Evidence Fabric
230+ evidence sources woven into a continuous stream of compliance proof. Cloud APIs, SaaS connectors, AI browser automation, and document ingestion — evidence that gathers itself.
Cloud Scanning
Automated security checks across AWS, Azure, GCP. Misconfigs mapped directly to framework controls.
SaaS Connectors
Pull compliance data from Jira, ServiceNow, Okta, GitHub, and 68+ more. Zero-code setup.
AI Browser Automation
AI navigates any web app like an auditor — captures screenshots, configs, and structured data as secure evidence.
Document Ingestion
Ingest policies, architecture docs, IaC templates. PDF, DOCX, YAML, Terraform, JSON, and more.
Type to filter across all categories
Amazon Web Services
85 servicesIAM
Identity policies, roles, MFA, access keys
S3
Bucket policies, encryption, public access, versioning
EC2
Security groups, EBS encryption, metadata, IMDSv2
CloudTrail
Audit logging, trail config, log file validation
RDS
Database encryption, backups, public access, patching
Lambda
Function policies, VPC config, runtime, code signing
KMS
Key management, rotation, policies, grants
GuardDuty
Threat detection, findings status, detector config
Config
Configuration rules, compliance status, recorder
VPC
Network ACLs, flow logs, peering, endpoints
EKS
Cluster config, RBAC, network policies, secrets
ECS
Task definitions, networking, secrets, logging
ECR
Image scanning, lifecycle policies, encryption
CloudFront
HTTPS enforcement, WAF association, geo restrictions
CloudWatch
Log groups, metric alarms, retention policies
Secrets Manager
Secret rotation, access policies, encryption
DynamoDB
Encryption, backup, PITR, access policies
SNS
Topic encryption, access policies, subscriptions
SQS
Queue encryption, access policies, DLQ config
API Gateway
Authorization, throttling, WAF, logging
Cognito
User pool policies, MFA enforcement, password rules
CloudFormation
Stack policies, drift detection, termination protection
Security Hub
Findings aggregation, standards compliance
Inspector
Vulnerability findings, network reachability
ACM
Certificate management, expiry, validation
EFS
File system encryption, access points, policies
ElastiCache
Encryption in transit/at rest, auth tokens
Redshift
Cluster encryption, audit logging, public access
Route 53
DNSSEC, query logging, health checks
SageMaker
Notebook encryption, VPC, IAM roles
AI Services
Model access policies, guardrails, VPC config
WAF / WAFv2
Web ACLs, rules, rate limiting, logging
Network Firewall
Firewall policies, stateful rules, logging
OpenSearch
Domain encryption, access policies, VPC
SSM
Parameter store, patch compliance, inventory
Step Functions
Workflow encryption, logging, IAM roles
Backup
Backup plans, vault lock, recovery points
Organizations
SCPs, account policies, delegated admin
Macie
Sensitive data discovery, classification
Access Analyzer
External access findings, policy validation
CodeBuild
Build encryption, VPC, privileged mode
Kinesis
Stream encryption, data retention
Glue
Job encryption, catalog security, VPC
EMR
Cluster encryption, logging, security config
ELB / ALB
SSL policies, access logging, WAF integration
Auto Scaling
Launch templates, health checks, scaling policies
AppSync
API auth, logging, WAF, field-level access
Athena
Workgroup encryption, query result encryption
Shield
DDoS protection, advanced protections
SES
Email auth (DKIM, SPF), identity policies
EventBridge
Event bus policies, archive, rules
Firehose
Delivery stream encryption, destination config
Neptune
Graph DB encryption, IAM auth, audit logs
MQ
Broker encryption, audit logging, auth
FSx
File system encryption, backups, access
DAX
Cluster encryption, IAM policies
Direct Connect
Connection encryption, virtual interfaces
DMS
Replication encryption, endpoint security
Glacier
Vault lock, access policies, encryption
Microsoft Azure
30+ servicesEntra ID (Azure AD)
Conditional access, MFA, privileged roles
Virtual Machines
Disk encryption, extensions, network security
Storage Accounts
Encryption, access keys, network rules, HTTPS
Key Vault
Key rotation, access policies, soft delete
SQL Database
TDE, auditing, threat detection, firewall
Network Security Groups
Inbound/outbound rules, flow logs
App Service
HTTPS enforcement, auth, TLS version
Azure Monitor
Diagnostic settings, log analytics, alerts
Defender for Cloud
Security posture, recommendations, alerts
AKS
Cluster config, RBAC, network policies
Cosmos DB
Encryption, network isolation, access keys
Azure Functions
Auth, HTTPS only, managed identity
Azure Firewall
Rules, threat intelligence, DNS proxy
Azure Policy
Compliance state, assignments, initiatives
Service Bus
Encryption, access policies, network rules
Container Registry
Image scanning, encryption, network access
Virtual Network
Subnets, peering, DDoS protection, service endpoints
Redis Cache
Encryption, non-SSL port, firewall rules
PostgreSQL / MySQL
SSL enforcement, backup retention, firewall
Activity Log
Audit logging, retention, export config
Application Gateway
WAF policies, SSL termination, routing
Logic Apps
Managed identity, access control, diagnostics
Front Door
WAF, HTTPS redirect, custom domains
Sentinel
SIEM rules, connectors, incidents
Google Cloud Platform
25+ servicesCloud IAM
Roles, service accounts, org policies
