Public site index · 343 pages
Sitemap
A complete index of the GRC Oversight website.
Platform
8- GRC Oversight
Governance, risk, and compliance automation from one workspace.
- AI assistant
Ask questions about your compliance program with tenant-scoped context.
- Free ChatGRC & questionnaire drafter demo
Try a free public ChatGRC and questionnaire-drafter demo grounded in general framework and glossary content. No account needed.
- Interactive product sandbox
Try the risk heat map, control toggles, and ChatGRC on a mock sample organization. No login, no real data.
- MCP developer docs
Per-tool reference, token setup, and copy-paste MCP client config for Claude and Cursor.
- MCP for GRC data
Connect AI clients to tenant-scoped controls, evidence, risks, and questionnaires.
- Product tour
A guided look at the GRC Oversight product surfaces.
- Why GRC Oversight
How GRC Oversight approaches evidence, pricing, scanners, and AI access.
Products
8- Access reviews
Run documented user access reviews with owners and evidence history.
- Compliance automation
Map controls to evidence and reuse work across frameworks.
- Privacy operations
RoPA, a data flow register, DSR tracking with an SLA clock, and DPIAs linked to your risk register.
- Products
Compliance automation, risk, trust center, questionnaires, vendor risk, and access reviews.
- Questionnaire automation
Draft security questionnaire answers from approved evidence and policies.
- Risk management
Track risks, owners, mitigations, and compliance alignment.
- Trust center
Publish a public security profile and manage sensitive trust documents.
- Vendor risk
Assess vendors, collect documents, and track third-party risk.
Public demo
33- Demo access reviews
Review periodic user access campaigns with reviewer decisions and audit-ready evidence history.
- Demo AI governance
Inspect an AI system inventory with risk classification, data categories, ownership, and human oversight.
- Demo API tokens and MCP
Preview API token and MCP setup for connecting AI clients to tenant-scoped compliance data.
- Demo assistant
Try a sample ChatGRC workspace that answers from fictional controls, evidence, policies, and risks.
- Demo auditor view
See the read-only auditor workspace for compliance posture, evidence, and audit trail review.
- Demo billing
Review the sample subscription, active frameworks, connected integrations, and unlimited-seat model.
- Demo board report
Review a quarterly security posture pack with risk, control health, findings, and vendor status.
- Demo compliance
Explore framework readiness, mapped controls, tests, and reusable evidence across compliance programs.
- Demo compliance snapshots
Browse point-in-time compliance snapshots with content hashes for audit packet references.
- Demo dashboard
Explore a fictional GRC Oversight workspace with compliance, monitoring, evidence, risk, and trust data.
- Demo data flows
Map data movement between systems with source, destination, data categories, and safeguards.
- Demo data subject requests
Track data subject request intake, ownership, status, and the 30-day SLA clock.
- Demo device posture
Inspect endpoint posture from sample MDM data, including encryption, compliance state, and check-in recency.
- Demo DPIA
Review data protection impact assessments linked to risks, vendors, and processing activities.
- Demo exceptions
Track time-boxed control and policy waivers with expiry-driven review and finding creation.
- Demo findings
Review centralized findings linked to controls, risks, policies, vendors, and remediation owners.
- Demo governance meetings
Review meeting records, decisions, attendees, and action items kept as governance evidence.
- Demo incidents and BC/DR
Track security incidents, operational incidents, post-mortems, and business-continuity exercises.
- Demo integrations
See connected evidence sources and integration health across cloud, identity, HR, code, and monitoring systems.
- Demo members
Invite and manage sample workspace members with unlimited seats.
- Demo obligations
Track jurisdictional legal and regulatory obligations separately from framework controls.
- Demo people
Explore HR roster, security-awareness training, and offboarding evidence in a sample workspace.
- Demo policies
Author, version, publish, and collect acknowledgements for sample compliance policies.
- Demo policy guardian
Find policy-to-control and policy-to-evidence gaps before review cycles drift.
- Demo questionnaires
Draft security questionnaire answers from approved sample evidence, policies, and controls.
- Demo reviews due
See recurring reviews across risks, policies, controls, vendors, access reviews, exceptions, and assets.
- Demo risk register
Score, prioritize, and track sample risks on a likelihood-by-impact grid.
- Demo RoPA
Browse GDPR Article 30 records of processing activities for a fictional organization.
- Demo scans and monitoring
Add sample domains, inspect scan history, and compare drift across public website trust scans.
- Demo settings
Explore organization, account, and security settings in the public demo workspace.
- Demo trust center
Publish a sample trust profile and manage public, NDA-gated, and private trust documents.
- Demo vendor risk
Review vendor inventory, criticality, document status, and third-party risk ratings.
- Demo webhooks
Configure sample outbound webhooks for GRC Oversight events.
Solutions
6- Defense contractors
Prepare CMMC and defense supplier evidence without inventing claims.
- Enterprise
Coordinate controls, evidence, risk, and trust workflows across larger teams.
- Growing teams
Scale compliance coverage as frameworks and integrations expand.
- Healthcare
Run a HIPAA Security Rule risk analysis and manage safeguards, BAAs, and breach-notification readiness.
- Solutions
GRC workflows for startups, growing teams, enterprise, and defense contractors.
- Startups
Get audit-ready without adding per-seat compliance costs.
