Ticketing

TrustVendor + Jira

Jira is the most widely used issue tracker in engineering and security teams. TrustVendor creates Jira issues automatically when signals fire — so vendor risk findings land in the same queue as your other security work.

How data flows

When a signal exceeds a configured severity threshold, TrustVendor creates a Jira issue in a project of your choice with the signal description, evidence link, and suggested remediation.

How to set up

  1. 1 In TrustVendor, navigate to Settings > Alerting > Jira.
  2. 2 Authenticate with your Jira workspace.
  3. 3 Select the target project and issue type.
  4. 4 Configure severity thresholds and which vendors to route.
  5. 5 Optionally map TrustVendor severity to Jira priority.

Common questions

Can I close a Jira issue and have TrustVendor acknowledge the signal?
Yes. A two-way sync is available: closing the Jira issue in a configured resolution state marks the TrustVendor signal as acknowledged.
How does TrustVendor signal severity map to Jira issue priority?
By default, critical maps to Jira's Highest, high to High, medium to Medium, and low to Low. The mapping is configurable in TrustVendor under Settings > Alerting > Jira, so teams that use custom Jira priority schemes can align it to their workflow without modifying the integration code.
Can I scope Jira issue creation to specific vendors or vendor groups rather than all monitored vendors?
Yes. Routing rules in TrustVendor let you filter by vendor group, data class (for example, only vendors handling PHI), or signal type. A common configuration is to send breach_notification and compliance_change signals for all vendors to Jira while routing lower-severity signals to Slack only, keeping the Jira backlog focused on actionable findings.
Does TrustVendor create a new Jira issue for every signal occurrence, or does it deduplicate?
TrustVendor deduplicates at the signal level using a dedupe_key that combines the vendor, signal type, and a content fingerprint. If the same underlying condition fires again before the existing signal is resolved, TrustVendor updates the last_seen timestamp rather than creating a second issue. A new Jira issue is only created when a genuinely new signal is raised.
Can existing Jira issues be retrospectively imported when first connecting TrustVendor?
TrustVendor does not import historical Jira issues, but it does backfill its own open signal history into the integration. Signals that were already open at the time of connection are pushed to Jira as new issues during the initial sync, so your backlog reflects all active vendor risk findings from day one of the connection.
Book a demo See API pricing