Compute Engine
Instance metadata, firewall rules, encryption
Cloud Storage
Bucket IAM, encryption, versioning, public access
GKE
Cluster security, network policies, workload identity
Cloud SQL
Encryption, SSL enforcement, backups, public IP
Cloud KMS
Key rotation, access control, HSM backing
Cloud Logging
Audit logs, retention, sinks, metrics
VPC
Firewall rules, flow logs, private Google access
Cloud Functions
IAM invoker, VPC connector, ingress settings
BigQuery
Dataset access, encryption, audit logging
Cloud Run
Ingress, IAM invoker, VPC connector
Pub/Sub
Encryption, IAM policies, dead lettering
Cloud Armor
WAF rules, DDoS protection, rate limiting
Security Command Center
Findings, asset inventory, misconfigurations
Artifact Registry
Container scanning, access control
Secret Manager
Secret versioning, IAM, rotation
Cloud DNS
DNSSEC, managed zones, logging
Dataflow
Streaming encryption, service account
Cloud Spanner
IAM, encryption, backup config
Memorystore
Auth, encryption in transit, VPC
Load Balancing
SSL policies, Cloud Armor integration
Org Policy
Constraints, inheritance, boolean policies
Other Cloud & Platform Providers
20+ servicesKubernetes
RBAC, network policies, pod security, secrets
Microsoft 365
Exchange, Teams, SharePoint, DLP policies
GitHub
Branch protection, code scanning, secrets, SSO
Google Workspace
Admin policies, sharing settings, 2SV, groups
Oracle Cloud
Compartments, policies, networking, encryption
Alibaba Cloud
RAM, OSS, security groups, ActionTrail
Cloudflare
WAF, DNS, SSL, access policies, DDoS
MongoDB Atlas
Encryption, network access, auditing
Terraform / IaC
IaC scanning, misconfig detection, policy-as-code
SaaS Connectors
68+ toolsIdentity & Access Management
Okta
Enterprise SSO, MFA, lifecycle management
Auth0
Developer-first identity platform
Ping Identity
Enterprise identity security
CyberArk
Privileged access management
JumpCloud
Directory-as-a-service
Keycloak
Open-source IAM (self-hosted)
Ticketing & Change Management
Jira Cloud Available
Change tickets, incidents, project roles
ServiceNow Available
Enterprise ITSM and change management
Freshservice
Mid-market ITSM platform
PagerDuty
Incident management and response
Linear
Modern startup issue tracking
Asana
Project tracking for teams
Zendesk
Customer service and ticketing
Monitoring & Logging
Datadog Available
Full-stack observability platform
Splunk
SIEM and log analytics
New Relic
APM and observability
Elastic / ELK
Open-source logging and search
Dynatrace
AI-powered APM
Grafana Cloud
Open-source dashboarding
Sumo Logic
Cloud-native log analytics
Prometheus
Open-source metrics and alerting
Source Control & CI/CD
GitLab
All-in-one DevOps platform
Bitbucket
Atlassian source control
Azure DevOps
Microsoft DevOps platform
Jenkins
CI/CD automation server
CircleCI
SaaS-native CI platform
Argo CD
GitOps for Kubernetes
Vulnerability Management
Qualys
Enterprise vulnerability scanning
Tenable
Network vulnerability management
Rapid7 InsightVM
Risk-based vulnerability management
CrowdStrike Spotlight
Endpoint vulnerability assessment
Snyk
Developer security (code/container/IaC)
Wiz
Agentless cloud security
Endpoint Protection
CrowdStrike Falcon
EDR/XDR platform
SentinelOne
Autonomous EDR
Microsoft Defender
M365-native endpoint protection
Palo Alto Cortex XDR
Network + endpoint security
Carbon Black
Enterprise EDR
Backup & Disaster Recovery
Veeam
Hybrid backup and DR
Commvault
Enterprise data protection
Rubrik
Zero-trust data security
Cohesity
Data management platform
HR & Security Training
KnowBe4
Security awareness training
Workday
Enterprise HCM
BambooHR
SMB HR platform
Rippling
Startup/SMB HR + IT
Email & Collaboration
Slack
Team messaging security
Zoom
Video conferencing security
Mimecast
Email security gateway
Document & Knowledge
Confluence Available
Policy pages and attachments
SharePoint Online Available
Document libraries via Graph API
Amazon S3 Available
Pull compliance documents from buckets
Notion
Modern team knowledge base
Google Drive
Cloud document storage
Box
Enterprise content management
Secrets & Encryption
HashiCorp Vault
Secrets management and data protection
AI Browser Automation
Unlimited targetsEvidence from any web application
AI navigates web applications like a human auditor — accessing configuration pages, capturing screenshots, and extracting structured data. Works with any web app, even those without APIs. No integration engineering required.
Evidence is captured as secure, auditable bundles with full provenance metadata.
Example targets
Admin consoles
Cloud dashboards
SaaS settings pages
Legacy systems
Internal tools
Vendor portals
Security consoles
Any web UI
Document Ingestion
13+ formatsPolicies, reports, certificates
DOCX
Word documents, SOPs, procedures
PPTX
Architecture presentations
XLSX / CSV
Spreadsheets, data exports, inventories
HTML
Web pages, exported content
TXT / Markdown
Plain text docs, READMEs
JSON
API responses, config exports
YAML
Kubernetes manifests, CI configs
Terraform (.tf)
Infrastructure as Code templates
CloudFormation
AWS IaC templates (JSON/YAML)
PNG / JPG
Screenshots, architecture diagrams
Don't see your source?
We add new evidence sources continuously. AI browser automation can connect to any web application today — no integration needed.