Services
5- Audit readiness & fractional vCISO
Guided gap assessment and hands-on evidence prep for your first audit.
- Auditor marketplace
Find an independent audit firm and share scoped, revocable evidence access.
- Managed questionnaire answering
We draft and research every answer; you review and approve before it's sent.
- Penetration test referrals
Find a pentest firm and turn the report into tracked, mapped remediation.
- Services
Audit readiness, auditor matching, managed questionnaires, and pentest referrals.
Frameworks
16- CMMC
Cybersecurity Maturity Model Certification for the U.S. defense base
- Cross-framework overlap visualizer
See which controls and tests are genuinely shared across frameworks in the live evidence graph.
- DORA
EU regulation on digital operational resilience for finance
- EU AI Act
EU regulation establishing risk-based rules for AI systems
- FedRAMP
U.S. program for cloud services used by federal agencies
- Frameworks
Security, privacy, AI, resilience, and audit frameworks supported by the evidence model.
- GDPR
EU regulation governing personal data protection
- HIPAA
U.S. rules for protecting health information
- ISO/IEC 27001
International standard for information security management
- ISO/IEC 27701
Privacy information management extension to ISO 27001
- ISO/IEC 42001
International standard for AI management systems
- NIS2
EU directive on cybersecurity for essential and important entities
- NIST AI RMF
NIST framework for managing AI risk
- PCI DSS
Security standard for handling payment card data
- SOC 2
Trust Services Criteria for service organizations
- SOX
U.S. law requiring internal control over financial reporting
Integrations
194- 1Password Business integration
Collect 1Password Business user roster, group membership, and vault access-control evidence via the read-only Business API.
- AbuseIPDB integration
Collect IP address reputation, blacklist, and block check evidence from AbuseIPDB API v2.
- ADP Workforce Now integration
Collect ADP Workforce Now worker and organizational data through the read-only ADP HR/Payroll API to support employee-lifecycle and access-review evidence.
- AlienVault integration
Collect AlienVault USM Anywhere alarms and events, as well as OTX threat intelligence pulse evidence through read-only API endpoints.
- Amazon S3 bucket exports integration
Upload a CSV export of Amazon S3 buckets mapping bucketName, publicAccessBlockEnabled, and defaultEncryptionEnabled.
- Anthropic (Admin API) integration
Collect organization member, workspace, and API-key inventory as read-only AI-governance compliance evidence through the Anthropic Admin API. Scoped strictly to organization/access evidence -- not model usage content or conversation data. Requires an Admin API key (distinct from a regular API key), sent as the `x-api-key` header alongside an `anthropic-version` header. Note: Anthropic's Admin API requires the `anthropic-version` header on every request, which this generic HTTP connector's single configurable auth-header does not cover by default -- flag this as a known limitation.
- Asana integration
Audit Asana workspace members and projects as read-only work-management access-review and inventory evidence.
- Ashby integration
Audit Ashby ATS/recruiting accounts and job posting inventory as read-only access-review and hiring-pipeline evidence.
- Auth0 integration
Audit MFA factors, breached-password & brute-force protection, and tenant settings.
- AWS integration
Audit S3 public-access/encryption and IAM user MFA.
- Azure Blob storage exports integration
Upload a CSV export of Azure Blob storage containers mapping containerName, publicAccess, and encryptionStatus.
- Azure DevOps integration
Collect Azure DevOps project, repository, and pipeline evidence through organization-scoped APIs.
- Backblaze B2 exports integration
Upload a CSV export of Backblaze B2 buckets mapping bucketId, bucketName, and bucketType.
- BambooHR integration
Collect BambooHR employee roster, status, and onboarding/offboarding date evidence through company-scoped API endpoints.
- Better Stack integration
Push log-retention, uptime-monitor, alerting-coverage, and access evidence from Better Stack Logs/Uptime through an approved export or automation path -- Better Stack's public API surface for team/member access evidence is not confidently documented, so this is a webhook (push) template rather than a bespoke read connector.
- BI/reporting webhooks integration
Push report availability, data freshness, or dashboard evidence from BI systems.
- Bitbucket integration
Collect workspace and repository evidence from Bitbucket Cloud APIs.
- Box integration
Collect Box user, group, and enterprise event-log evidence through the read-only Box Platform API to support access-review and data-handling audits.
- BreezyHR integration
Audit BreezyHR recruiting-team user accounts and open position inventory as read-only ATS access-review and hiring-pipeline evidence.
- Brevo integration
Collect account info and verified-sender inventory as read-only 'who can send as us' access-review evidence through the Brevo (Sendinblue) API. Scoped strictly to access evidence, not campaign or contact data. Brevo's confirmed team/user-management endpoints are gated behind its Corporate/multi-account plan tier and are not confidently documented for standard accounts, so 'who has admin' evidence is NOT covered here -- track it manually until confirmed.
- Brex integration
Audit Brex team-member roster and roles as finance-system access-review evidence (who can move money).
- Buildkite integration
Collect pipeline and build-run inventory as read-only CI/CD compliance evidence through the Buildkite REST API.
- Carbon Black (VMware Carbon Black Cloud) integration
Collect device/endpoint coverage and alert evidence as read-only EDR compliance signal through the VMware Carbon Black Cloud API. Substitute your CBC console hostname for <your-cbc-host> and your org key for <org-key> in each endpoint path.
