Notifications

In-app + email + Slack notifications for personal events: findings assigned to you, mentions, scan completions you triggered, integration events.

Notifications vs Alerts

Two different systems, often confused:

  • Alerts — org-wide, severity-driven, routed to shared channels (#sec-alerts Slack, PagerDuty on-call). About new findings, SLA breaches, attacks.
  • Notifications (this page) — personal, action-driven, routed to YOUR channels. About things you specifically need to know.

Personal notification events

Finding assigned to you
Mentioned in finding comment (@you)
Scan you triggered completed
PR gate failed on your PR
Verify-fix result on your fix
API key expired / expiring
Invited to a new org / project
Role changed
Audit log mention of your account

Delivery channels

  • In-app — bell icon top-right; unread counter.
  • Email — to your account email.
  • Slack DM — if you've connected Slack at account level.
  • Browser push — when sectora.io is open in another tab.
  • Mobile push — when the Sectora mobile app is installed.

Configuration

Settings → Notifications. Per-event-type, per-channel toggle. Defaults:

  • Finding assigned → in-app + email + Slack DM
  • Mentioned → in-app + Slack DM
  • Scan completed (your scan) → in-app only
  • PR gate failed → in-app + email
  • Verify-fix result → in-app + Slack DM
  • API key expiring → email (7 days), in-app + email (1 day)
  • Invited to org → email (always)

Quiet hours

Set per-day quiet windows in your local timezone. Non-urgent notifications (e.g. scan completed) hold until after the window; urgent events (Critical findings assigned, API key just expired) ignore quiet hours.

Digest mode

Instead of one notification per event, opt into a digest — single email at configurable time(s) (e.g. 09:00 daily) listing everything since the previous digest. Reduces interruption; useful for non-urgent event types.

What's next