GRC Oversight

Platform

8
  • GRC Oversight

    Governance, risk, and compliance automation from one workspace.

  • AI assistant

    Ask questions about your compliance program with tenant-scoped context.

  • Free ChatGRC & questionnaire drafter demo

    Try a free public ChatGRC and questionnaire-drafter demo grounded in general framework and glossary content. No account needed.

  • Interactive product sandbox

    Try the risk heat map, control toggles, and ChatGRC on a mock sample organization. No login, no real data.

  • MCP developer docs

    Per-tool reference, token setup, and copy-paste MCP client config for Claude and Cursor.

  • MCP for GRC data

    Connect AI clients to tenant-scoped controls, evidence, risks, and questionnaires.

  • Product tour

    A guided look at the GRC Oversight product surfaces.

  • Why GRC Oversight

    How GRC Oversight approaches evidence, pricing, scanners, and AI access.

Products

8
  • Access reviews

    Run documented user access reviews with owners and evidence history.

  • Compliance automation

    Map controls to evidence and reuse work across frameworks.

  • Privacy operations

    RoPA, a data flow register, DSR tracking with an SLA clock, and DPIAs linked to your risk register.

  • Products

    Compliance automation, risk, trust center, questionnaires, vendor risk, and access reviews.

  • Questionnaire automation

    Draft security questionnaire answers from approved evidence and policies.

  • Risk management

    Track risks, owners, mitigations, and compliance alignment.

  • Trust center

    Publish a public security profile and manage sensitive trust documents.

  • Vendor risk

    Assess vendors, collect documents, and track third-party risk.

Public demo

33
  • Demo access reviews

    Review periodic user access campaigns with reviewer decisions and audit-ready evidence history.

  • Demo AI governance

    Inspect an AI system inventory with risk classification, data categories, ownership, and human oversight.

  • Demo API tokens and MCP

    Preview API token and MCP setup for connecting AI clients to tenant-scoped compliance data.

  • Demo assistant

    Try a sample ChatGRC workspace that answers from fictional controls, evidence, policies, and risks.

  • Demo auditor view

    See the read-only auditor workspace for compliance posture, evidence, and audit trail review.

  • Demo billing

    Review the sample subscription, active frameworks, connected integrations, and unlimited-seat model.

  • Demo board report

    Review a quarterly security posture pack with risk, control health, findings, and vendor status.

  • Demo compliance

    Explore framework readiness, mapped controls, tests, and reusable evidence across compliance programs.

  • Demo compliance snapshots

    Browse point-in-time compliance snapshots with content hashes for audit packet references.

  • Demo dashboard

    Explore a fictional GRC Oversight workspace with compliance, monitoring, evidence, risk, and trust data.

  • Demo data flows

    Map data movement between systems with source, destination, data categories, and safeguards.

  • Demo data subject requests

    Track data subject request intake, ownership, status, and the 30-day SLA clock.

  • Demo device posture

    Inspect endpoint posture from sample MDM data, including encryption, compliance state, and check-in recency.

  • Demo DPIA

    Review data protection impact assessments linked to risks, vendors, and processing activities.

  • Demo exceptions

    Track time-boxed control and policy waivers with expiry-driven review and finding creation.

  • Demo findings

    Review centralized findings linked to controls, risks, policies, vendors, and remediation owners.

  • Demo governance meetings

    Review meeting records, decisions, attendees, and action items kept as governance evidence.

  • Demo incidents and BC/DR

    Track security incidents, operational incidents, post-mortems, and business-continuity exercises.

  • Demo integrations

    See connected evidence sources and integration health across cloud, identity, HR, code, and monitoring systems.

  • Demo members

    Invite and manage sample workspace members with unlimited seats.

  • Demo obligations

    Track jurisdictional legal and regulatory obligations separately from framework controls.

  • Demo people

    Explore HR roster, security-awareness training, and offboarding evidence in a sample workspace.

  • Demo policies

    Author, version, publish, and collect acknowledgements for sample compliance policies.

  • Demo policy guardian

    Find policy-to-control and policy-to-evidence gaps before review cycles drift.

  • Demo questionnaires

    Draft security questionnaire answers from approved sample evidence, policies, and controls.

  • Demo reviews due

    See recurring reviews across risks, policies, controls, vendors, access reviews, exceptions, and assets.

  • Demo risk register

    Score, prioritize, and track sample risks on a likelihood-by-impact grid.

  • Demo RoPA

    Browse GDPR Article 30 records of processing activities for a fictional organization.

  • Demo scans and monitoring

    Add sample domains, inspect scan history, and compare drift across public website trust scans.

  • Demo settings

    Explore organization, account, and security settings in the public demo workspace.

  • Demo trust center

    Publish a sample trust profile and manage public, NDA-gated, and private trust documents.

  • Demo vendor risk

    Review vendor inventory, criticality, document status, and third-party risk ratings.

  • Demo webhooks

    Configure sample outbound webhooks for GRC Oversight events.

Solutions

6
  • Defense contractors

    Prepare CMMC and defense supplier evidence without inventing claims.