- Checkr integration
Collect Checkr background-check report status and package/order configuration as pre-employment screening compliance evidence.
- CI/CD and deploy webhooks integration
Push build, deploy, approval, and required-check evidence from CI/CD systems.
- CircleCI integration
Collect CircleCI account, context, and project environment-variable evidence through API v2.
- Cisco Meraki integration
Collect Meraki organization, network, and device inventory plus admin 2FA status through the read-only Meraki Dashboard API.
- Cisco Secure Endpoint integration
Collect endpoint/computer coverage and detection-event evidence as read-only EDR compliance signal through the Cisco Secure Endpoint (AMP) API.
- Cisco Umbrella integration
Collect Cisco Umbrella DNS security policy, destination-list/blocklist, and roaming-client deployment evidence through the read-only Umbrella API.
- Clerk integration
Audit Clerk user MFA enrollment, banned/locked status, and organization admin membership.
- ClickUp integration
Audit ClickUp workspace members and spaces as read-only project-management access-review and inventory evidence.
- Cloudflare integration
Collect Cloudflare zone security settings, firewall/WAF rule configuration, and account member access as DNS/edge-security compliance evidence.
- Cloudways integration
Connect Cloudways API v2 by entering the current API base URL and read-only evidence endpoints from the Cloudways API Playground.
- Codefresh integration
Collect pipeline and workflow-run inventory as read-only CI/CD compliance evidence through the Codefresh API.
- Comms and alerting webhooks integration
Push escalation, alert-delivery, incident-notification, or on-call evidence from alerting systems.
- Confluence integration
Collect Atlassian Confluence space membership, permission, and audit-log evidence through the read-only Confluence Cloud REST API.
- Coralogix integration
Collect Coralogix alert, parsing-rule, and outbound-webhook configuration evidence through documented read-only HTTP endpoints.
- CouchDB integration
Audit Apache CouchDB cluster membership, admin configuration, anonymous-access settings, and per-database security docs through read-only REST calls.
- CrateDB integration
Audit CrateDB user inventory, privilege grants, and cluster node health through read-only SQL system queries.
- CrowdStrike Falcon integration
Audit sensor coverage, reduced-functionality and stale hosts, and detections.
- CSV / file upload integration
Upload a CSV export (users, devices, access grants). Each row becomes evidence; an optional column drives the pass/fail verdict.
- Database inventory exports integration
Upload database role/grant, TLS, audit-log, or configuration exports.
- Databricks integration
Collect cluster configuration, job, and workspace-user inventory as read-only compliance evidence through the Databricks REST API (self-hosted workspace). Substitute your workspace URL for the <your-workspace> placeholder in the base URL.
- Datadog integration
Audit monitor coverage, log retention, audit-trail readability, and users.
- Deel integration
Audit Deel global payroll/EOR worker roster as read-only HR access-review and offboarding evidence.
- DigiCert integration
Collect certificate order and expiry-date inventory as read-only PKI/TLS-lifecycle compliance evidence through the DigiCert CertCentral API.
- DigitalOcean integration
Collect DigitalOcean cloud-infrastructure evidence (droplet/resource inventory, firewall configuration, and team member access) for cloud configuration and access-review compliance.
- Discord integration
Collect guild (server), member, and role inventory as read-only compliance evidence through the Discord bot REST API, for orgs using Discord as an internal comms/alerting channel.
- Docs and e-sign exports integration
Upload policy-signoff, document, attestation, or e-signature exports.
- DocuSign integration
Collect DocuSign envelope, template, user, and account evidence through read-only REST API endpoints.
- Dropbox Business integration
Collect Dropbox Business team member, group, and activity-log evidence through the read-only Dropbox Business API for access-review audits.
- Dropbox Sign integration
Collect Dropbox Sign (HelloSign) account, team, and signature-request evidence through the read-only API to support e-signature and document-control audits.
- DuckDB integration
Audit a DuckDB instance exposed via an HTTP query endpoint (e.g. a MotherDuck-compatible or self-hosted SQL-over-HTTP proxy), not a local file. Checks attached-database read-only posture, external access / unsigned extension settings, and loaded extension inventory through read-only SQL introspection.
- Duo Security integration
Collect Duo Security MFA evidence (user enrollment status, authentication device inventory, and administrator access) for multi-factor authentication compliance.
- Dynatrace integration
Collect monitored-entity and problem/alert inventory as read-only observability compliance evidence through the Dynatrace Environment API v2.
- Elastic Security / Kibana integration
Collect detection-rule and alert inventory as read-only SIEM compliance evidence through the Kibana/Elastic Security API (self-hosted or Elastic Cloud).
- F5 BIG-IP integration
Collect F5 BIG-IP system readiness, licensing, provision status, and LTM virtual server configurations via the iControl REST API.
- Fleet integration
Collect Fleet (osquery) host inventory, policy compliance, and user access evidence through the read-only Fleet REST API for device-posture and endpoint-management controls.
- Fortinet FortiGate integration
Collect firewall configuration, policies, system status, and system logs from Fortinet FortiGate devices via the FortiOS REST API.
- Freshdesk integration
Collect read-only Freshdesk agent, role, and group evidence through the Freshdesk API v2 for access-review evidence. This is not a general ticketing/task-automation connector.
