Integrations

Real connectors for the stack you actually run.

Every Joopler connector is read-only and least-privilege. We never ask for write access, admin credentials, or long-lived personal tokens.

Available today

Connect once. Monitor continuously.

AWS

Pull IAM baselines, S3 configuration, CloudTrail, GuardDuty findings, and more. Read-only IAM role, least-privilege scoped policy.

Azure

Subscription posture: Defender for Cloud, storage account settings, and policy compliance. Read-only service principal.

GCP

IAM, Security Command Center findings, and Cloud Asset Inventory. Read-only service account with narrow scopes.

VMware vSphere

On-prem and air-gapped virtualization posture: vCenter and ESXi hardening. Least-privilege read-only role, with an optional in-network collector for private vCenter.

GitHub

Branch protection, code review requirements, MFA enforcement, and secret scanning. Read-only GitHub App.

Slack

Deliver control-drift and expiration alerts to your security channels. Send-only bot token.

Google Workspace

Directory, MFA enforcement, admin roles, mailbox-forwarding checks, and OAuth grant reviews. Read-only domain-wide delegation.

Jira

Track exceptions, remediation tickets, and access-review workflows alongside your engineering work.

Okta

MFA enforcement, admin roles, deprovisioning, and OAuth app grants, the source for shadow-AI discovery. Read-only API token.

Microsoft Entra ID

Identity governance: member MFA registration, stale-guest review, and sign-in log access. Read-only Microsoft Graph token.

Ping (PingOne)

Identity governance: MFA configuration, per-user MFA, and activity-log access. Read-only worker-app token.

Jamf Pro

Apple device posture: FileVault encryption and management state. Read-only API token.

Microsoft Intune

Device posture: managed-device compliance and disk encryption. Read-only Microsoft Graph token.

Anthropic

AI-provider governance: admin hygiene and workspace-scoped API keys, with unmodified API responses stored as evidence.

OpenAI

AI-provider governance: owner hygiene and organization audit-log access, captured as verifiable evidence.

Microsoft Copilot

AI-provider governance: Global Admin hygiene, MFA Conditional Access, and directory audit logging for M365 Copilot.

Workday

HRIS: onboarding completion, background checks, and timely offboarding. Read-only scoped access.

ServiceNow

Change and incident records captured as evidence. Read-only instance access.

GitLab

Group two-factor-authentication enforcement. Read-only access token.

Sentry

Organization two-factor-authentication enforcement. Read-only auth token.

Datadog

Monitoring and alerting coverage from active monitors. Read-only API and application keys.

PagerDuty

Incident response: on-call escalation policies. Read-only access key.

Snyk

Vulnerability management: projects under continuous dependency scanning. Read-only API token.

Prowler

Cloud security posture scanned against CIS benchmarks; open critical/high findings surfaced. Read-only API key.

Cloudflare

Edge TLS: the zone enforces Full or Strict SSL to origin. Read-only scoped token.

Auth0

Identity: multi-factor authentication factors enabled. Read-only Management API token.

HCP Terraform

Infrastructure as code: organization two-factor conformance. Read-only team or user token.

Tailscale

Network access: an explicit tailnet access-control (ACL) policy. Read-only API token.

Semgrep

Application security: static analysis (SAST) scanning of source. Read-only token.

GitGuardian

Application security: repositories monitored for leaked secrets. Read-only token.

New Relic

Observability: alert policies for system and security signals. Read-only user key.

Opsgenie

Incident response: on-call schedules route incidents to a responder. Read-only API key.

Fleet

MDM-free device posture from osquery: host inventory and disk encryption across macOS, Windows, and Linux. Read-only API token.

More connectors on the roadmap: Snowflake, and more. Tell us what you need.

Least-privilege by design

Every connector ships with a documented, minimal permission set. Access is scoped, auditable, and revocable at any time. Nothing Joopler collects requires elevated access to your systems.

Ready to see verifiable compliance?

Book a demo. Connect your stack. Share auditor-defensible evidence in days, not months.