GRC Oversight

Connect your stack. Evidence collects itself.

The tools already know whether your controls are alive. GRC Oversight connects to them, pulls the proof, and keeps the audit trail current without the screenshot scramble.

0

Connectors

0

Categories

0

Evidence checks

Evidence switchboard

Real catalog entries, grouped by signal

188 total
AWSSecurity
Cisco MerakiSecurity
CrowdStrike FalconSecurity
DatadogData
DigitalOceanCloud
GitHubData
Google WorkspaceSecurity
Microsoft Entra IDIdentity
OktaSecurity
ServiceNowInbound

Free public scanner

The front door gets graded before the buyer even talks to you.

GRC Oversight includes a free, no-login website trust scan: TLS, headers, DNS and email hygiene, cookies, limited exposure, and accessibility. Passive checks only.

1

TLS

Certificate, expiry, trust chain, protocol, cipher

2

Headers

HSTS, CSP, X-Frame-Options, Referrer Policy

3

DNS

SPF, DMARC, CAA, DNSSEC signals

4

Accessibility

Rendered-page axe findings by impact

5

Cookies

Secure, HttpOnly, SameSite, consent behavior

6

Exposure

Limited checks for public .git, .env, security.txt

1Password Business
AbuseIPDB
ADP Workforce Now
AlienVault
Amazon S3 bucket exports
Anthropic (Admin API)
Asana
Ashby
Auth0
AWS
Azure Blob storage exports
Azure DevOps
Backblaze B2 exports
BambooHR
Better Stack
BI/reporting webhooks
Bitbucket
Box
BreezyHR
Brevo
Brex
Buildkite
Carbon Black (VMware Carbon Black Cloud)
Checkr

An evidence pipeline with receipts, not theater

Connectors do more than decorate a landing page. They feed tests, findings, trust pages, questionnaires, and framework maps. Filter and search our catalog live.

All Available Connectors

188 active

The catalog is the bait. The evidence pipeline is the weapon.

Connectors feed our unified graph, mapping the same evidence to requirements across 15+ frameworks.

01

Authorize read-only

Connect with least privilege and encrypted credentials. OAuth appears only where the provider path is configured.

02

Sync evidence

Workers collect system posture, users, tickets, devices, or configuration on a schedule instead of on page load.

03

Normalize signals

Each connector turns provider-specific data into evidence assets, checks, findings, and provenance.

04

Prove controls

One evidence source can satisfy requirements across SOC 2, ISO 27001, HIPAA, PCI, and internal controls.

Directory truth

Every connector, working today.

Every entry in the catalog is a real, working connector you can enable right now.

0

Connectors

Live entries in the catalog, each backed by a real implementation.

0

Categories

Identity, cloud, code, security, HR, ticketing, and more.

0

Evidence checks

Distinct checks these connectors run to generate audit evidence.

The fine print, without the fog machine

Yes. Every entry in the directory is backed by an actual connector implementation, not a placeholder logo. Some connect natively with OAuth or an API key, others use a prefilled generic HTTP, CSV, or webhook setup — either way, evidence actually flows.

The design target is least-privilege and read-only wherever the provider allows it. Credentials are encrypted at rest and the connector contract is scoped to evidence collection.

Yes. Evidence is normalized into the compliance graph so a single identity, cloud, ticketing, or security source can support requirements across multiple frameworks.

Use the request path or the generic API, CSV, OAuth, and webhook connectors when the source can expose compliance evidence. We do not list unsupported systems as complete native connectors.

Bring your stack. Leave with a proof map.

Bring your tool list and we will separate what is native, what uses REST coverage, and what should come through a template.