🔌 Evidence Connector Framework
Pull evidence automatically from APIs, manage collection schedules, and route evidence to the AI analysis pipeline. Full OAuth integrations coming Q3 2026.
🔄 Working Now — API Pull Connector
Generic REST Connector

Enter any REST API endpoint that returns JSON or text. The response is previewed here and can be imported as evidence into the AI annotation pipeline.

📅 Evidence Collection Schedules
⏳ Loading schedules…
🟢 Live Connectors — Pull Evidence Directly from APIs
Okta
User access listings, MFA status, deprovisioning events, system audit logs
🟢 Live
  • Active user listing
  • Deprovisioned users
  • System audit log (last 100 events)
AWS IAM
IAM users, credential report, access key rotation, attached policies
🟢 Live
⚠️ AWS IAM requires SigV4 request signing, which needs server-side AWS SDK support not available in serverless edge functions. Option A: Download your IAM credential report from AWS Console → IAM → Credential report and import it using the Generic REST connector above or Evidence Intelligence directly. Option B: Contact support for dedicated AWS integration setup.

Requires an IAM user with ReadOnlyAccess policy. Credentials entered below are stored only in your browser session.
  • IAM users list
  • IAM credential report
  • IAM policies attached to users
GitHub
Organisation members, repository access, outside collaborators, admin users
🟢 Live
  • Organisation members
  • Repository access list
  • Outside collaborators
  • Admin users
Azure AD (Microsoft Entra)
All users, sign-in logs, guest accounts, MFA registration status
🟢 Live

Requires a service principal with Microsoft Graph API permissions: User.Read.All, AuditLog.Read.All, Reports.Read.All

  • All users
  • Sign-in logs (last 100)
  • Guest accounts
  • MFA registration status
🚀 Coming Soon — Cloud Integrations
🔵
Google Workspace
Admin audit log, user provisioning, sharing settings, 2FA enforcement
Q4 2026
🔌 All Supported Data Sources
Identity & Access
🔐
Okta
MFA, SSO, user lifecycle, access policies
Live API
🔷
Azure AD / Entra
Conditional access, MFA, privileged identity
Live API
🔵
Google Workspace
Admin audit log, user provisioning, 2FA
Q4 2026
🪟
Active Directory
Domain users, GPO, OU structure, privileged groups
Upload
🔑
CyberArk (PAM)
Privileged account vault, session recordings, safe policies
Upload
🏓
Ping Identity
SSO federation, MFA, access policies
Upload
Cloud & Infrastructure
☁️
AWS IAM
IAM policies, CloudTrail, Security Hub, GuardDuty
Live API
🔷
GCP
IAM, Cloud Audit Logs, Security Command Center
Q4 2026
🛡️
Microsoft Defender for Cloud
Secure Score, recommendations, cloud workload protection
Q4 2026
🌐
Cloudflare
WAF, DDoS, Zero Trust access, DNS
Upload
Code & DevOps
🐙
GitHub
Branch protection, secret scanning, dependabot, CODEOWNERS
Live API
🦊
GitLab
SAST, DAST, dependency scanning, merge controls
Q3 2026
📋
Jira
Vulnerability tickets, remediation sprints, risk register
Upload
🔧
Azure DevOps
Pipeline security, branch policies, work items
Upload
Security Tools
🦅
CrowdStrike
Endpoint detection, threat intelligence, vulnerability management
Upload
🛡️
Microsoft Defender
Endpoint protection, Secure Score, threat analytics
Upload
🔍
Qualys
Vulnerability scan reports, asset inventory, patch status
Upload
📊
Splunk
SIEM alerts, log coverage, incident timeline
Upload
🎯
Rapid7 InsightVM
Vulnerability assessments, remediation tracking
Upload
HR & Offboarding
👥
Workday
Employee records, joiner/mover/leaver data, org structure
Upload
🎋
BambooHR
Employee lifecycle, onboarding checklists, terminations
Upload
💼
ADP
Payroll, employee status, access entitlements
Upload
Network
🔥
Palo Alto NGFW
Firewall policies, threat prevention, URL filtering
Upload
☁️
Zscaler
Zero trust network access, web proxy, DLP
Upload
🌐
Cisco (ISE / Umbrella)
Network access control, DNS security, segmentation
Upload