  • Enterprise

    Coordinate controls, evidence, risk, and trust workflows across larger teams.

  • Growing teams

    Scale compliance coverage as frameworks and integrations expand.

  • Healthcare

    Run a HIPAA Security Rule risk analysis and manage safeguards, BAAs, and breach-notification readiness.

  • Solutions

    GRC workflows for startups, growing teams, enterprise, and defense contractors.

  • Startups

    Get audit-ready without adding per-seat compliance costs.

Services

5

Frameworks

16
  • CMMC

    Cybersecurity Maturity Model Certification for the U.S. defense base

  • Cross-framework overlap visualizer

    See which controls and tests are genuinely shared across frameworks in the live evidence graph.

  • DORA

    EU regulation on digital operational resilience for finance

  • EU AI Act

    EU regulation establishing risk-based rules for AI systems

  • FedRAMP

    U.S. program for cloud services used by federal agencies

  • Frameworks

    Security, privacy, AI, resilience, and audit frameworks supported by the evidence model.

  • GDPR

    EU regulation governing personal data protection

  • HIPAA

    U.S. rules for protecting health information

  • ISO/IEC 27001

    International standard for information security management

  • ISO/IEC 27701

    Privacy information management extension to ISO 27001

  • ISO/IEC 42001

    International standard for AI management systems

  • NIS2

    EU directive on cybersecurity for essential and important entities

  • NIST AI RMF

    NIST framework for managing AI risk

  • PCI DSS

    Security standard for handling payment card data

  • SOC 2

    Trust Services Criteria for service organizations

  • SOX

    U.S. law requiring internal control over financial reporting

Integrations

194
  • 1Password Business integration

    Collect 1Password Business user roster, group membership, and vault access-control evidence via the read-only Business API.

  • AbuseIPDB integration

    Collect IP address reputation, blacklist, and block check evidence from AbuseIPDB API v2.

  • ADP Workforce Now integration

    Collect ADP Workforce Now worker and organizational data through the read-only ADP HR/Payroll API to support employee-lifecycle and access-review evidence.

  • AlienVault integration

    Collect AlienVault USM Anywhere alarms and events, as well as OTX threat intelligence pulse evidence through read-only API endpoints.

  • Amazon S3 bucket exports integration

    Upload a CSV export of Amazon S3 buckets mapping bucketName, publicAccessBlockEnabled, and defaultEncryptionEnabled.

  • Anthropic (Admin API) integration

    Collect organization member, workspace, and API-key inventory as read-only AI-governance compliance evidence through the Anthropic Admin API. Scoped strictly to organization/access evidence -- not model usage content or conversation data. Requires an Admin API key (distinct from a regular API key), sent as the `x-api-key` header alongside an `anthropic-version` header. Note: Anthropic's Admin API requires the `anthropic-version` header on every request, which this generic HTTP connector's single configurable auth-header does not cover by default -- flag this as a known limitation.

  • Asana integration

    Audit Asana workspace members and projects as read-only work-management access-review and inventory evidence.

  • Ashby integration

    Audit Ashby ATS/recruiting accounts and job posting inventory as read-only access-review and hiring-pipeline evidence.

  • Auth0 integration

    Audit MFA factors, breached-password & brute-force protection, and tenant settings.

  • AWS integration

    Audit S3 public-access/encryption and IAM user MFA.

  • Azure Blob storage exports integration

    Upload a CSV export of Azure Blob storage containers mapping containerName, publicAccess, and encryptionStatus.

  • Azure DevOps integration

    Collect Azure DevOps project, repository, and pipeline evidence through organization-scoped APIs.

  • Backblaze B2 exports integration

    Upload a CSV export of Backblaze B2 buckets mapping bucketId, bucketName, and bucketType.

  • BambooHR integration

    Collect BambooHR employee roster, status, and onboarding/offboarding date evidence through company-scoped API endpoints.

  • Better Stack integration

    Push log-retention, uptime-monitor, alerting-coverage, and access evidence from Better Stack Logs/Uptime through an approved export or automation path -- Better Stack's public API surface for team/member access evidence is not confidently documented, so this is a webhook (push) template rather than a bespoke read connector.

  • BI/reporting webhooks integration

    Push report availability, data freshness, or dashboard evidence from BI systems.

  • Bitbucket integration

    Collect workspace and repository evidence from Bitbucket Cloud APIs.

  • Box integration

    Collect Box user, group, and enterprise event-log evidence through the read-only Box Platform API to support access-review and data-handling audits.

  • BreezyHR integration

    Audit BreezyHR recruiting-team user accounts and open position inventory as read-only ATS access-review and hiring-pipeline evidence.

  • Brevo integration

    Collect account info and verified-sender inventory as read-only 'who can send as us' access-review evidence through the Brevo (Sendinblue) API. Scoped strictly to access evidence, not campaign or contact data. Brevo's confirmed team/user-management endpoints are gated behind its Corporate/multi-account plan tier and are not confidently documented for standard accounts, so 'who has admin' evidence is NOT covered here -- track it manually until confirmed.

