.ai
Integrations

Connect the systems behind your controls.

Use read-only integrations to collect supported observations, identify drift, and prepare evidence for review without giving vCISO.ai permission to change your systems.

Read-only collection

Released integrations observe supported provider settings and inventory.

Human review remains required

An observation can prepare evidence, but does not verify an entire control by itself.

Disconnect at any time

Administrators can remove stored access and expire connector-derived evidence.

Available now

16 released, read-only integrations.

Each card describes currently supported observations. Availability does not imply complete control coverage.

Cloud and application platforms

Amazon Web Services

Available

Checks account access, CloudTrail, GuardDuty, S3 public-access blocking, RDS protection, and security-group exposure.

  • Root account MFA status
  • Root account access key status
  • IAM account password policy
  • 5 more supported observations

Google Cloud

Available

Checks public IAM bindings and audit logging configuration in a Google Cloud project.

  • Public IAM policy bindings
  • Audit log configuration

Microsoft Azure

Available

Checks Defender for Cloud plan coverage and activity logging in an Azure subscription.

  • Defender for Cloud plan status
  • Activity log configuration

Vercel

Available

Inventories Vercel projects and deployment environments through read-only API requests.

  • Project inventory
  • Deployment environment inventory

Detailed setup documentation is available in the authenticated workspace.

Supabase

Available

Inventories Supabase projects and records reported project health through the Management API.

  • Project inventory
  • Project health summary

Detailed setup documentation is available in the authenticated workspace.

Source control and delivery

GitHub

Available

Checks organization access defaults, repository controls, and high-risk Dependabot alert coverage.

  • Organization two-factor authentication status
  • Default repository permission policy
  • Visible repository inventory
  • 2 more supported observations

GitLab

Available

Checks top-level group two-factor authentication enforcement and public visibility.

  • Group two-factor authentication status
  • Group visibility status

Detailed setup documentation is available in the authenticated workspace.

Identity

Okta

Available

Collects paginated user inventory and verifies required authenticator enrollment settings in Okta.

  • Paginated user inventory
  • Required authenticator enrollment settings

Microsoft Entra ID

Available

Collects account security, access policy, administrator, and activity evidence from Microsoft Entra ID.

  • Conditional Access and security defaults
  • MFA registration report
  • User security inventory
  • 2 more supported observations

Workforce

Google Workspace

Available

Collects account security, external sharing activity, and administrator evidence from Google Workspace.

  • Two step verification report
  • External sharing activity
  • User account inventory
  • 1 more supported observations

BambooHR

Available

Collects current employee and workforce account inventory counts from BambooHR without persisting personal records.

  • Current employee inventory
  • Workforce account status summary

Detailed setup documentation is available in the authenticated workspace.

Endpoints and operations

Jamf Pro

Available

Collects device enrollment, encryption, and update compliance evidence from Jamf managed Apple devices.

  • Device enrollment inventory
  • Disk encryption compliance
  • OS update status
  • 1 more supported observations

Detailed setup documentation is available in the authenticated workspace.

Datadog

Available

Collects monitoring coverage, alerting, and log retention evidence from Datadog.

  • Monitor and alert configurations
  • Log retention settings

Detailed setup documentation is available in the authenticated workspace.

Cloudflare

Available

Collects WAF and minimum TLS configuration evidence from Cloudflare zones.

  • WAF rule configuration
  • TLS settings report

Detailed setup documentation is available in the authenticated workspace.

Collaboration and workflow

Slack

Available

Inventories workspace users and administrators using a scoped, read-only Slack app token.

  • User inventory
  • Administrator inventory
  • Workspace identity

Detailed setup documentation is available in the authenticated workspace.

Jira Cloud

Available

Collects Jira user inventory and administrative visibility evidence from Atlassian Cloud.

  • User inventory
  • Administrative permission check
  • Account identity

Detailed setup documentation is available in the authenticated workspace.

Start with the roadmap

Start with the systems your roadmap prioritizes.

Complete the free assessment first. Activate a plan when you are ready to connect supported providers and review the resulting work.