Integrations

Real connectors for the stack you actually run.

Every Joopler connector is read-only and least-privilege. We never ask for write access, admin credentials, or long-lived personal tokens.

Available today

Connect once. Monitor continuously.

AWS

Pull IAM baselines, S3 configuration, CloudTrail, GuardDuty findings, and more. Read-only IAM role, least-privilege scoped policy.

Azure

Subscription posture: Defender for Cloud, storage account settings, and policy compliance. Read-only service principal.

GCP

IAM, Security Command Center findings, and Cloud Asset Inventory. Read-only service account with narrow scopes.

VMware vSphere

On-prem and air-gapped virtualization posture: vCenter and ESXi hardening. Least-privilege read-only role, with an optional in-network collector for private vCenter.

GitHub

Branch protection, code review requirements, MFA enforcement, and secret scanning. Read-only GitHub App.

Slack

Deliver control-drift and expiration alerts to your security channels. Send-only bot token.

Google Workspace

Directory, MFA enforcement, admin roles, and OAuth grant reviews. Read-only domain-wide delegation.

Jira

Track exceptions, remediation tickets, and access-review workflows alongside your engineering work.

Okta

MFA enforcement, admin roles, deprovisioning, and OAuth app grants, the source for shadow-AI discovery. Read-only API token.

Microsoft Entra ID

Identity governance: member MFA registration, stale-guest review, and sign-in log access. Read-only Microsoft Graph token.

Ping (PingOne)

Identity governance: MFA configuration, per-user MFA, and activity-log access. Read-only worker-app token.

Jamf Pro

Apple device posture: FileVault encryption and management state. Read-only API token.

Microsoft Intune

Device posture: managed-device compliance and disk encryption. Read-only Microsoft Graph token.

Anthropic

AI-provider governance: admin hygiene and workspace-scoped API keys, with unmodified API responses stored as evidence.

OpenAI

AI-provider governance: owner hygiene and organization audit-log access, captured as verifiable evidence.

Microsoft Copilot

AI-provider governance: Global Admin hygiene, MFA Conditional Access, and directory audit logging for M365 Copilot.

Workday

HRIS: onboarding completion, background checks, and timely offboarding. Read-only scoped access.

ServiceNow

Change and incident records captured as evidence. Read-only instance access.

GitLab

Group two-factor-authentication enforcement. Read-only access token.

Sentry

Organization two-factor-authentication enforcement. Read-only auth token.

Datadog

Monitoring and alerting coverage from active monitors. Read-only API and application keys.

PagerDuty

Incident response: on-call escalation policies. Read-only access key.

Snyk

Vulnerability management: projects under continuous dependency scanning. Read-only API token.

Prowler

Cloud security posture scanned against CIS benchmarks; open critical/high findings surfaced. Read-only API key.

Cloudflare

Edge TLS: the zone enforces Full or Strict SSL to origin. Read-only scoped token.

Auth0

Identity: multi-factor authentication factors enabled. Read-only Management API token.

HCP Terraform

Infrastructure as code: organization two-factor conformance. Read-only team or user token.

Tailscale

Network access: an explicit tailnet access-control (ACL) policy. Read-only API token.

Semgrep

Application security: static analysis (SAST) scanning of source. Read-only token.

GitGuardian

Application security: repositories monitored for leaked secrets. Read-only token.

New Relic

Observability: alert policies for system and security signals. Read-only user key.

Opsgenie

Incident response: on-call schedules route incidents to a responder. Read-only API key.

Fleet

MDM-free device posture from osquery: host inventory and disk encryption across macOS, Windows, and Linux. Read-only API token.

More connectors on the roadmap: Snowflake, and more. Tell us what you need.

Least-privilege by design

Every connector ships with a documented, minimal permission set. Access is scoped, auditable, and revocable at any time. Nothing Joopler collects requires elevated access to your systems.

Ready to see verifiable compliance?

Start free. Connect your stack. Share auditor-defensible evidence in days, not months.