  • Brex integration

    Audit Brex team-member roster and roles as finance-system access-review evidence (who can move money).

  • Buildkite integration

    Collect pipeline and build-run inventory as read-only CI/CD compliance evidence through the Buildkite REST API.

  • Carbon Black (VMware Carbon Black Cloud) integration

    Collect device/endpoint coverage and alert evidence as read-only EDR compliance signal through the VMware Carbon Black Cloud API. Substitute your CBC console hostname for <your-cbc-host> and your org key for <org-key> in each endpoint path.

  • Checkr integration

    Collect Checkr background-check report status and package/order configuration as pre-employment screening compliance evidence.

  • CI/CD and deploy webhooks integration

    Push build, deploy, approval, and required-check evidence from CI/CD systems.

  • CircleCI integration

    Collect CircleCI account, context, and project environment-variable evidence through API v2.

  • Cisco Meraki integration

    Collect Meraki organization, network, and device inventory plus admin 2FA status through the read-only Meraki Dashboard API.

  • Cisco Secure Endpoint integration

    Collect endpoint/computer coverage and detection-event evidence as read-only EDR compliance signal through the Cisco Secure Endpoint (AMP) API.

  • Cisco Umbrella integration

    Collect Cisco Umbrella DNS security policy, destination-list/blocklist, and roaming-client deployment evidence through the read-only Umbrella API.

  • Clerk integration

    Audit Clerk user MFA enrollment, banned/locked status, and organization admin membership.

  • ClickUp integration

    Audit ClickUp workspace members and spaces as read-only project-management access-review and inventory evidence.

  • Cloudflare integration

    Collect Cloudflare zone security settings, firewall/WAF rule configuration, and account member access as DNS/edge-security compliance evidence.

  • Cloudways integration

    Connect Cloudways API v2 by entering the current API base URL and read-only evidence endpoints from the Cloudways API Playground.

  • Codefresh integration

    Collect pipeline and workflow-run inventory as read-only CI/CD compliance evidence through the Codefresh API.

  • Comms and alerting webhooks integration

    Push escalation, alert-delivery, incident-notification, or on-call evidence from alerting systems.

  • Confluence integration

    Collect Atlassian Confluence space membership, permission, and audit-log evidence through the read-only Confluence Cloud REST API.

  • Coralogix integration

    Collect Coralogix alert, parsing-rule, and outbound-webhook configuration evidence through documented read-only HTTP endpoints.

  • CouchDB integration

    Audit Apache CouchDB cluster membership, admin configuration, anonymous-access settings, and per-database security docs through read-only REST calls.

  • CrateDB integration

    Audit CrateDB user inventory, privilege grants, and cluster node health through read-only SQL system queries.

  • CrowdStrike Falcon integration

    Audit sensor coverage, reduced-functionality and stale hosts, and detections.

  • CSV / file upload integration

    Upload a CSV export (users, devices, access grants). Each row becomes evidence; an optional column drives the pass/fail verdict.

  • Database inventory exports integration

    Upload database role/grant, TLS, audit-log, or configuration exports.

  • Databricks integration

    Collect cluster configuration, job, and workspace-user inventory as read-only compliance evidence through the Databricks REST API (self-hosted workspace). Substitute your workspace URL for the <your-workspace> placeholder in the base URL.

  • Datadog integration

    Audit monitor coverage, log retention, audit-trail readability, and users.

  • Deel integration

    Audit Deel global payroll/EOR worker roster as read-only HR access-review and offboarding evidence.

  • DigiCert integration

    Collect certificate order and expiry-date inventory as read-only PKI/TLS-lifecycle compliance evidence through the DigiCert CertCentral API.

  • DigitalOcean integration

    Collect DigitalOcean cloud-infrastructure evidence (droplet/resource inventory, firewall configuration, and team member access) for cloud configuration and access-review compliance.

  • Discord integration

    Collect guild (server), member, and role inventory as read-only compliance evidence through the Discord bot REST API, for orgs using Discord as an internal comms/alerting channel.

  • Docs and e-sign exports integration

    Upload policy-signoff, document, attestation, or e-signature exports.

  • DocuSign integration

    Collect DocuSign envelope, template, user, and account evidence through read-only REST API endpoints.

  • Dropbox Business integration

    Collect Dropbox Business team member, group, and activity-log evidence through the read-only Dropbox Business API for access-review audits.

  • Dropbox Sign integration

    Collect Dropbox Sign (HelloSign) account, team, and signature-request evidence through the read-only API to support e-signature and document-control audits.

  • DuckDB integration

    Audit a DuckDB instance exposed via an HTTP query endpoint (e.g. a MotherDuck-compatible or self-hosted SQL-over-HTTP proxy), not a local file. Checks attached-database read-only posture, external access / unsigned extension settings, and loaded extension inventory through read-only SQL introspection.

  • Duo Security integration

    Collect Duo Security MFA evidence (user enrollment status, authentication device inventory, and administrator access) for multi-factor authentication compliance.

  • Dynatrace integration

    Collect monitored-entity and problem/alert inventory as read-only observability compliance evidence through the Dynatrace Environment API v2.