- Freshservice integration
Collect Freshservice agent, requester, and audit-log evidence through the read-only Freshservice ITSM API to support access-review and change-management audits.
- Generic e-Signatures integration
Collect signature agreement, template, user, and transaction log evidence from standard e-signature REST endpoints.
- Generic transport/protocol evidence integration
Push normalized evidence from GraphQL, SFTP, SSH, LDAP, Kafka, AMQP, MQTT, or another bridge.
- Gitea integration
Collect repository, branch, collaborator, organization, and pull-request evidence through the Gitea API.
- GitGuardian integration
Collect GitGuardian secrets-detection evidence (incident inventory, source/perimeter coverage, and team member access) for secret-scanning compliance attestations.
- GitHub integration
Audit repository branch protection, visibility, and member 2FA.
- GitLab integration
Audit group 2FA enforcement, protected branches, MR approvals, and CI/CD secrets.
- Google BigQuery integration
Collect dataset, table, and job-history inventory as read-only compliance evidence through the BigQuery REST API. Substitute your GCP project ID for the <project-id> placeholder in each endpoint path.
- Google Cloud integration
Audit project IAM, service-account keys, Cloud Storage, and log sinks.
- Google Workspace integration
Audit users, 2-step verification, super admins, and OAuth app grants.
- Grafana integration
Collect user, organization, datasource, and alert-rule inventory as read-only observability compliance evidence through the Grafana HTTP API (self-hosted or Grafana Cloud).
- Greenhouse integration
Audit Greenhouse recruiter/hiring-manager accounts and live job postings as read-only HR/ATS access-review and hiring-pipeline evidence.
- Gusto integration
Collect Gusto HR roster and termination evidence through documented read-only API endpoints.
- HackerOne integration
Collect HackerOne program, report, and member evidence through the read-only HackerOne API to support vulnerability-management and bug-bounty audits.
- HashiCorp Vault integration
Collect HashiCorp Vault authentication method, policy, and audit-device configuration evidence through the read-only HTTP API for secrets-management and access-control controls.
- Heroku integration
Collect Heroku deployment-platform evidence (team member access, app inventory, and config-var/add-on posture) for change-management and access-review attestations.
- Hetzner Cloud integration
Collect server, firewall, network, and SSH-key inventory through the Hetzner Cloud API.
- HiBob integration
Audit HiBob HR roster (active/terminated workers, hire and termination dates) as read-only access-review and offboarding evidence.
- HR and recruiting exports integration
Upload roster, hiring, termination, department, or recruiting exports from Tier 2 HR systems.
- HTTP / REST endpoint integration
Point at any evidence-producing JSON API: base URL + auth header + read-only endpoints with JSON-path assertions. Each endpoint becomes evidence.
- HubSpot integration
Collect HubSpot user, team, and audit-log evidence through the read-only CRM API for access-review and change-tracking controls.
- IBM QRadar integration
Collect security offenses and asset inventory as read-only SIEM compliance evidence through the IBM QRadar REST API (self-hosted).
- Imperva WAF integration
Collect Imperva Cloud WAF site inventory and status/WAF-mode posture through the documented Imperva Cloud Security API. Customer supplies the account's API ID/key as the Authorization header value; site-specific security-rule evidence requires a documented site ID and is left customer-configured.
- Inbound webhook integration
Push normalized compliance evidence to us from approved n8n, Zapier, Make, or CI workflows. We mint a secret URL; POST normalized JSON and it lands as evidence.
- incident.io integration
Collect incident-response records and responder roster as BC/DR and SOC 2 CC7 evidence.
- Integrations
Connect cloud, identity, code, HR, observability, and security systems for evidence.
- Intercom (Access Review) integration
Audit Intercom workspace admin roster as access-review evidence (who has admin access). Scoped to admin/access evidence only, not conversation or contact data.
- Intruder integration
Collect open vulnerability issues and scanned-target inventory as read-only compliance evidence through the Intruder API.
- Jamf integration
Collect Jamf device inventory and compliance evidence through read-only Jamf Pro API endpoints.
- Jenkins integration
Collect Jenkins job, node, controller, and plugin evidence through read-only JSON API endpoints.
- Jira integration
Collect Jira project and change-ticket evidence through read-only Jira REST endpoints.
- JumpCloud integration
Collect user, group, and managed-system evidence from JumpCloud read APIs.
- Justworks integration
Audit Justworks PEO/HR employee roster as read-only access-review and offboarding evidence: active worker hire dates and terminated worker termination dates.
- Kandji integration
Collect Kandji device and blueprint evidence through read-only Kandji API endpoints.
- KnowBe4 integration
Collect security awareness training and phishing simulation evidence from KnowBe4 read APIs.
- LDAP / Active Directory integration
On-prem/hybrid directory bind: user roster, group membership, disabled/stale accounts, and password-policy attributes for access-review + deprovisioning evidence. NOT YET IMPLEMENTED — config/registration only; see the TODO in ldap.ts for the missing client-library dependency.
- Lever integration
Audit Lever recruiting/hiring team accounts and published job postings as read-only access-review and offboarding evidence.
- Linear integration
Collect Linear team and issue evidence through the Linear GraphQL API.
- Linode (Akamai) integration
Collect instances, firewalls, users, and account-event evidence through Linode API v4.
- LogRocket integration
Push normalized frontend session, issue, performance, or alert evidence from LogRocket through an approved export or automation path.
