TLS
Certificate, expiry, trust chain, protocol, cipher
The tools already know whether your controls are alive. GRC Oversight connects to them, pulls the proof, and keeps the audit trail current without the screenshot scramble.
0
Connectors
0
Categories
0
Evidence checks
Evidence switchboard
Real catalog entries, grouped by signal
Free public scanner
GRC Oversight includes a free, no-login website trust scan: TLS, headers, DNS and email hygiene, cookies, limited exposure, and accessibility. Passive checks only.
Certificate, expiry, trust chain, protocol, cipher
HSTS, CSP, X-Frame-Options, Referrer Policy
SPF, DMARC, CAA, DNSSEC signals
Rendered-page axe findings by impact
Secure, HttpOnly, SameSite, consent behavior
Limited checks for public .git, .env, security.txt
Connectors do more than decorate a landing page. They feed tests, findings, trust pages, questionnaires, and framework maps. Filter and search our catalog live.
Connectors feed our unified graph, mapping the same evidence to requirements across 15+ frameworks.
01
Connect with least privilege and encrypted credentials. OAuth appears only where the provider path is configured.
02
Workers collect system posture, users, tickets, devices, or configuration on a schedule instead of on page load.
03
Each connector turns provider-specific data into evidence assets, checks, findings, and provenance.
04
One evidence source can satisfy requirements across SOC 2, ISO 27001, HIPAA, PCI, and internal controls.
Directory truth
Every entry in the catalog is a real, working connector you can enable right now.
0
Connectors
Live entries in the catalog, each backed by a real implementation.
0
Categories
Identity, cloud, code, security, HR, ticketing, and more.
0
Evidence checks
Distinct checks these connectors run to generate audit evidence.
Yes. Every entry in the directory is backed by an actual connector implementation, not a placeholder logo. Some connect natively with OAuth or an API key, others use a prefilled generic HTTP, CSV, or webhook setup — either way, evidence actually flows.
The design target is least-privilege and read-only wherever the provider allows it. Credentials are encrypted at rest and the connector contract is scoped to evidence collection.
Yes. Evidence is normalized into the compliance graph so a single identity, cloud, ticketing, or security source can support requirements across multiple frameworks.
Use the request path or the generic API, CSV, OAuth, and webhook connectors when the source can expose compliance evidence. We do not list unsupported systems as complete native connectors.
Bring your tool list and we will separate what is native, what uses REST coverage, and what should come through a template.