Developers
Four ways to connect to xmodo
More than 400 integrations collect evidence and run tests without code. For your own connections, use the API, webhooks, CSV import or MCP server. They are documented in the product and available on every plan with API access.
Connection options
API
Read and write controls, evidence, tests, risks, vendors and findings from your own systems. API keys are limited to your account, permissions follow user roles, and the activity log records every call.
Webhooks
Subscribe to events such as a failed test, expired evidence, a closed finding or an approved AI proposal. Send them to your ticketing, chat or data platform.
CSV import
Import custom frameworks from CSV with the columns Section ID, Section Name, Section Description, Parent Section ID and Control IDs. xmodo rejects duplicate section IDs and shows the errors before it saves anything.
MCP server
The MCP server lets AI agents work with your programme. Agents can list failing tests, fetch a control's evidence and draft a mapping for review. A named person must approve each agent proposal before it enters the programme.
Agents need approval too
Every proposal an agent makes through the MCP server shows a source and a confidence score. It waits for a named person to approve it, in the same way as the platform's own AI. The activity log records what was proposed, what was accepted and who accepted it. This applies to every agent, and examiners can review it.
Frequently asked questions
Where is the API reference?
The API reference is inside the product, in your account. It shows your keys and the endpoints your role can call. Request access on the contact page and we will set up a sandbox account.
Is there a sandbox?
Yes. We can provide a sandbox account for integration work. It has the same API and webhooks as production.