- Logsnag integration
Receive normalized incident, alert, monitor, or log-source evidence derived from Logsnag event streams.
- Looker integration
Collect Looker user, group, role, dashboard, and Look metadata through documented Looker API 4.0 read endpoints.
- Mercury integration
Collect cash-account inventory as read-only finance-system evidence through the Mercury API. Mercury's public API does not document a team-member/role or money-movement-permission listing endpoint as of this writing, so 'who can move money' access-review evidence is NOT covered here -- track it manually (e.g. via Mercury's dashboard team-permissions screen) until Mercury documents one.
- Metabase integration
Collect Metabase user, group, collection, database, dashboard, and card inventory through documented read-only API endpoints.
- Microsoft Azure integration
Collect Azure subscription and posture evidence through read-only Azure Resource Manager endpoints.
- Microsoft Azure Monitor integration
Collect diagnostic-settings and activity-log configuration as read-only logging/audit-trail compliance evidence through the Azure Resource Manager API.
- Microsoft Defender integration
Collect Microsoft Defender alert, incident, secure score, and device evidence through Microsoft Graph security endpoints.
- Microsoft Entra ID integration
Collect directory, role, and policy evidence through Microsoft Graph read-only endpoints.
- Microsoft Intune integration
Collect managed-device, enrollment-summary, and compliance-policy evidence through Microsoft Graph Intune endpoints.
- Microsoft SQL Server integration
Audit SQL Server login inventory, mixed-mode authentication, and database inventory through read-only system-catalog queries.
- Microsoft Teams integration
Collect Microsoft Teams team/channel roster and membership evidence via Microsoft Graph as collaboration access-control documentation.
- Microsoft Teams integration
Collect team, channel, and membership inventory as read-only compliance evidence through the Microsoft Graph Teams API.
- Mimecast integration
Collect Mimecast email security policy, threat, and account audit evidence through the read-only Mimecast API to support email-security and phishing-defense audits.
- MISP integration
Collect threat-intel attribute and event exports as read-only evidence through the self-hosted MISP API.
- Monday.com integration
Collect Monday.com board, item, update, and user evidence through the Monday.com GraphQL API. Use only for change, incident, access-request, or approval evidence.
- MongoDB Atlas integration
Collect organization, project, cluster, database-user, and access-list inventory through the MongoDB Atlas API v1.0.
- MongoDB integration
Audit MongoDB/Atlas authentication status, database inventory, and auth mechanisms through read-only admin commands.
- MongoDB self-hosted exports integration
Upload MongoDB user role, network access-list, or configuration exports.
- MySQL exports integration
Upload a CSV export of MySQL user privileges, TLS status, or server settings.
- MySQL integration
Audit MySQL/MariaDB TLS status, user/auth-plugin inventory, and database inventory through read-only SQL metadata queries.
- Neon integration
Audit Neon project inventory, branch protection, and project-sharing (collaborator) access.
- Netlify integration
Collect site and deploy inventory as read-only deploy/CI compliance evidence through the Netlify API. Substitute your site ID for the <site-id> placeholder in the deploys endpoint path.
- Network security webhooks integration
Push firewall, WAF, DNS security, certificate, or managed-network posture evidence.
- New Relic integration
Collect New Relic user roster, authentication domain (SSO) configuration, and alert policy evidence as observability access-control and monitoring documentation.
- Nightfall.ai integration
Collect DLP/PII-detection findings and detection-rule inventory as read-only data-loss-prevention compliance evidence through the Nightfall.ai API.
- Notion integration
Collect Notion workspace evidence (user/member inventory and page/database content coverage) for documentation and access-review compliance.
- OAuth2 (generic) integration
Connect an evidence-producing OAuth2 SaaS via authorization-code flow; read a userinfo/resource endpoint as evidence. Env-gated per provider.
- Object storage exports integration
Upload S3-compatible, Azure Blob, GCS, or Backblaze bucket/container exports.
- Observability webhooks integration
Push monitor, incident, alert, retention, or log-source coverage evidence.
- Okta integration
Audit active users for MFA enrollment and offboarding gaps.
- OmniHR integration
Audit OmniHR (APAC HRIS) employee roster as read-only HR access-review and offboarding evidence.
- OneLogin integration
Collect user, role, and application-assignment evidence from OneLogin APIs.
- OpenAI (Admin/Organization) integration
Collect organization member, project, and API-key inventory as read-only AI-governance compliance evidence through the OpenAI Admin API. Scoped strictly to organization/access evidence, not model usage content or completions data. Requires an Admin API key (distinct from a regular project API key). API keys are listed per-project; substitute your project ID for the <project-id> placeholder in the api-keys endpoint path.
- OpenCTI integration
Collect indicator, report, malware, and attack pattern evidence from OpenCTI via read-only GraphQL API queries.
- Opsgenie integration
Collect on-call schedules, escalation policies, and team-membership evidence as read-only compliance signal through the Opsgenie REST API. Signl4 is primarily a webhook-receiver product with no meaningful read API; capture Signl4 alerting evidence via the generic comms-alerting-webhook template instead of a bespoke connector.
- Oracle Database integration
Audit Oracle Database account status, audit/login parameters, and DBA role grants through ORDS read-only SQL metadata queries.
- PagerDuty integration
Audit escalation policies, on-call coverage, and incident-response readiness.
