Integrations — connect your security stack
10 native connectors pull configuration, identity, endpoint, and vulnerability data from the systems your controls already run on — and attach each artifact to the control it proves. No more quarterly screenshot drills.
Native connectors
Grouped by what they cover. Each connector maps its data to the controls it satisfies.
Cloud configuration
-
AWS ConfigResource configuration state and conformance-pack findings across your AWS accounts.
-
Google Cloud (SCC)Security Command Center findings and asset inventory from Google Cloud.
-
Microsoft AzureResource configuration and Microsoft Defender for Cloud posture findings.
Identity & access
-
OktaUsers, groups, MFA enrollment, and access logs for access-review controls.
-
Google WorkspaceUser and group membership and 2-step verification status.
Endpoint & EDR
-
CrowdStrike FalconEndpoint agent health, coverage, and detection posture.
-
Microsoft DefenderEndpoint protection status and alert posture.
Vulnerability scanning
-
QualysVulnerability scan results and host findings.
App & dependency
-
GitHub (Dependabot)Dependency alerts and code-scanning results from your repositories.
-
SnykOpen-source, container, and infrastructure-as-code vulnerabilities.
How evidence sync works
Credentials encrypted with AES-256-GCM at rest. Decrypted only at sync time.
Integrations — frequently asked questions
How are integration credentials secured?
Integration credentials are encrypted with AES-256-GCM at rest and decrypted only inside the sync worker, at the moment a sync runs.
Can I sync on a schedule or on demand?
Both — connectors sync on a schedule you set and can also be triggered on demand, with each artifact timestamped and attached to the control it supports.
What if the tool I use isn’t listed?
You can attach evidence manually from any source via the upload UI, or use the public REST API at /v1/* with a workspace-scoped token from Settings → API tokens. Outbound event webhooks are on the roadmap; today, workflow events mirror to Slack via an incoming webhook per company.
Which frameworks does the evidence count toward?
Because controls are cross-mapped, a single piece of evidence can satisfy the equivalent control across PCI DSS, ISO 27001, SOC 2, NIST CSF and more.