40+ integrations out of the box. Anything else? Bring it.
While other compliance platforms make you wait quarters for a new integration, we built a universal connector engineon top of a 40+ integration catalog — cloud providers, identity, SCM, productivity, observability, ticketing, billing, HR. Plug them in with your existing credentials and start collecting evidence in minutes. And when your stack includes something niche or in-house, you don’t wait for our roadmap. Bring your own API key, your own IAM role, your own scanner output, or your own connector manifest — we’ll evidence it all the same way.
Your compliance evidence, flowing in real-time
Evidence flows automatically from every connected platform into a unified compliance picture. No manual exports. No spreadsheet wrangling. Just continuous, audit-ready data.
The connector list you don’t have to wait for
Every other compliance platform has the same answer when you ask about a tool they don’t support: “It’s on the roadmap.” We have a different answer. Bring your credentials however your vendor gives them to you — we have a path for all four.
BYO API Key
Generate a read-only API key in your vendor’s admin console. Paste it in. We’ll validate the scopes and start collecting evidence in minutes — no OAuth tenant-app review required.
BYO IAM Role
Cloud providers? Don’t hand us long-lived keys. Grant our principal a read-only role via cross-account AssumeRole (AWS), Workload Identity Federation (GCP), or service principal (Azure). Short-lived credentials only.
BYO Scanner Output
Already running Prowler, Checkov, Trivy, or Snyk in your CI? Drag the JSON in. We normalize it into the same evidence format and map findings to SCF controls across every framework you care about.
BYO Connector Manifest
The tool isn’t on our list and isn’t open-source? Write a YAML manifest — endpoints, auth header, capability rules, SCF mapping — and upload it. We validate it against our threat model (egress allow-list, SSRF guard, DNS-rebinding protection) and dry-run probe it against your real vendor before it goes live. The connector list isn’t a list. It’s an architectural promise.
Built-in Integrations
Connect your stack — and anything else
48 integrations supported out of the box (including the BYO upload path). None of them block you — and if your tool isn’t here, write a manifest today.
| Integration | Category | Description | Status |
|---|---|---|---|
AWS | Cloud | IAM, S3, CloudTrail, EC2 | Active |
GCP | Cloud | IAM, Cloud Storage, Audit Logs | Active |
Azure | Cloud | Storage, Activity Logs, RBAC | Active |
DigitalOcean | Cloud | Droplets, Kubernetes, team & spaces | Active |
Oracle Cloud | Cloud | Compute, identity, security zones | Active |
What Integrations Enable
More than data collection—full lifecycle management
Every integration powers continuous security operations across your stack.
Security Scanning
Continuously scan configurations across cloud, code, and productivity platforms
Findings Management
Surface misconfigurations with severity, remediation guidance, and ownership
Workflow Automation
Route findings to the right teams and track remediation through to completion
Evidence Collection
Automatically gather compliance artifacts with full audit trail
Catch misconfigurations before they become incidents
Integrations run continuous security scans across your connected platforms. When someone disables MFA, opens an S3 bucket, or removes branch protection, you'll know within minutes—not months.
- 69+ security controls monitored
- Real-time configuration change detection
- Severity-based prioritization
- Remediation guidance for every finding
Enforce policies directly in your platforms
Don't just detect misconfigurations—fix them. Integrations enable automatic policy enforcement using OPA-generated rules. When policies are published, enforcement happens where the configuration lives.
Route findings to the right people, automatically
Integrations with Slack, Jira, and email mean findings get to the people who can fix them. Set up routing rules based on severity, platform, or ownership. Track remediation from discovery to resolution.
- Slack notifications for critical findings
- Automatic Jira ticket creation
- Escalation rules for overdue items
- Remediation SLA tracking
Compliance evidence that collects itself
Every integration continuously collects compliance artifacts—configuration snapshots, access logs, policy exports. Evidence is mapped to controls and timestamped for auditors. When audit season comes, you're already ready.
- Automatic evidence collection
- Evidence mapped to framework controls
- Full audit trail with timestamps
- One-click auditor pack generation
Know when integrations need attention
Monitor the health of all your integrations in one place. Get alerted when credentials expire, connections fail, or permissions change. Keep your evidence collection running smoothly.
- Real-time connection status
- Credential expiration alerts
- Permission change notifications
- Automatic retry on failures
Ready to connect your stack?
Set up your first integration in minutes.