How to export your data from Jit

Jit does not offer a single 'export all my data' button. You can export your vulnerability/security findings as a CSV from the Backlog page, and export your Software Bill of Materials (SBOM) as a CycloneDX JSON file from the UI (with an optional local Python script to convert that JSON to CSV).

Formats: CSV, JSON (CycloneDX)Plan: Not explicitly plan-gated for the Backlog CSV export in Jit's docs. For SBOM, some report fields are described as requiring 'Premium user privileges' — if you're not a Premium user, that data is omitted from the SBOM report.Role: Not specified in Jit's documentation — any user with access to the Backlog and SBOM pages can trigger these exports.

✓ Verified against Jit's official documentation, June 2026

Step by step

  1. 1Log in to the Jit web app.
  2. 2Go to the Backlog page in the left-hand menu to view all findings across SAST, SCA, secrets detection, IaC scanning, CSPM, DAST, CI/CD security, and container scanning.
  3. 3Optional: apply filters or select a custom view to narrow down the findings list before exporting.
  4. 4Click the Export CSV button in the top right corner of the Backlog page to download your findings as a CSV file.
  5. 5In the left menu, select SBOM. If SBOM hasn't been activated yet, click Activate and wait for the scan to run.
  6. 6Download the SBOM report from the Jit UI; it is provided in the CycloneDX JSON format.
  7. 7If you need CSV instead of JSON, download the cyclonedx-to-csv.py script, save your exported SBOM JSON locally, and run the script from a terminal with python3 to convert it.

What the export includes

  • ✓Backlog CSV: per-finding data such as location, priority score, finding name, first-detected date, resolution status, finding type, CVSS severity, and ignored/false-positive flag.
  • ✓SBOM (CycloneDX JSON): component/library details, dependencies and sub-dependencies, known vulnerabilities per component, license types, and links to documentation/project URLs.
  • ✓SBOM-to-CSV script output: component name, version, package URL (purl), type, publisher, group, description, licenses, CPE, and author.

What it doesn't include

  • ✗Account, user, and team/role data.
  • ✗Integration configurations (e.g. GitHub/GitLab connections, Jira/Linear/Shortcut ticketing setup, SIEM forwarding rules).
  • ✗Audit logs.
  • ✗Source code or repository content.
  • ✗The finding detail panel's full context graph (risk factor relationships) — only the tabular Backlog columns are included in the CSV.
  • ✗Custom views/saved filters themselves (only the resulting finding list can be exported).
  • ✗Full SBOM detail if you're not a Premium user — those fields are left out of the report.

Before you start

  • ⚠There's no native 'Export CSV' button for SBOM — you must download the CycloneDX JSON first, then run a separate local Python script to get a CSV.
  • ⚠SBOM scans run daily and the report is only updated after each scan, so an export reflects the last scan, not real-time state.
  • ⚠Some SBOM report fields require Premium user privileges; without them, that information simply won't appear in your exported report.
  • ⚠The Backlog export is a direct, immediate CSV download (no async job/email) — the docs describe clicking Export CSV as starting the download right away.
  • ⚠Jit's docs don't describe a bulk/account-level export covering integrations, audit logs, or settings — only findings (Backlog) and SBOM are documented as exportable.

Where to take your data

Free and cheaper tools that can take a Jit export. See all Jit alternatives →

Jit's Backlog CSV and SBOM JSON are reference exports, not an import file Snyk consumes directly. Reconnect your repos in Snyk and let it re-scan for SCA/SAST findings; use the CycloneDX SBOM JSON as an offline reference to cross-check which vulnerabilities and components were previously tracked in Jit.

Trivy

Trivy can scan a CycloneDX SBOM file for known vulnerabilities (trivy sbom <file>), so you can feed the SBOM JSON exported from Jit's UI directly into Trivy to get an equivalent vulnerability view without re-scanning from scratch.

Dependabot

Dependabot doesn't import external findings; enable Dependabot alerts/security updates on your GitHub repos and use the exported Backlog CSV as a checklist to confirm previously known SCA vulnerabilities are now tracked.

Exporting from Jit: common questions

Can I export all my Jit data in one go?+

No. Jit's documentation only describes two separate exports: a CSV of Backlog findings and an SBOM report (CycloneDX JSON, optionally converted to CSV with a local script). There's no single full-account export.

What format is the Jit SBOM export in?+

CycloneDX JSON. If you need CSV, you have to download a Python script from Jit's docs and run it locally against the JSON file you exported.

Does the Backlog CSV export include everything shown in the UI?+

It includes the standard Backlog columns (location, priority, name, first detected, resolution, type, severity, ignored status). The deeper finding-detail context graph isn't part of the CSV — you'd need to copy that from the finding's detail panel individually.

Do I need a paid/Premium plan to export data from Jit?+

The Backlog CSV export isn't described as plan-restricted in Jit's docs. The SBOM report does note that some fields require Premium user privileges and are omitted otherwise.

Can I export Jit's integration settings or audit logs?+

Jit's export documentation doesn't cover integration configurations or audit logs — only Backlog findings and SBOM data are documented as exportable.

Will my exported SBOM stay up to date after I leave Jit?+

No. SBOM scans run daily and the report only reflects the most recent scan at the time you download it, so treat it as a snapshot, not a live feed.

Sources

This guide was written from Jit's own documentation and checked against it in June 2026. If a step has changed, the official page wins.