Compliance integrations:
what we connect to, and exactly what we check.
Read-only connections that turn live configuration into audit evidence. This page lists only integrations that run real checks, and says plainly which ones do not yet.
What does a TryTrustable integration do?
A TryTrustable integration connects a system you already run with read-only credentials, reads its live configuration, and evaluates it against controls. Each check returns pass, fail, not applicable or could not verify, with the resources it looked at. Passing checks are filed as evidence automatically, and connected accounts are re-checked on a schedule rather than once.
The point is to replace screenshots. A screenshot shows a setting on the day it was taken; a check records what it read, when, and what the value was, and runs again on its own. Each result is filed against the framework references its control answers, and through the shared control library it counts wherever that control is required. The evidence ledger is where it lands.
Which integrations are available?
Three integrations run live checks today, 48 in all: GitHub, with 13 checks on organisation security and change management; AWS, with 15 checks across IAM, S3, CloudTrail, RDS, GuardDuty and Security Hub; and Google Cloud, with 20 checks across Cloud SQL, IAM, logging, Cloud Run, monitoring, secrets and Security Command Center. Okta, GitLab and Google Workspace have a connect screen in the product but do not run checks yet, so they produce no evidence.
| Integration | Status | What it reads | What it evidences |
|---|---|---|---|
| GitHub | Live | Organisation settings, repositories, branches, branch protection and rulesets, pull requests and reviews, CODEOWNERS and CI file names, Dependabot and secret-scanning status | 13 checks; change management, MFA, asset inventory, secure development, vulnerability management |
| Amazon Web Services | Live | IAM account summary, users, MFA devices, access keys and password policy; S3 account-level Block Public Access; CloudTrail; RDS; GuardDuty; Security Hub | 15 checks; MFA, access, key management, logging, encryption at rest, backup, network exposure, vulnerability management |
| Google Cloud | Live | Project IAM policy and audit config, service-account keys, Cloud SQL, log buckets, Cloud Run, Container Scanning API state, uptime checks and alerts, Secret Manager metadata, Security Command Center | 20 checks; encryption in transit, network exposure, backup, access, key management, logging, vulnerability management |
| Okta | Not yet | None | No checks run |
| GitLab | Not yet | None | No checks run |
| Google Workspace | Not yet | None | No checks run |
Status as of October 2026, taken from the product source. A connect screen without checks is marked Not yet.
Checks that need no integration
Some of the most important checks read the platform's own records rather than a third-party system. Ten DPDP checks run hourly against your consent, rights, breach and processor records: the consent ledger is intact and records the notice shown; every purpose has a lawful basis; withdrawals reached every processor; no prohibited processing of children's data; rights requests are answered in time; nomination is available; breaches were notified; processors are under contract; no processor sits in a restricted destination; and assessments are current. The consent platform and the DPDP guide cover the law behind them.
Code-level evidence comes from your pipeline instead: the SDK and CI gate run the scanners in your own CI, described in compliance as code.
How integration results reach every framework
A check belongs to one shared control in the library, such as formal change management, and is filed under the requirements that control answers: SOC 2 CC8.1 and ISO/IEC 27001 A.8.32 for a branch-protection check, for example. The same control also answers requirements in the DPDP Act, ISO/IEC 42001 and others. The framework mappings publish those shared rows pair by pair, generated from the same library, and coverage lists every regime.
The things people ask us
Which integrations are available?
Three integrations run live checks today, 48 in all: GitHub, with 13 checks on organisation security and change management; AWS, with 15 checks across IAM, S3, CloudTrail, RDS, GuardDuty and Security Hub; and Google Cloud, with 20 checks across Cloud SQL, IAM, logging, Cloud Run, monitoring, secrets and Security Command Center. Okta, GitLab and Google Workspace have a connect screen in the product but do not run checks yet, so they produce no evidence.
Are the integrations read-only?
Yes. The GitHub integration makes only GET requests to the GitHub REST API. The AWS integration calls 16 Get, List and Describe actions, and the Google Cloud integration uses 8 read-only roles with no write permission. None changes a setting or writes to your account. Credentials are encrypted at rest with AES-256-GCM and are never written to logs.
Why are Okta, GitLab and Google Workspace not listed?
Because they do not run checks yet. The product has a connect screen for them, but a connection without checks produces no evidence, and listing it as an integration would suggest otherwise. We will add a page for each when its checks read your real configuration.
How often do integrations re-check?
The first check runs when you connect. After that a scheduler re-syncs every connected account on a fixed interval, six hours by default, and anyone can press Sync. The scheduled and manual paths run the same code, so a scheduled result is never produced differently from the one you watched.
Do failing checks become evidence?
No. Only passing checks are filed as evidence, because a failing result is not evidence that a control works. Evidence items expire after 90 days and each sync renews them, so a connection that stops syncing stops counting. Failing results stay visible on the connected account, with the repositories, users or resources that caused them, until a later sync finds them fixed.
Is there an integration for Datadog or a SIEM?
No. There is no Datadog or SIEM connector today. If a log platform matters for your audit, say so when you book a demo; it helps us order the work.
Your next audit could be a link.
Thirty minutes. We connect one cloud account live and show you real evidence landing in the ledger before the call ends.