Partners
Partner with the control planefor machine authority.
Trustivan reads from AWS IAM, GitHub, Kubernetes, HashiCorp Vault and MCP tool servers today. Partners help us cover more of the estate security teams run, reach more of those teams and get the model right.
Technology · Channel & advisory · Research
Technology partners
Categories we integrate with
Connectors are built to one contract and labelled honestly as available or planned. These are the categories and what each reads today — names and status live on the integrations page.
See every integration and its statusIdentity providers
The source of truth for which applications, service users and OAuth grants are supposed to exist
- Trustivan reads
- Nothing yet — no identity-provider connector is built; a future capability
Cloud platforms
Where most workload and service identities are born — and where effective access is decided
- Trustivan reads
- AWS IAM: roles, machine users, access-key metadata, trust, group membership, inline policy statements
Secrets & vaults
So credential findings know where a vault already helps, and where a secret lives outside one
- Trustivan reads
- HashiCorp Vault: AppRoles, identity entities, policy names, auth mounts — never secret data
Code & CI/CD
Automation identities, deploy keys and pipeline secrets that quietly hold production access
- Trustivan reads
- GitHub: App installations, bot members, repositories — not tokens, deploy keys, secrets or runners
SIEM, SOAR & ITSM
Where findings and audit events would reach the tools your teams already triage and remediate in
- Trustivan reads
- Nothing yet — no export, webhook or ticketing integration is built; a future capability
AI platforms & agent frameworks
Agents, assistants and MCP servers — and the credentials, tools and permissions they inherit
- Trustivan reads
- Model Context Protocol: tool servers and the tools they list — no connector discovers an agent
How integration works
One connector contract. Four steps to a listed integration.
Every integration is built to the same read-only contract, validated on sample data and published with an honest status — so security teams know exactly what connects and what it reads.
Scope the read model
Agree which entities your platform exposes — identities, credential metadata, permissions, activity — and which scopes a read-only connector needs. Nothing outside that scope is requested.
Build to the connector contract
One abstraction covers authentication, pagination, rate limits, full and incremental sync, error handling and the mapping of every record to the identity graph with its source attached.
Validate in a sample tenant
Classification, ownership resolution and graph edges are checked together against a joint test account and clearly labelled illustrative data before anything reaches a customer.
Publish with an honest status
The integration is listed on the integrations page as available or planned — and joint announcements wait until customers can actually connect it.
Every connector commits to
- Read-only scopes, issued and revocable by the customer
- Tenant-scoped sync — no data crosses customer boundaries
- A source record on every identity, credential and permission
- Metadata only: secret material is never collected
- Incremental sync so the graph stays current without load
What we look for
- An API or export that exposes identities, grants or agents — not just logs
- Stable authentication for machine clients (OAuth, service credentials or OIDC)
- A team that will field integration questions and review the read model
- Shared customers, or a category our customers keep asking about
Why partner
What every partner can count on
A defined category
Position around AI Agent Security and Non-Human Identity Security, not another dashboard
A graph customers can verify
Every finding carries its evidence, so the security teams you serve can check the work rather than trust the pitch
Honesty as a feature
Availability labels and illustrative sample data mean nobody on your side has to walk back a claim
Engineers in the room
Integration questions and first engagements are handled by the people who build the connectors
Channel & advisory
For the advisors and resellers security teams already trust
Most security teams meet a new category through someone they already work with. We would rather equip that person properly than go around them.
Resellers & MSSPs
Add NHI and agent governance to your portfolio with a product that is honest about what it ships
Advisory & consulting
Run NHI and agent-security assessments on the evidence model and hand clients a report they keep
Identity & cloud integrators
Connect Trustivan to the identity, cloud and vault estates you already implement for customers
What channel partners get
- Enablement on the model: owner → identity → credential → service → resource → action, and how to explain it to a CISO
- Sample environments: demo tenants with clearly labelled illustrative data for workshops and walkthroughs
- Co-delivered first engagements: our engineers join your first assessments until your team runs them alone
- The real roadmap: the same trajectory we publish, with the detail behind it and honest dates
What we ask
- Security depth: teams that already practise identity, cloud or application security
- The same honesty rules: no claims about availability, customers or metrics that we would not make ourselves
- Evidence-first delivery: reports to customers carry the evidence, not just the score
- Candour: tell us what customers actually ask for — especially when it is not what we built
Research partners
Help define the threat model for agentic identity
We work with researchers, practitioners and standards contributors on the threat vocabulary of non-human and agentic identity — referencing frameworks such as the OWASP NHI Top 10, which belong to their authors.
Threat research
Confused deputy, delegation abuse, credential chaining, tool poisoning — reproduce it, document it, map it
Framework mapping
Editorial mappings to the OWASP NHI Top 10 and agentic threat work, with attribution to the projects that own them
Open write-ups & datasets
Illustrative datasets and published analysis — always labelled simulated, never presented as telemetry
Start a conversation
Tell us what you build, deliver or study.
Technology integration, channel and advisory, or research — describe the partnership you have in mind and a member of the team will reply within two business days.
Prefer email? hello@trustivan.com