- Personio integration
Audit Personio HR roster (active/inactive employees, hire and termination dates) as read-only access-review and offboarding evidence.
- Postgres integration
Audit Postgres security settings, role inventory, and database inventory through read-only SQL metadata queries.
- PostHog integration
Audit PostHog organization member roles (admin/owner) and 2FA enrollment as observability access-review evidence.
- Power BI integration
Collect Power BI workspace, report, dashboard, dataset, and workspace-user inventory through documented REST API read endpoints.
- Qovery integration
Audit Qovery organization member roster and roles as deploy/hosting access-review evidence.
- Qualys integration
Collect Qualys asset, detection, and vulnerability scan evidence through read-only Qualys API endpoints.
- QuestDB integration
Audit QuestDB table durability (WAL), partitioning hygiene, and server configuration through read-only HTTP query endpoints.
- Rapid7 InsightVM integration
Collect Rapid7 InsightVM asset and vulnerability evidence through read-only API endpoints.
- Recorded Future integration
Collect threat intelligence alerts, IP, domain, and hash risk lists from Recorded Future API.
- Redis integration
Audit Redis authentication, TLS, persistence, and ACL posture through read-only RESP commands.
- Render integration
Collect service and workspace-owner inventory as read-only deploy/hosting compliance evidence through the Render REST API v1. Render's public API does not document a team-member/role-listing endpoint as of this writing, so member-role access-review evidence is NOT covered here -- track it manually until Render documents one, or reclassify to a bespoke connector if that changes.
- Resend integration
Collect API-key and verified-domain inventory as read-only 'who can send as us' access-review evidence through the Resend API. Scoped strictly to access evidence, not campaign or contact data. Resend's public API does not document a team-member/role-listing endpoint as of this writing, so 'who has admin' evidence is NOT covered -- track it manually until Resend documents one.
- Rippling integration
Audit HR roster, employment status, and offboarding dates.
- Salesforce (Security & Access) integration
Collect user roster, profile/permission-set assignments, and login-history evidence as read-only access-review compliance signal through the Salesforce REST API. Scoped to security/identity evidence only -- not sales, marketing, or customer-record data.
- Salesforce integration
Collect Salesforce user access, permission set, and login-history evidence through the read-only REST API for access-review and account-monitoring controls.
- Secrets-management exports integration
Upload vault, secret inventory, rotation, or access-review exports from secrets-management systems.
- Security tooling webhooks integration
Push vulnerability, EDR, SIEM, threat-intel, DLP, or training evidence from Tier 2 security tools.
- SecurityScorecard integration
Collect SecurityScorecard vendor risk ratings, factor scores, and issue findings through the read-only SecurityScorecard API to support third-party risk audits.
- SendGrid (Access Review) integration
Audit SendGrid teammate roster (who has admin), pending invites, and verified senders (who can send as us). Scoped to access evidence only, not campaign/contact data.
- SentinelOne integration
Collect SentinelOne agent and threat evidence through management-console API endpoints.
- Sentry integration
Collect Sentry organization member roles, project error-issue inventory, and audit log evidence as error-monitoring access and change-control documentation.
- ServiceNow integration
Collect change-request and incident evidence through ServiceNow Table API endpoints.
- Shopify (Security & Access) integration
Collect staff-account roster and API access-scope inventory as read-only access-review compliance evidence through the Shopify Admin API. Scoped strictly to security/access evidence, not storefront, product, order, or customer data.
- Shortcut integration
Audit Shortcut member accounts and projects as read-only project/issue-tracking access-review and workspace inventory evidence.
- SignNow integration
Collect SignNow document, template, user, and folder evidence through read-only REST API endpoints.
- SigNoz integration
Push log-retention, trace/metric-access, and alerting-coverage evidence from a self-hosted or SigNoz Cloud deployment -- SigNoz has no confidently-documented public admin/access-management REST API, so this is a webhook (push) template rather than a bespoke read connector.
- Slack integration
Collect Slack workspace, user, and channel evidence through read-only Slack Web API endpoints.
- Snowflake integration
Collect Snowflake access, role, and configuration evidence through the documented Snowflake SQL API.
- Snyk integration
Audit open vulnerabilities by severity, license issues, and scan recency.
- SonarQube / SonarCloud integration
Collect SonarQube/SonarCloud static-analysis evidence (quality gate status, project inventory, and security hotspot findings) for SAST coverage attestations.
- Splunk integration
Collect Splunk index, data-input, and saved-search evidence through management API endpoints.
- Stripe (Security Config) integration
Collect webhook-endpoint configuration and account security settings as read-only PCI-adjacent compliance evidence through the Stripe API. Scoped strictly to security configuration, not payment, billing, or customer financial data, and NOT a substitute for a real PCI DSS assessment. Note: Stripe does not expose API-key listing/rotation status via the API for security reasons, so key-management evidence must be tracked manually.
- Stripe integration
Collect Stripe team member roles and API key configuration evidence through the read-only Stripe API for access-review and credential-hygiene controls.
- Supabase integration
Collect project, database-role, and auth-settings evidence as read-only compliance signal through the Supabase Management API.
- SurrealDB integration
Audit SurrealDB namespace/database configuration and table permissions through read-only SurrealQL introspection queries.
- Tableau integration
Collect Tableau Cloud/Server site user, group, project, workbook, and data-source inventory through documented REST API read endpoints.