  • Elastic Security / Kibana integration

    Collect detection-rule and alert inventory as read-only SIEM compliance evidence through the Kibana/Elastic Security API (self-hosted or Elastic Cloud).

  • F5 BIG-IP integration

    Collect F5 BIG-IP system readiness, licensing, provision status, and LTM virtual server configurations via the iControl REST API.

  • Fleet integration

    Collect Fleet (osquery) host inventory, policy compliance, and user access evidence through the read-only Fleet REST API for device-posture and endpoint-management controls.

  • Fortinet FortiGate integration

    Collect firewall configuration, policies, system status, and system logs from Fortinet FortiGate devices via the FortiOS REST API.

  • Freshdesk integration

    Collect read-only Freshdesk agent, role, and group evidence through the Freshdesk API v2 for access-review evidence. This is not a general ticketing/task-automation connector.

  • Freshservice integration

    Collect Freshservice agent, requester, and audit-log evidence through the read-only Freshservice ITSM API to support access-review and change-management audits.

  • Generic e-Signatures integration

    Collect signature agreement, template, user, and transaction log evidence from standard e-signature REST endpoints.

  • Generic transport/protocol evidence integration

    Push normalized evidence from GraphQL, SFTP, SSH, LDAP, Kafka, AMQP, MQTT, or another bridge.

  • Gitea integration

    Collect repository, branch, collaborator, organization, and pull-request evidence through the Gitea API.

  • GitGuardian integration

    Collect GitGuardian secrets-detection evidence (incident inventory, source/perimeter coverage, and team member access) for secret-scanning compliance attestations.

  • GitHub integration

    Audit repository branch protection, visibility, and member 2FA.

  • GitLab integration

    Audit group 2FA enforcement, protected branches, MR approvals, and CI/CD secrets.

  • Google BigQuery integration

    Collect dataset, table, and job-history inventory as read-only compliance evidence through the BigQuery REST API. Substitute your GCP project ID for the <project-id> placeholder in each endpoint path.

  • Google Cloud integration

    Audit project IAM, service-account keys, Cloud Storage, and log sinks.

  • Google Workspace integration

    Audit users, 2-step verification, super admins, and OAuth app grants.

  • Grafana integration

    Collect user, organization, datasource, and alert-rule inventory as read-only observability compliance evidence through the Grafana HTTP API (self-hosted or Grafana Cloud).

  • Greenhouse integration

    Audit Greenhouse recruiter/hiring-manager accounts and live job postings as read-only HR/ATS access-review and hiring-pipeline evidence.

  • Gusto integration

    Collect Gusto HR roster and termination evidence through documented read-only API endpoints.

  • HackerOne integration

    Collect HackerOne program, report, and member evidence through the read-only HackerOne API to support vulnerability-management and bug-bounty audits.

  • HashiCorp Vault integration

    Collect HashiCorp Vault authentication method, policy, and audit-device configuration evidence through the read-only HTTP API for secrets-management and access-control controls.

  • Heroku integration

    Collect Heroku deployment-platform evidence (team member access, app inventory, and config-var/add-on posture) for change-management and access-review attestations.

  • Hetzner Cloud integration

    Collect server, firewall, network, and SSH-key inventory through the Hetzner Cloud API.

  • HiBob integration

    Audit HiBob HR roster (active/terminated workers, hire and termination dates) as read-only access-review and offboarding evidence.

  • HR and recruiting exports integration

    Upload roster, hiring, termination, department, or recruiting exports from Tier 2 HR systems.

  • HTTP / REST endpoint integration

    Point at any evidence-producing JSON API: base URL + auth header + read-only endpoints with JSON-path assertions. Each endpoint becomes evidence.

  • HubSpot integration

    Collect HubSpot user, team, and audit-log evidence through the read-only CRM API for access-review and change-tracking controls.

  • IBM QRadar integration

    Collect security offenses and asset inventory as read-only SIEM compliance evidence through the IBM QRadar REST API (self-hosted).

  • Imperva WAF integration

    Collect Imperva Cloud WAF site inventory and status/WAF-mode posture through the documented Imperva Cloud Security API. Customer supplies the account's API ID/key as the Authorization header value; site-specific security-rule evidence requires a documented site ID and is left customer-configured.

  • Inbound webhook integration

    Push normalized compliance evidence to us from approved n8n, Zapier, Make, or CI workflows. We mint a secret URL; POST normalized JSON and it lands as evidence.

  • incident.io integration

    Collect incident-response records and responder roster as BC/DR and SOC 2 CC7 evidence.

  • Integrations

    Connect cloud, identity, code, HR, observability, and security systems for evidence.

  • Intercom (Access Review) integration

    Audit Intercom workspace admin roster as access-review evidence (who has admin access). Scoped to admin/access evidence only, not conversation or contact data.

  • Intruder integration

    Collect open vulnerability issues and scanned-target inventory as read-only compliance evidence through the Intruder API.

  • Jamf integration

    Collect Jamf device inventory and compliance evidence through read-only Jamf Pro API endpoints.

