Real connectors for the stack you actually run.
Every Joopler connector is read-only and least-privilege. We never ask for write access, admin credentials, or long-lived personal tokens.
Connect once. Monitor continuously.
AWS
Pull IAM baselines, S3 configuration, CloudTrail, GuardDuty findings, and more. Read-only IAM role, least-privilege scoped policy.
Azure
Subscription posture: Defender for Cloud, storage account settings, and policy compliance. Read-only service principal.
GCP
IAM, Security Command Center findings, and Cloud Asset Inventory. Read-only service account with narrow scopes.
VMware vSphere
On-prem and air-gapped virtualization posture: vCenter and ESXi hardening. Least-privilege read-only role, with an optional in-network collector for private vCenter.
GitHub
Branch protection, code review requirements, MFA enforcement, and secret scanning. Read-only GitHub App.
Slack
Deliver control-drift and expiration alerts to your security channels. Send-only bot token.
Google Workspace
Directory, MFA enforcement, admin roles, mailbox-forwarding checks, and OAuth grant reviews. Read-only domain-wide delegation.
Jira
Track exceptions, remediation tickets, and access-review workflows alongside your engineering work.
Okta
MFA enforcement, admin roles, deprovisioning, and OAuth app grants, the source for shadow-AI discovery. Read-only API token.
Microsoft Entra ID
Identity governance: member MFA registration, stale-guest review, and sign-in log access. Read-only Microsoft Graph token.
Ping (PingOne)
Identity governance: MFA configuration, per-user MFA, and activity-log access. Read-only worker-app token.
Jamf Pro
Apple device posture: FileVault encryption and management state. Read-only API token.
Microsoft Intune
Device posture: managed-device compliance and disk encryption. Read-only Microsoft Graph token.
Anthropic
AI-provider governance: admin hygiene and workspace-scoped API keys, with unmodified API responses stored as evidence.
OpenAI
AI-provider governance: owner hygiene and organization audit-log access, captured as verifiable evidence.
Microsoft Copilot
AI-provider governance: Global Admin hygiene, MFA Conditional Access, and directory audit logging for M365 Copilot.

Workday
HRIS: onboarding completion, background checks, and timely offboarding. Read-only scoped access.

ServiceNow
Change and incident records captured as evidence. Read-only instance access.
GitLab
Group two-factor-authentication enforcement. Read-only access token.
Sentry
Organization two-factor-authentication enforcement. Read-only auth token.
Datadog
Monitoring and alerting coverage from active monitors. Read-only API and application keys.
PagerDuty
Incident response: on-call escalation policies. Read-only access key.
Snyk
Vulnerability management: projects under continuous dependency scanning. Read-only API token.
Prowler
Cloud security posture scanned against CIS benchmarks; open critical/high findings surfaced. Read-only API key.
Cloudflare
Edge TLS: the zone enforces Full or Strict SSL to origin. Read-only scoped token.
Auth0
Identity: multi-factor authentication factors enabled. Read-only Management API token.
HCP Terraform
Infrastructure as code: organization two-factor conformance. Read-only team or user token.
Tailscale
Network access: an explicit tailnet access-control (ACL) policy. Read-only API token.
Semgrep
Application security: static analysis (SAST) scanning of source. Read-only token.
GitGuardian
Application security: repositories monitored for leaked secrets. Read-only token.
New Relic
Observability: alert policies for system and security signals. Read-only user key.
Opsgenie
Incident response: on-call schedules route incidents to a responder. Read-only API key.
Fleet
MDM-free device posture from osquery: host inventory and disk encryption across macOS, Windows, and Linux. Read-only API token.
Least-privilege by design
Every connector ships with a documented, minimal permission set. Access is scoped, auditable, and revocable at any time. Nothing Joopler collects requires elevated access to your systems.
Ready to see verifiable compliance?
Book a demo. Connect your stack. Share auditor-defensible evidence in days, not months.