- Tailscale integration
Collect Tailscale zero-trust network evidence (device inventory, ACL/network policy configuration, and user roles) for network access control compliance.
- Teamwork integration
Collect read-only Teamwork project and task evidence for change, incident, access-request, or approval workflows. This is not a general task-automation connector.
- Tenable.io integration
Collect Tenable.io vulnerability scan results, asset inventory, and user access/MFA configuration as continuous vulnerability-management evidence.
- Terraform Cloud integration
Collect Terraform Cloud IaC evidence (workspace inventory, run/apply history, and organization member access) for infrastructure change-management compliance.
- TheHive integration
Collect case and alert inventory as read-only SOC/incident-response compliance evidence through the self-hosted TheHive API.
- Ticketing, ITSM, and approval exports integration
Upload change, incident, access-request, or approval exports from Tier 2 ticketing/PM systems. This is not a general task-automation connector.
- TimescaleDB integration
Audit TimescaleDB security settings, hypertable compression, and retention policies through read-only SQL metadata queries.
- Travis CI integration
Collect repository, build, and environment-variable-config evidence as read-only CI/CD compliance signal through the Travis CI API.
- Trellix ePO integration
Collect managed-system and policy-assignment inventory as read-only endpoint-security compliance evidence through the Trellix (McAfee) ePolicy Orchestrator remote API (self-hosted). ePO's remote commands return plain text by convention; append `?:output=json` to request JSON where supported by the deployment.
- Trello integration
Audit Trello workspace membership and board inventory as read-only Kanban/task-management access-review and change-management evidence.
- Twilio integration
Collect account configuration, verified sender numbers, and usage-record evidence as read-only compliance signal for orgs using Twilio as an SMS/voice alerting channel -- analogous to the Discord/Opsgenie templates. Not intended for general consumer messaging content or customer-communication data.
- Vercel integration
Collect Vercel deployment-platform evidence (team member access, project inventory, and environment variable/secret configuration) for change-management and access-review attestations.
- VirusTotal integration
Collect file-hash, URL, and IP-reputation lookup results as read-only malware-analysis compliance evidence through the VirusTotal API v3.
- Vultr integration
Collect instance, user, network, and account-log evidence through Vultr API v2.
- Wiz integration
Collect Wiz cloud security posture findings, vulnerability issues, and configuration compliance results as CSPM evidence via the read-only Wiz API.
- Workday integration
Collect Workday worker, organization, role, and termination-feed evidence through customer-configured read-only API endpoints.
- Wrike integration
Collect task, folder/project, and contact evidence through the Wrike API v4 for change, access-request, or approval reviews.
- YouTrack integration
Audit JetBrains YouTrack user accounts and project inventory as read-only issue-tracker access-review and workspace evidence.
- Zabbix integration
Collect host and user inventory as read-only observability compliance evidence through the self-hosted Zabbix JSON-RPC API. Note: Zabbix API is a single JSON-RPC endpoint, not REST resource paths; older Zabbix versions expect the auth token inside the request body/params, while newer versions (6.4+) accept a Bearer auth header -- confirm the customer Zabbix version before configuring the generic connector auth header.
- Zendesk integration
Collect Zendesk agent roster, role/permission configuration, and account security policy as support-operations access-control evidence.
- Zoho Desk integration
Audit Zoho Desk agent roster and department inventory as read-only helpdesk access-review evidence.
Resources
11- Access-review checklist
How to run a documented access review that stands up as evidence.
- Audit-readiness checklist
Evidence and approvals to prepare before an audit kickoff.
- Benchmark report
Scanner benchmarks and how to interpret public trust signals.
- Email authentication guide
SPF, DKIM, DMARC, CAA, and related domain hygiene guidance.
- Framework readiness quiz
Answer a few questions to get a recommended starting framework, an honest readiness estimate, and a real step-by-step roadmap.
- Free policy generator
Generate a starter security policy draft in seconds: Information Security, Access Control, Acceptable Use, Incident Response, Data Retention, or Vendor Management.
- Questionnaire-prep guide
Prepare approved sources for faster security questionnaire answers.
- Resources
Practical guides for audit readiness, security reviews, access reviews, and scanner fixes.
- Scanner remediation guide
How to fix common findings from the free website trust scan.
- SOC 2 & ISO 27001 cost & timeline calculator
Estimate a rough engineering-hours range and see the real readiness journey for SOC 2 or ISO 27001.
- Vendor-review checklist
What to extract from vendor security documents and how to rate risk.
Comparisons
22- Compare GRC platforms
A neutral buyer guide for comparing GRC platforms and their capabilities.
- GRC buyer guide
How to evaluate compliance platforms before choosing one.
- GRC Oversight vs Anecdotes
Public-source comparison of GRC Oversight and Anecdotes.
- GRC Oversight vs AuditBoard
Public-source comparison of GRC Oversight and AuditBoard.
- GRC Oversight vs Bastion
Public-source comparison of GRC Oversight and Bastion.
- GRC Oversight vs Comp AI
Public-source comparison of GRC Oversight and Comp AI.
- GRC Oversight vs Conveyor
Public-source comparison of GRC Oversight and Conveyor.
- GRC Oversight vs Cypago
Public-source comparison of GRC Oversight and Cypago.
