieves a company's overall grade (A to F) and score (0 to 100) by primary domain.
-   **Get Company Factor Scores** Retrieves per-factor scores such as patching cadence, network security, and DNS health.
-   **Get Company Issues by Type** Returns detailed issue findings for a given issue type.
-   **Get Company Historical Scores** Pulls a company's overall score trend over time.
-   **Get Company Historical Factor Scores** Pulls a company's per-factor score trend over time.
-   **Get Company Information** Reads company profile information for a domain.

### Portfolios

5

-   **Get Portfolio Companies** Lists the companies in a portfolio with their grades. Powers continuous monitoring.
-   **Create Portfolio** Creates a portfolio for ongoing supply-chain risk reporting.
-   **Add Company to Portfolio** Adds a company to a monitored portfolio.
-   **Remove Company from Portfolio** Removes a company from a portfolio.
-   **List Portfolios** Lists the portfolios of monitored companies.

### Industry Benchmarking

2

-   **Get Industry Score** Retrieves an industry's benchmark score.
-   **Get Industry Factor Scores** Retrieves an industry's per-factor benchmark scores for peer comparison.

### Reports

2

-   **Generate Report** Queues a detailed or summary security report asynchronously and returns a report id.
-   **Get Score Plan** Retrieves a prioritized remediation plan for a company.

## Frequently Asked Questions

### What can FlowRunner do with SecurityScorecard?

FlowRunner agents can run Get Company Score, Get Company Factor Scores, and Get Company Historical Scores in SecurityScorecard, plus 12 more actions.

### Does connecting SecurityScorecard to FlowRunner require OAuth?

No. SecurityScorecard connects to FlowRunner with an API key, no OAuth flow required.

### Can SecurityScorecard trigger a FlowRunner workflow automatically?

SecurityScorecard doesn't currently expose triggers in FlowRunner. It connects as an action step inside workflows started by another trigger.

**Work at SecurityScorecard?** This integration exposes SecurityScorecard to AI agents on every FlowRunner plan, including through MCP, at no cost to you. [See what FlowRunner offers integration partners](https://flowrunner.ai/integrations/partners), including how to keep this page current.

---
Markdown version of https://flowrunner.ai/integrations/securityscorecard. Site index: https://flowrunner.ai/llms.txt