  • Jenkins integration

    Collect Jenkins job, node, controller, and plugin evidence through read-only JSON API endpoints.

  • Jira integration

    Collect Jira project and change-ticket evidence through read-only Jira REST endpoints.

  • JumpCloud integration

    Collect user, group, and managed-system evidence from JumpCloud read APIs.

  • Justworks integration

    Audit Justworks PEO/HR employee roster as read-only access-review and offboarding evidence: active worker hire dates and terminated worker termination dates.

  • Kandji integration

    Collect Kandji device and blueprint evidence through read-only Kandji API endpoints.

  • KnowBe4 integration

    Collect security awareness training and phishing simulation evidence from KnowBe4 read APIs.

  • LDAP / Active Directory integration

    On-prem/hybrid directory bind: user roster, group membership, disabled/stale accounts, and password-policy attributes for access-review + deprovisioning evidence. NOT YET IMPLEMENTED — config/registration only; see the TODO in ldap.ts for the missing client-library dependency.

  • Lever integration

    Audit Lever recruiting/hiring team accounts and published job postings as read-only access-review and offboarding evidence.

  • Linear integration

    Collect Linear team and issue evidence through the Linear GraphQL API.

  • Linode (Akamai) integration

    Collect instances, firewalls, users, and account-event evidence through Linode API v4.

  • LogRocket integration

    Push normalized frontend session, issue, performance, or alert evidence from LogRocket through an approved export or automation path.

  • Logsnag integration

    Receive normalized incident, alert, monitor, or log-source evidence derived from Logsnag event streams.

  • Looker integration

    Collect Looker user, group, role, dashboard, and Look metadata through documented Looker API 4.0 read endpoints.

  • Mercury integration

    Collect cash-account inventory as read-only finance-system evidence through the Mercury API. Mercury's public API does not document a team-member/role or money-movement-permission listing endpoint as of this writing, so 'who can move money' access-review evidence is NOT covered here -- track it manually (e.g. via Mercury's dashboard team-permissions screen) until Mercury documents one.

  • Metabase integration

    Collect Metabase user, group, collection, database, dashboard, and card inventory through documented read-only API endpoints.

  • Microsoft Azure integration

    Collect Azure subscription and posture evidence through read-only Azure Resource Manager endpoints.

  • Microsoft Azure Monitor integration

    Collect diagnostic-settings and activity-log configuration as read-only logging/audit-trail compliance evidence through the Azure Resource Manager API.

  • Microsoft Defender integration

    Collect Microsoft Defender alert, incident, secure score, and device evidence through Microsoft Graph security endpoints.

  • Microsoft Entra ID integration

    Collect directory, role, and policy evidence through Microsoft Graph read-only endpoints.

  • Microsoft Intune integration

    Collect managed-device, enrollment-summary, and compliance-policy evidence through Microsoft Graph Intune endpoints.

  • Microsoft SQL Server integration

    Audit SQL Server login inventory, mixed-mode authentication, and database inventory through read-only system-catalog queries.

  • Microsoft Teams integration

    Collect Microsoft Teams team/channel roster and membership evidence via Microsoft Graph as collaboration access-control documentation.

  • Microsoft Teams integration

    Collect team, channel, and membership inventory as read-only compliance evidence through the Microsoft Graph Teams API.

  • Mimecast integration

    Collect Mimecast email security policy, threat, and account audit evidence through the read-only Mimecast API to support email-security and phishing-defense audits.

  • MISP integration

    Collect threat-intel attribute and event exports as read-only evidence through the self-hosted MISP API.

  • Monday.com integration

    Collect Monday.com board, item, update, and user evidence through the Monday.com GraphQL API. Use only for change, incident, access-request, or approval evidence.

  • MongoDB Atlas integration

    Collect organization, project, cluster, database-user, and access-list inventory through the MongoDB Atlas API v1.0.

  • MongoDB integration

    Audit MongoDB/Atlas authentication status, database inventory, and auth mechanisms through read-only admin commands.

  • MongoDB self-hosted exports integration

    Upload MongoDB user role, network access-list, or configuration exports.

  • MySQL exports integration

    Upload a CSV export of MySQL user privileges, TLS status, or server settings.

  • MySQL integration

    Audit MySQL/MariaDB TLS status, user/auth-plugin inventory, and database inventory through read-only SQL metadata queries.

  • Neon integration

    Audit Neon project inventory, branch protection, and project-sharing (collaborator) access.

  • Netlify integration

    Collect site and deploy inventory as read-only deploy/CI compliance evidence through the Netlify API. Substitute your site ID for the <site-id> placeholder in the deploys endpoint path.

  • Network security webhooks integration

    Push firewall, WAF, DNS security, certificate, or managed-network posture evidence.

  • New Relic integration

    Collect New Relic user roster, authentication domain (SSO) configuration, and alert policy evidence as observability access-control and monitoring documentation.

  • Nightfall.ai integration

    Collect DLP/PII-detection findings and detection-rule inventory as read-only data-loss-prevention compliance evidence through the Nightfall.ai API.