- GRC Oversight vs Drata
Public-source comparison of GRC Oversight and Drata.
- GRC Oversight vs Hyperproof
Public-source comparison of GRC Oversight and Hyperproof.
- GRC Oversight vs OneTrust
Public-source comparison of GRC Oversight and OneTrust.
- GRC Oversight vs SafeBase
Public-source comparison of GRC Oversight and SafeBase.
- GRC Oversight vs Scytale
Public-source comparison of GRC Oversight and Scytale.
- GRC Oversight vs Secureframe
Public-source comparison of GRC Oversight and Secureframe.
- GRC Oversight vs Sprinto
Public-source comparison of GRC Oversight and Sprinto.
- GRC Oversight vs Strike Graph
Public-source comparison of GRC Oversight and Strike Graph.
- GRC Oversight vs Thoropass
Public-source comparison of GRC Oversight and Thoropass.
- GRC Oversight vs TrustCloud
Public-source comparison of GRC Oversight and TrustCloud.
- GRC Oversight vs UpGuard
Public-source comparison of GRC Oversight and UpGuard.
- GRC Oversight vs Vanta
Public-source comparison of GRC Oversight and Vanta.
- GRC Oversight vs VComply
Public-source comparison of GRC Oversight and VComply.
- GRC Oversight vs Whistic
Public-source comparison of GRC Oversight and Whistic.
Glossary
26- Access review
A periodic, documented check that every user's access to a system is still appropriate for their current role, also called a user access review (UAR).
- BAA
Business Associate Agreement: a contract required under HIPAA between a covered entity and any vendor that handles protected health information on its behalf.
- CAIQ
Consensus Assessments Initiative Questionnaire: a standardized cloud security questionnaire published by the Cloud Security Alliance, paired with the CSA STAR registry.
- Continuous monitoring
Running tests on a schedule so configuration drift surfaces between audits, not at audit time.
- Control
An objective within a framework (e.g. SOC 2 CC6.1) that you must satisfy and prove.
- Control owner
The named individual accountable for a control's operation and evidence: who an auditor or reviewer would ask if something looks wrong.
- Cross-mapping
Reusing one passing test across the multiple frameworks whose requirements it satisfies.
- DPA
Data Processing Agreement: a contract required under GDPR (and similar laws) between a data controller and a processor, governing how personal data is handled.
- Evidence
The artifact backing a test result, carrying a timestamp, source system, and content hash.
- FedRAMP
A U.S. government program standardizing security assessment, authorization, and monitoring for cloud services used by federal agencies.
- GRC glossary
Definitions for compliance, risk, trust, and security review terms.
- HITRUST
A certifiable framework (the HITRUST CSF) widely used in healthcare that harmonizes controls from HIPAA, ISO 27001, NIST, and other sources.
- ISMS
Information Security Management System: the overall management structure (policies, risk process, roles, continual improvement) that ISO 27001 certifies.
- ISO 27001
An international standard specifying requirements for an Information Security Management System (ISMS), with certification issued by accredited bodies.
- MCP
Model Context Protocol: the open standard that lets AI clients like Claude and Cursor call your tenant's tools.
- POA&M
Plan of Action and Milestones: a formal, tracked remediation plan for a known control gap or weakness, with owners and target dates.
- Requirement
The finest-grain obligation inside a control: the level at which mapping happens so one test can serve many frameworks.
- Residual risk
The risk that remains after controls and mitigations have been applied, as opposed to inherent risk, which is the risk before any mitigation.
- Security questionnaire
A form a prospective or existing customer sends asking about your security and compliance practices, often as a gate before signing or renewing a contract.
- SIG
Standardized Information Gathering questionnaire: a widely used, standardized third-party risk assessment questionnaire published by Shared Assessments.
- SOC 2
An AICPA audit report on a service organization's controls over security, availability, processing integrity, confidentiality, and privacy.
- SSP
System Security Plan: a document describing a system's boundaries, the controls it implements, and how each control is satisfied.
- Test
An automated or manual check that produces a pass/fail result against a requirement.
- Trust center
A public page sharing your security posture and NDA-gated documents to shorten customer reviews.
- TSC
Trust Services Criteria: the AICPA criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) that a SOC 2 report is evaluated against.
- Vendor risk assessment
The process of evaluating a third-party vendor's security posture (often via their SOC 2 report or a questionnaire) before and during the relationship.
Company
10- Changelog
Product and site updates for GRC Oversight.
- Contact
Contact GRC Oversight.
- Customers
Customer-facing information without invented logos or claims.
- Free website trust scan
Run a passive security, privacy, and accessibility scan for any public website.
- GRC Oversight: Trust Center
GRC Oversight's own public trust profile — the same self-serve Trust Center product every customer gets.
- Platform status
Current status for the web app, API, scanner, trust center, assistant, and connector surfaces.
- Pricing
Build your own plan by frameworks activated and integrations connected, with unlimited seats.
- Roadmap
Current and planned product direction.
- Sitemap
A human-readable index of public GRC Oversight pages.
- Trust center
Public trust and security profile for GRC Oversight.
Security, privacy, and legal
4- Privacy
Privacy policy for GRC Oversight.
- Scanner policy
Methodology, scope, and limits for the public website trust scanner.
- Security
How GRC Oversight handles security and trust.
- Terms
Terms of service for GRC Oversight.