How to export your data from Jit
Jit does not offer a single 'export all my data' button. You can export your vulnerability/security findings as a CSV from the Backlog page, and export your Software Bill of Materials (SBOM) as a CycloneDX JSON file from the UI (with an optional local Python script to convert that JSON to CSV).
✓ Verified against Jit's official documentation, June 2026
Step by step
- 1Log in to the Jit web app.
- 2Go to the Backlog page in the left-hand menu to view all findings across SAST, SCA, secrets detection, IaC scanning, CSPM, DAST, CI/CD security, and container scanning.
- 3Optional: apply filters or select a custom view to narrow down the findings list before exporting.
- 4Click the Export CSV button in the top right corner of the Backlog page to download your findings as a CSV file.
- 5In the left menu, select SBOM. If SBOM hasn't been activated yet, click Activate and wait for the scan to run.
- 6Download the SBOM report from the Jit UI; it is provided in the CycloneDX JSON format.
- 7If you need CSV instead of JSON, download the cyclonedx-to-csv.py script, save your exported SBOM JSON locally, and run the script from a terminal with python3 to convert it.
What the export includes
- ✓Backlog CSV: per-finding data such as location, priority score, finding name, first-detected date, resolution status, finding type, CVSS severity, and ignored/false-positive flag.
- ✓SBOM (CycloneDX JSON): component/library details, dependencies and sub-dependencies, known vulnerabilities per component, license types, and links to documentation/project URLs.
- ✓SBOM-to-CSV script output: component name, version, package URL (purl), type, publisher, group, description, licenses, CPE, and author.
What it doesn't include
- ✗Account, user, and team/role data.
- ✗Integration configurations (e.g. GitHub/GitLab connections, Jira/Linear/Shortcut ticketing setup, SIEM forwarding rules).
- ✗Audit logs.
- ✗Source code or repository content.
- ✗The finding detail panel's full context graph (risk factor relationships) — only the tabular Backlog columns are included in the CSV.
- ✗Custom views/saved filters themselves (only the resulting finding list can be exported).
- ✗Full SBOM detail if you're not a Premium user — those fields are left out of the report.
Before you start
- ⚠There's no native 'Export CSV' button for SBOM — you must download the CycloneDX JSON first, then run a separate local Python script to get a CSV.
- ⚠SBOM scans run daily and the report is only updated after each scan, so an export reflects the last scan, not real-time state.
- ⚠Some SBOM report fields require Premium user privileges; without them, that information simply won't appear in your exported report.
- ⚠The Backlog export is a direct, immediate CSV download (no async job/email) — the docs describe clicking Export CSV as starting the download right away.
- ⚠Jit's docs don't describe a bulk/account-level export covering integrations, audit logs, or settings — only findings (Backlog) and SBOM are documented as exportable.
Where to take your data
Free and cheaper tools that can take a Jit export. See all Jit alternatives →
Jit's Backlog CSV and SBOM JSON are reference exports, not an import file Snyk consumes directly. Reconnect your repos in Snyk and let it re-scan for SCA/SAST findings; use the CycloneDX SBOM JSON as an offline reference to cross-check which vulnerabilities and components were previously tracked in Jit.
Trivy
Trivy can scan a CycloneDX SBOM file for known vulnerabilities (trivy sbom <file>), so you can feed the SBOM JSON exported from Jit's UI directly into Trivy to get an equivalent vulnerability view without re-scanning from scratch.
Dependabot
Dependabot doesn't import external findings; enable Dependabot alerts/security updates on your GitHub repos and use the exported Backlog CSV as a checklist to confirm previously known SCA vulnerabilities are now tracked.
Exporting from Jit: common questions
Can I export all my Jit data in one go?+
No. Jit's documentation only describes two separate exports: a CSV of Backlog findings and an SBOM report (CycloneDX JSON, optionally converted to CSV with a local script). There's no single full-account export.
What format is the Jit SBOM export in?+
CycloneDX JSON. If you need CSV, you have to download a Python script from Jit's docs and run it locally against the JSON file you exported.
Does the Backlog CSV export include everything shown in the UI?+
It includes the standard Backlog columns (location, priority, name, first detected, resolution, type, severity, ignored status). The deeper finding-detail context graph isn't part of the CSV — you'd need to copy that from the finding's detail panel individually.
Do I need a paid/Premium plan to export data from Jit?+
The Backlog CSV export isn't described as plan-restricted in Jit's docs. The SBOM report does note that some fields require Premium user privileges and are omitted otherwise.
Can I export Jit's integration settings or audit logs?+
Jit's export documentation doesn't cover integration configurations or audit logs — only Backlog findings and SBOM data are documented as exportable.
Will my exported SBOM stay up to date after I leave Jit?+
No. SBOM scans run daily and the report only reflects the most recent scan at the time you download it, so treat it as a snapshot, not a live feed.
Sources
This guide was written from Jit's own documentation and checked against it in June 2026. If a step has changed, the official page wins.
Jit head-to-head
More Security tools people are leaving
All Security alternatives →What would you save without Jit?
Pick your team size and see the yearly number.