Integrations

Connect every system.Normalize every identity.

Five connectors read identities, credential metadata, permissions and MCP tools from AWS, GitHub, Kubernetes, HashiCorp Vault and MCP servers — read-only, least-privilege, and every other system labelled planned.

5 available · 52 planned

Connectors

Browse by system, category or status

Search what a connector reads, then filter by category or availability. Status reflects the connector contract roadmap, not a marketing claim.

Category
Status

Showing all 57 connectors

  • AWS IAM

    Available

    Cloud

    Reads Roles, machine users, access-key metadata, trust, inline policy statements

  • Azure / Entra ID

    Planned

    Cloud

    Reads Service principals, app registrations, managed identities, role assignments

  • Google Cloud IAM

    Planned

    Cloud

    Reads Service accounts, keys, workload identity, IAM bindings

  • Kubernetes

    Available

    Cloud

    Reads Service accounts, role bindings, workloads that run as them

  • Oracle Cloud

    Planned

    Cloud

    Reads Users, dynamic groups, API keys, policies

  • Okta

    Planned

    Identity

    Reads Applications, API tokens, service users, OAuth grants

  • Microsoft Entra ID

    Planned

    Identity

    Reads Enterprise apps, OAuth consents, credentials, owners

  • Active Directory

    Planned

    Identity

    Reads Service accounts, gMSAs, SPNs, delegation

  • Ping Identity

    Planned

    Identity

    Reads OAuth clients, applications, grants

  • HashiCorp Vault

    Available

    Secrets & Vaults

    Reads AppRoles, machine identity entities, auth mounts, policy names

  • AWS Secrets Manager

    Planned

    Secrets & Vaults

    Reads Secrets, rotation status, resource policies

  • Azure Key Vault

    Planned

    Secrets & Vaults

    Reads Secrets, keys, certificates, access policies

  • GCP Secret Manager

    Planned

    Secrets & Vaults

    Reads Secrets, versions, IAM bindings

  • CyberArk Conjur

    Planned

    Secrets & Vaults

    Reads Hosts, variables, policies

  • Akeyless

    Planned

    Secrets & Vaults

    Reads Items, auth methods, roles

  • 1Password

    Planned

    Secrets & Vaults

    Reads Service accounts, vault access

  • GitHub

    Available

    Code & CI/CD

    Reads App installations, bot members, repositories and their visibility

  • GitLab

    Planned

    Code & CI/CD

    Reads Tokens, deploy keys, CI variables, runners

  • Bitbucket

    Planned

    Code & CI/CD

    Reads App passwords, access keys, pipeline variables

  • Jenkins

    Planned

    Code & CI/CD

    Reads Credentials store, service users, job bindings

  • CircleCI

    Planned

    Code & CI/CD

    Reads Contexts, environment variables, OIDC

  • Buildkite

    Planned

    Code & CI/CD

    Reads Agent tokens, cluster queues

  • Terraform Cloud

    Planned

    Code & CI/CD

    Reads Workspaces, variable sets, team tokens

  • Azure DevOps

    Planned

    Code & CI/CD

    Reads Service connections, PATs, pipelines

  • JFrog Artifactory

    Planned

    Code & CI/CD

    Reads Access tokens, service users

  • Slack

    Planned

    Collaboration & SaaS

    Reads Apps, bot tokens, scopes, installers

  • Microsoft 365

    Planned

    Collaboration & SaaS

    Reads App consents, mailbox delegations, Graph permissions

  • Google Workspace

    Planned

    Collaboration & SaaS

    Reads OAuth apps, domain-wide delegation, service accounts

  • Salesforce

    Planned

    Collaboration & SaaS

    Reads Connected apps, integration users, OAuth tokens

  • Atlassian Jira & Confluence

    Planned

    Collaboration & SaaS

    Reads API tokens, OAuth apps, service accounts

  • ServiceNow

    Planned

    Security & ITSM

    Reads Integration users, OAuth apps, ticket workflows

  • Notion

    Planned

    Collaboration & SaaS

    Reads Integrations, tokens, shared pages

  • Zendesk

    Planned

    Collaboration & SaaS

    Reads API tokens, OAuth clients

  • Workato

    Planned

    Collaboration & SaaS

    Reads Connections, recipes, service identities

  • Snowflake

    Planned

    Data

    Reads Service users, key-pair auth, roles, grants

  • Databricks

    Planned

    Data

    Reads Service principals, tokens, workspace permissions

  • PostgreSQL

    Planned

    Data

    Reads Roles, grants, connection identities

  • MongoDB Atlas

    Planned

    Data

    Reads Database users, API keys, roles

  • Amazon S3

    Planned

    Data

    Reads Bucket policies, access points, reachability

  • BigQuery

