Real connectors for the stack you actually run.
Every Joopler connector is read-only and least-privilege. We never ask for write access, admin credentials, or long-lived personal tokens.
Connect once. Monitor continuously.
AWS
Pull IAM baselines, S3 configuration, CloudTrail, GuardDuty findings, and more. Read-only IAM role, least-privilege scoped policy.
Azure
Subscription posture: Defender for Cloud, storage account settings, and policy compliance. Read-only service principal.
GCP
IAM, Security Command Center findings, and Cloud Asset Inventory. Read-only service account with narrow scopes.
VMware vSphere
On-prem and air-gapped virtualization posture: vCenter and ESXi hardening. Least-privilege read-only role, with an optional in-network collector for private vCenter.
GitHub
Branch protection, code review requirements, MFA enforcement, and secret scanning. Read-only GitHub App.
Slack
Deliver control-drift and expiration alerts to your security channels. Send-only bot token.
Google Workspace
Directory, MFA enforcement, admin roles, and OAuth grant reviews. Read-only domain-wide delegation.
Jira
Track exceptions, remediation tickets, and access-review workflows alongside your engineering work.
Okta
MFA enforcement, admin roles, deprovisioning, and OAuth app grants, the source for shadow-AI discovery. Read-only API token.
Microsoft Entra ID
Identity governance: member MFA registration, stale-guest review, and sign-in log access. Read-only Microsoft Graph token.
Ping (PingOne)
Identity governance: MFA configuration, per-user MFA, and activity-log access. Read-only worker-app token.
Jamf Pro
Apple device posture: FileVault encryption and management state. Read-only API token.
Microsoft Intune
Device posture: managed-device compliance and disk encryption. Read-only Microsoft Graph token.
Anthropic
AI-provider governance: admin hygiene and workspace-scoped API keys, with unmodified API responses stored as evidence.
OpenAI
AI-provider governance: owner hygiene and organization audit-log access, captured as verifiable evidence.
Microsoft Copilot
AI-provider governance: Global Admin hygiene, MFA Conditional Access, and directory audit logging for M365 Copilot.

Workday
HRIS: onboarding completion, background checks, and timely offboarding. Read-only scoped access.

ServiceNow
Change and incident records captured as evidence. Read-only instance access.
GitLab
Group two-factor-authentication enforcement. Read-only access token.
Sentry
Organization two-factor-authentication enforcement. Read-only auth token.
Datadog
Monitoring and alerting coverage from active monitors. Read-only API and application keys.
PagerDuty
Incident response: on-call escalation policies. Read-only access key.
Snyk
Vulnerability management: projects under continuous dependency scanning. Read-only API token.
Prowler
Cloud security posture scanned against CIS benchmarks; open critical/high findings surfaced. Read-only API key.
Cloudflare
Edge TLS: the zone enforces Full or Strict SSL to origin. Read-only scoped token.
Auth0
Identity: multi-factor authentication factors enabled. Read-only Management API token.
HCP Terraform
Infrastructure as code: organization two-factor conformance. Read-only team or user token.
Tailscale
Network access: an explicit tailnet access-control (ACL) policy. Read-only API token.
Semgrep
Application security: static analysis (SAST) scanning of source. Read-only token.
GitGuardian
Application security: repositories monitored for leaked secrets. Read-only token.
New Relic
Observability: alert policies for system and security signals. Read-only user key.
Opsgenie
Incident response: on-call schedules route incidents to a responder. Read-only API key.
Fleet
MDM-free device posture from osquery: host inventory and disk encryption across macOS, Windows, and Linux. Read-only API token.
Least-privilege by design
Every connector ships with a documented, minimal permission set. Access is scoped, auditable, and revocable at any time. Nothing Joopler collects requires elevated access to your systems.
Ready to see verifiable compliance?
Start free. Connect your stack. Share auditor-defensible evidence in days, not months.