  • Notion integration

    Collect Notion workspace evidence (user/member inventory and page/database content coverage) for documentation and access-review compliance.

  • OAuth2 (generic) integration

    Connect an evidence-producing OAuth2 SaaS via authorization-code flow; read a userinfo/resource endpoint as evidence. Env-gated per provider.

  • Object storage exports integration

    Upload S3-compatible, Azure Blob, GCS, or Backblaze bucket/container exports.

  • Observability webhooks integration

    Push monitor, incident, alert, retention, or log-source coverage evidence.

  • Okta integration

    Audit active users for MFA enrollment and offboarding gaps.

  • OmniHR integration

    Audit OmniHR (APAC HRIS) employee roster as read-only HR access-review and offboarding evidence.

  • OneLogin integration

    Collect user, role, and application-assignment evidence from OneLogin APIs.

  • OpenAI (Admin/Organization) integration

    Collect organization member, project, and API-key inventory as read-only AI-governance compliance evidence through the OpenAI Admin API. Scoped strictly to organization/access evidence, not model usage content or completions data. Requires an Admin API key (distinct from a regular project API key). API keys are listed per-project; substitute your project ID for the <project-id> placeholder in the api-keys endpoint path.

  • OpenCTI integration

    Collect indicator, report, malware, and attack pattern evidence from OpenCTI via read-only GraphQL API queries.

  • Opsgenie integration

    Collect on-call schedules, escalation policies, and team-membership evidence as read-only compliance signal through the Opsgenie REST API. Signl4 is primarily a webhook-receiver product with no meaningful read API; capture Signl4 alerting evidence via the generic comms-alerting-webhook template instead of a bespoke connector.

  • Oracle Database integration

    Audit Oracle Database account status, audit/login parameters, and DBA role grants through ORDS read-only SQL metadata queries.

  • PagerDuty integration

    Audit escalation policies, on-call coverage, and incident-response readiness.

  • Personio integration

    Audit Personio HR roster (active/inactive employees, hire and termination dates) as read-only access-review and offboarding evidence.

  • Postgres integration

    Audit Postgres security settings, role inventory, and database inventory through read-only SQL metadata queries.

  • PostHog integration

    Audit PostHog organization member roles (admin/owner) and 2FA enrollment as observability access-review evidence.

  • Power BI integration

    Collect Power BI workspace, report, dashboard, dataset, and workspace-user inventory through documented REST API read endpoints.

  • Qovery integration

    Audit Qovery organization member roster and roles as deploy/hosting access-review evidence.

  • Qualys integration

    Collect Qualys asset, detection, and vulnerability scan evidence through read-only Qualys API endpoints.

  • QuestDB integration

    Audit QuestDB table durability (WAL), partitioning hygiene, and server configuration through read-only HTTP query endpoints.

  • Rapid7 InsightVM integration

    Collect Rapid7 InsightVM asset and vulnerability evidence through read-only API endpoints.

  • Recorded Future integration

    Collect threat intelligence alerts, IP, domain, and hash risk lists from Recorded Future API.

  • Redis integration

    Audit Redis authentication, TLS, persistence, and ACL posture through read-only RESP commands.

  • Render integration

    Collect service and workspace-owner inventory as read-only deploy/hosting compliance evidence through the Render REST API v1. Render's public API does not document a team-member/role-listing endpoint as of this writing, so member-role access-review evidence is NOT covered here -- track it manually until Render documents one, or reclassify to a bespoke connector if that changes.

  • Resend integration

    Collect API-key and verified-domain inventory as read-only 'who can send as us' access-review evidence through the Resend API. Scoped strictly to access evidence, not campaign or contact data. Resend's public API does not document a team-member/role-listing endpoint as of this writing, so 'who has admin' evidence is NOT covered -- track it manually until Resend documents one.

  • Rippling integration

    Audit HR roster, employment status, and offboarding dates.

  • Salesforce (Security & Access) integration

    Collect user roster, profile/permission-set assignments, and login-history evidence as read-only access-review compliance signal through the Salesforce REST API. Scoped to security/identity evidence only -- not sales, marketing, or customer-record data.

  • Salesforce integration

    Collect Salesforce user access, permission set, and login-history evidence through the read-only REST API for access-review and account-monitoring controls.

  • Secrets-management exports integration

    Upload vault, secret inventory, rotation, or access-review exports from secrets-management systems.

  • Security tooling webhooks integration

    Push vulnerability, EDR, SIEM, threat-intel, DLP, or training evidence from Tier 2 security tools.

  • SecurityScorecard integration

    Collect SecurityScorecard vendor risk ratings, factor scores, and issue findings through the read-only SecurityScorecard API to support third-party risk audits.

  • SendGrid (Access Review) integration

    Audit SendGrid teammate roster (who has admin), pending invites, and verified senders (who can send as us). Scoped to access evidence only, not campaign/contact data.

  • SentinelOne integration

    Collect SentinelOne agent and threat evidence through management-console API endpoints.

