Compliance evidence lives in the tools you already run. We pull configuration and access data from them automatically — read-only, on a schedule — so tests stay current without manual screenshots.
Connect evidence-producing systems via API, OAuth, or webhook — plus native evidence connectors.
Receives normalized compliance evidence from approved automation tools such as n8n, Zapier, or Make.
Don't see your tool? Request a connector for evidence coverage.
An integration is not just a logo. It is a read-only pipe that keeps evidence current and feeds the tests that prove your controls.
Connect a system with the least privilege it needs — read-only wherever possible. Credentials are envelope-encrypted; the app's database role cannot read the master key.
A background worker pulls configuration and access data on a cadence, with backoff and caching so we never hammer a provider's API on a page load.
Synced data becomes the input to automated tests. A test reads the live state, produces a pass/fail, and attaches the result as evidence with full provenance.
Because evidence is in the graph, one connected system can satisfy requirements across many frameworks at once — no duplicate screenshots per standard.
We list capability categories and the evidence each one collects. Specific named connectors are published as they ship — we don't show integrations that don't exist yet.
Pull configuration and posture data from your cloud accounts to prove infrastructure controls.
IaaS / PaaS providers and container platforms
Check repository settings and access to prove change-management and code controls.
Git hosting and source-control platforms
Verify how people authenticate to prove access-control and authentication controls.
SSO / IdP and directory services
Reconcile your roster against system access to prove onboarding and offboarding controls.
HRIS and people directories
Confirm device posture to prove endpoint-hardening controls.
Mobile device management platforms
Evidence monitoring and retention to prove detection and logging controls.
Monitoring and log-management tools
Tie change requests and approvals to evidence for change-management controls.
Issue trackers and documentation tools
Bring evidence-producing systems into the graph through our API when there is no off-the-shelf connector.
Internal tools with compliance evidence APIs
Integrations are the variable cost driver, so they are a fair thing to meter. You connect what you need and pay for the connectors you use — while seats stay free and unlimited. Frameworks are the other axis.
Free
Seats
Scoped
Frameworks
Metered
Integrations
Public dollar amounts appear on the pricing page once they're set — we don't fabricate numbers.
Because a logo wall implies connectors that may not exist yet, and we don't publish things that aren't real. We list capability categories and the evidence each one pulls. Specific named connectors appear here as they ship — not before.
The least privilege required, read-only wherever the data allows it. We pull configuration and access metadata to verify controls; we are not in the business of writing to your production systems. Credentials are envelope-encrypted at rest.
On a schedule, not just on demand. A background worker re-syncs each connected system on a cadence with exponential backoff and caching, so drift surfaces continuously between audits rather than only when someone clicks refresh.
Use the custom API path when the system exposes compliance evidence or control state over an API. Tell us what evidence you need and we'll talk through coverage.
Integrations are one of two pricing axes — the variable one. You pay for the connectors you actually use, not per seat. The other axis is frameworks. Seats are free and unlimited. This keeps pricing tied to the real cost driver instead of how many people you invite.
Yes — that's the whole point of the graph. A single connected identity provider proving MFA enforcement can satisfy requirements in SOC 2, ISO 27001, and HIPAA simultaneously, because mapping happens at the requirement level.
Get a guided demo and we'll map your tools to the evidence they can prove.