    Planned

    Data

    Reads Dataset IAM, service-account access

  • Elasticsearch

    Planned

    Data

    Reads API keys, service tokens, roles

  • Model Context Protocol

    Available

    AI & MCP

    Reads MCP servers and their tools, with publisher-declared effect

  • OpenAI Platform

    Planned

    AI & MCP

    Reads API keys, service accounts, projects

  • Anthropic Claude

    Planned

    AI & MCP

    Reads API keys, workspaces

  • Azure OpenAI

    Planned

    AI & MCP

    Reads Deployments, keys, managed identity access

  • Amazon Bedrock

    Planned

    AI & MCP

    Reads Invocation roles, knowledge base access

  • Vertex AI

    Planned

    AI & MCP

    Reads Service accounts, IAM bindings

  • LangChain / LangGraph

    Planned

    AI & MCP

    Reads Tool registries, credentials

  • CrowdStrike Falcon

    Planned

    Security & ITSM

    Reads API clients

  • Wiz

    Planned

    Security & ITSM

    Reads Cloud findings, identity exposure context

  • Splunk

    Planned

    Security & ITSM

    Reads Findings export, detection events

  • Microsoft Sentinel

    Planned

    Security & ITSM

    Reads Findings export, incident workflows

  • Datadog

    Planned

    Security & ITSM

    Reads API and application keys

  • PagerDuty

    Planned

    Security & ITSM

    Reads Incident routing, API keys

  • SPIFFE / SPIRE

    Planned

    Identity

    Reads SVIDs, trust domains, workload registrations

  • Docker Hub

    Planned

    Code & CI/CD

    Reads Access tokens, organization members

  • Webhook / generic

    Planned

    Security & ITSM

    Reads Evidence export and remediation callbacks

Product names are used nominatively to identify supported systems. Status reflects the connector contract roadmap and is never a claim of certification or partnership.

Coverage

Your clouds. Your clusters. Your vaults. Your MCP servers.

Coverage grows where non-human identities actually live — and every tile carries its status.

  • AWS IAM
  • Azure / Entra IDPlanned
  • Google Cloud IAMPlanned
  • Kubernetes
  • Oracle CloudPlanned
  • OktaPlanned
  • Microsoft Entra IDPlanned
  • Active DirectoryPlanned
  • Ping IdentityPlanned
  • HashiCorp Vault
  • AWS Secrets ManagerPlanned
  • Azure Key VaultPlanned
  • GCP Secret ManagerPlanned
  • CyberArk ConjurPlanned
  • AkeylessPlanned
  • 1PasswordPlanned
  • GitHub
  • GitLabPlanned
  • BitbucketPlanned
  • JenkinsPlanned
  • CircleCIPlanned
  • BuildkitePlanned
  • Terraform CloudPlanned
  • Azure DevOpsPlanned
  • JFrog ArtifactoryPlanned
  • SlackPlanned
  • Microsoft 365Planned
  • Google WorkspacePlanned
  • SalesforcePlanned
  • Atlassian Jira & ConfluencePlanned
  • ServiceNowPlanned
  • NotionPlanned
  • ZendeskPlanned
  • WorkatoPlanned
  • SnowflakePlanned
  • DatabricksPlanned
  • PostgreSQLPlanned
  • MongoDB AtlasPlanned
  • Amazon S3Planned
  • BigQueryPlanned
  • ElasticsearchPlanned
  • Model Context Protocol
  • OpenAI PlatformPlanned
  • Anthropic ClaudePlanned
  • Azure OpenAIPlanned
  • Amazon BedrockPlanned
  • Vertex AIPlanned
  • LangChain / LangGraphPlanned
  • CrowdStrike FalconPlanned
  • WizPlanned
  • SplunkPlanned
  • Microsoft SentinelPlanned
  • DatadogPlanned
  • PagerDutyPlanned
  • SPIFFE / SPIREPlanned
  • Docker HubPlanned
  • Webhook / genericPlanned

Contract

One connector contract. Every source.

Every connector implements the same contract, so identities from different systems can be compared, traversed and governed the same way.

Normalized Identity Types

Map provider objects to service accounts, roles, workloads, bots and AppRoles with one schema

Sync Lifecycle

Authorize, enumerate, normalize, attach evidence, reconcile and retire — resumable on every run

Evidence

Keep the source record, timestamps and whether it was observed or inferred for every node and edge

Pagination

Page through large tenants with resumable cursors and rate-limit awareness — never a partial snapshot presented as complete

Tenant Isolation

Run each tenant’s connectors, credentials and evidence in isolation; nothing is shared across tenants

Connector Permissions

Read-only, least-privilege provider permissions, documented per connector before you connect; nothing writes back

Missing a connector? Tell us what it should read.

Connector requests feed the roadmap directly. Name the system, the identity types it holds and the evidence you need from it.

Connect one account. See every identity in it.

See how TRUSTIVAN connects identity, credential, access, agent and action context into one control plane.