  • Sentry integration

    Collect Sentry organization member roles, project error-issue inventory, and audit log evidence as error-monitoring access and change-control documentation.

  • ServiceNow integration

    Collect change-request and incident evidence through ServiceNow Table API endpoints.

  • Shopify (Security & Access) integration

    Collect staff-account roster and API access-scope inventory as read-only access-review compliance evidence through the Shopify Admin API. Scoped strictly to security/access evidence, not storefront, product, order, or customer data.

  • Shortcut integration

    Audit Shortcut member accounts and projects as read-only project/issue-tracking access-review and workspace inventory evidence.

  • SignNow integration

    Collect SignNow document, template, user, and folder evidence through read-only REST API endpoints.

  • SigNoz integration

    Push log-retention, trace/metric-access, and alerting-coverage evidence from a self-hosted or SigNoz Cloud deployment -- SigNoz has no confidently-documented public admin/access-management REST API, so this is a webhook (push) template rather than a bespoke read connector.

  • Slack integration

    Collect Slack workspace, user, and channel evidence through read-only Slack Web API endpoints.

  • Snowflake integration

    Collect Snowflake access, role, and configuration evidence through the documented Snowflake SQL API.

  • Snyk integration

    Audit open vulnerabilities by severity, license issues, and scan recency.

  • SonarQube / SonarCloud integration

    Collect SonarQube/SonarCloud static-analysis evidence (quality gate status, project inventory, and security hotspot findings) for SAST coverage attestations.

  • Splunk integration

    Collect Splunk index, data-input, and saved-search evidence through management API endpoints.

  • Stripe (Security Config) integration

    Collect webhook-endpoint configuration and account security settings as read-only PCI-adjacent compliance evidence through the Stripe API. Scoped strictly to security configuration, not payment, billing, or customer financial data, and NOT a substitute for a real PCI DSS assessment. Note: Stripe does not expose API-key listing/rotation status via the API for security reasons, so key-management evidence must be tracked manually.

  • Stripe integration

    Collect Stripe team member roles and API key configuration evidence through the read-only Stripe API for access-review and credential-hygiene controls.

  • Supabase integration

    Collect project, database-role, and auth-settings evidence as read-only compliance signal through the Supabase Management API.

  • SurrealDB integration

    Audit SurrealDB namespace/database configuration and table permissions through read-only SurrealQL introspection queries.

  • Tableau integration

    Collect Tableau Cloud/Server site user, group, project, workbook, and data-source inventory through documented REST API read endpoints.

  • Tailscale integration

    Collect Tailscale zero-trust network evidence (device inventory, ACL/network policy configuration, and user roles) for network access control compliance.

  • Teamwork integration

    Collect read-only Teamwork project and task evidence for change, incident, access-request, or approval workflows. This is not a general task-automation connector.

  • Tenable.io integration

    Collect Tenable.io vulnerability scan results, asset inventory, and user access/MFA configuration as continuous vulnerability-management evidence.

  • Terraform Cloud integration

    Collect Terraform Cloud IaC evidence (workspace inventory, run/apply history, and organization member access) for infrastructure change-management compliance.

  • TheHive integration

    Collect case and alert inventory as read-only SOC/incident-response compliance evidence through the self-hosted TheHive API.

  • Ticketing, ITSM, and approval exports integration

    Upload change, incident, access-request, or approval exports from Tier 2 ticketing/PM systems. This is not a general task-automation connector.

  • TimescaleDB integration

    Audit TimescaleDB security settings, hypertable compression, and retention policies through read-only SQL metadata queries.

  • Travis CI integration

    Collect repository, build, and environment-variable-config evidence as read-only CI/CD compliance signal through the Travis CI API.

  • Trellix ePO integration

    Collect managed-system and policy-assignment inventory as read-only endpoint-security compliance evidence through the Trellix (McAfee) ePolicy Orchestrator remote API (self-hosted). ePO's remote commands return plain text by convention; append `?:output=json` to request JSON where supported by the deployment.

  • Trello integration

    Audit Trello workspace membership and board inventory as read-only Kanban/task-management access-review and change-management evidence.

  • Twilio integration

    Collect account configuration, verified sender numbers, and usage-record evidence as read-only compliance signal for orgs using Twilio as an SMS/voice alerting channel -- analogous to the Discord/Opsgenie templates. Not intended for general consumer messaging content or customer-communication data.

  • Vercel integration

    Collect Vercel deployment-platform evidence (team member access, project inventory, and environment variable/secret configuration) for change-management and access-review attestations.

  • VirusTotal integration

    Collect file-hash, URL, and IP-reputation lookup results as read-only malware-analysis compliance evidence through the VirusTotal API v3.

  • Vultr integration

    Collect instance, user, network, and account-log evidence through Vultr API v2.

  • Wiz integration

    Collect Wiz cloud security posture findings, vulnerability issues, and configuration compliance results as CSPM evidence via the read-only Wiz API.

  • Workday integration

    Collect Workday worker, organization, role, and termination-feed evidence through customer-configured read-only API endpoints.

  • Wrike integration

    Collect task, folder/project, and contact evidence through the Wrike API v4 for change, access-request, or approval reviews.

