Pull evidence automatically from APIs, manage collection schedules, and route evidence to the AI analysis pipeline. Full OAuth integrations coming Q3 2026.
🗄️
Supabase
Database Security
⚪ Not pulled
Checks RLS, SSL, auth settings, org members Criteria: CC6.1, CC6.3, CC6.4, CC7.1, CC6.6 Last pulled:Never
🌐
Netlify
Hosting & Deployment
⚪ Not pulled
Checks HTTPS, deploy history, team access, env vars Criteria: CC8.1, CC6.2, CC6.7, CC6.8 Last pulled:Never
🔥
Cloudflare
WAF & Network Security
⚪ Not pulled
Checks WAF, SSL mode, min TLS, email security (SPF/DMARC/DKIM) Criteria: CC6.6, CC6.7, CC7.1 Last pulled:Never
User list, 2FA enforcement, suspended accounts Criteria: CC6.1, CC6.2, CC6.4, CC6.5 Last pulled:Never Requires Google Workspace + service account
🤖
Anthropic API
AI Security Controls
✅ Always available
API key storage, server-side routing, ZDR, BYOLLM, logging Criteria: CC6.8, CC6.7, CC2.3, CC7.2, C1.1 Last pulled:Never No credentials needed — checks own config
📥 1 document imported from connector — ready to analyse
🔄 Working Now — API Pull Connector
Generic REST Connector
Enter any REST API endpoint that returns JSON or text. The response is previewed here and can be imported as evidence into the AI annotation pipeline.
📅 Evidence Collection Schedules
⏳ Loading schedules…
🟢 Live Connectors — Pull Evidence Directly from APIs
🔐
Okta
User access listings, MFA status, deprovisioning events, system audit logs
🟢 Live
Active user listing
Deprovisioned users
System audit log (last 100 events)
☁️
AWS IAM
IAM users, credential report, access key rotation, attached policies
🟢 Live
⚠️ AWS IAM requires SigV4 request signing, which needs server-side AWS SDK support not available in serverless edge functions. Option A: Download your IAM credential report from AWS Console → IAM → Credential report and import it using the Generic REST connector above or Evidence Intelligence directly. Option B: Contact support for dedicated AWS integration setup.
Requires an IAM user with ReadOnlyAccess policy. Credentials entered below are stored only in your browser session.