  • YouTrack integration

    Audit JetBrains YouTrack user accounts and project inventory as read-only issue-tracker access-review and workspace evidence.

  • Zabbix integration

    Collect host and user inventory as read-only observability compliance evidence through the self-hosted Zabbix JSON-RPC API. Note: Zabbix API is a single JSON-RPC endpoint, not REST resource paths; older Zabbix versions expect the auth token inside the request body/params, while newer versions (6.4+) accept a Bearer auth header -- confirm the customer Zabbix version before configuring the generic connector auth header.

  • Zendesk integration

    Collect Zendesk agent roster, role/permission configuration, and account security policy as support-operations access-control evidence.

  • Zoho Desk integration

    Audit Zoho Desk agent roster and department inventory as read-only helpdesk access-review evidence.

Resources

11

Comparisons

22

Glossary

26
  • Access review

    A periodic, documented check that every user's access to a system is still appropriate for their current role, also called a user access review (UAR).

  • BAA

    Business Associate Agreement: a contract required under HIPAA between a covered entity and any vendor that handles protected health information on its behalf.

  • CAIQ

    Consensus Assessments Initiative Questionnaire: a standardized cloud security questionnaire published by the Cloud Security Alliance, paired with the CSA STAR registry.

  • Continuous monitoring

    Running tests on a schedule so configuration drift surfaces between audits, not at audit time.

  • Control

    An objective within a framework (e.g. SOC 2 CC6.1) that you must satisfy and prove.

  • Control owner

    The named individual accountable for a control's operation and evidence: who an auditor or reviewer would ask if something looks wrong.

  • Cross-mapping

    Reusing one passing test across the multiple frameworks whose requirements it satisfies.

  • DPA

    Data Processing Agreement: a contract required under GDPR (and similar laws) between a data controller and a processor, governing how personal data is handled.

  • Evidence

    The artifact backing a test result, carrying a timestamp, source system, and content hash.

  • FedRAMP

    A U.S. government program standardizing security assessment, authorization, and monitoring for cloud services used by federal agencies.

  • GRC glossary

    Definitions for compliance, risk, trust, and security review terms.

  • HITRUST

    A certifiable framework (the HITRUST CSF) widely used in healthcare that harmonizes controls from HIPAA, ISO 27001, NIST, and other sources.

  • ISMS

    Information Security Management System: the overall management structure (policies, risk process, roles, continual improvement) that ISO 27001 certifies.

  • ISO 27001

    An international standard specifying requirements for an Information Security Management System (ISMS), with certification issued by accredited bodies.

  • MCP

    Model Context Protocol: the open standard that lets AI clients like Claude and Cursor call your tenant's tools.

  • POA&M

    Plan of Action and Milestones: a formal, tracked remediation plan for a known control gap or weakness, with owners and target dates.

  • Requirement

    The finest-grain obligation inside a control: the level at which mapping happens so one test can serve many frameworks.

  • Residual risk

    The risk that remains after controls and mitigations have been applied, as opposed to inherent risk, which is the risk before any mitigation.

  • Security questionnaire

    A form a prospective or existing customer sends asking about your security and compliance practices, often as a gate before signing or renewing a contract.

  • SIG

    Standardized Information Gathering questionnaire: a widely used, standardized third-party risk assessment questionnaire published by Shared Assessments.

  • SOC 2

    An AICPA audit report on a service organization's controls over security, availability, processing integrity, confidentiality, and privacy.

  • SSP

    System Security Plan: a document describing a system's boundaries, the controls it implements, and how each control is satisfied.

  • Test

    An automated or manual check that produces a pass/fail result against a requirement.

  • Trust center

    A public page sharing your security posture and NDA-gated documents to shorten customer reviews.

  • TSC

    Trust Services Criteria: the AICPA criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) that a SOC 2 report is evaluated against.

  • Vendor risk assessment

    The process of evaluating a third-party vendor's security posture (often via their SOC 2 report or a questionnaire) before and during the relationship.

Company

10
  • Changelog

    Product and site updates for GRC Oversight.

  • Contact

    Contact GRC Oversight.

  • Customers

    Customer-facing information without invented logos or claims.

  • Free website trust scan

    Run a passive security, privacy, and accessibility scan for any public website.

  • GRC Oversight: Trust Center

    GRC Oversight's own public trust profile — the same self-serve Trust Center product every customer gets.

  • Platform status

    Current status for the web app, API, scanner, trust center, assistant, and connector surfaces.

  • Pricing

    Build your own plan by frameworks activated and integrations connected, with unlimited seats.

  • Roadmap

    Current and planned product direction.

  • Sitemap

    A human-readable index of public GRC Oversight pages.

  • Trust center

    Public trust and security profile for GRC Oversight.

Security, privacy, and legal

4
  • Privacy

    Privacy policy for GRC Oversight.

  • Scanner policy

    Methodology, scope, and limits for the public website trust scanner.

  • Security

    How GRC Oversight handles security and trust.

  • Terms

    Terms of service for GRC Oversight.