TrustPoint

Connect the stack you already own.

Connectors bring posture and evidence in. Slack and Microsoft Teams integrations post platform events out to where your team works.

  1. Your security tools

    Connectors

  2. Scheduled collection

    cursors, retry, run history

  3. Rules

    authorable, versioned

  4. Control result and evidence

    with provenance

  5. Posture and report

    board, manager, regulator

Connectors run inside the platform and reach only the hosts allowed for each connection.

Your security tools feed a scheduled collection. Rules turn what was collected into a control result and an evidence item carrying its provenance. That result drives the posture dashboard and the reports read from it.

Continuous control monitoring connectors

These bring posture and evidence in. They run inside the platform, and each connection can reach only the hosts allowed for it.

Identity

  • Active Directory / Entra ID (LDAP)

    In catalogue

    ad-entra

    Directory accounts, group membership and stale-account state.

  • Microsoft Entra ID (Graph)

    In catalogue

    entra.graph.v1

    Conditional access policies, MFA registration and privileged role assignment.

  • Okta

    In catalogue

    okta.v1

    Sign-on policies, factor enrolment and application assignment.

  • Ping Identity

    In catalogue

    ping.v1

    Authentication policies and user population state.

Cloud security posture

  • Microsoft Defender for Cloud

    In catalogue

    azure.defender-cloud.v1

    Secure score, regulatory compliance state and resource recommendations.

  • Wiz

    In catalogue

    wiz.v1

    Cloud configuration issues, toxic combinations and exposure findings.

  • Prisma Cloud

    In catalogue

    prisma-cloud.v1

    Policy violations and compliance posture across cloud accounts.

  • Check Point CloudGuard

    In catalogue

    checkpoint.cloudguard.v1

    Cloud posture rulesets and configuration drift.

Vulnerability management

  • Tenable.io

    In catalogue

    tenable.io.v1

    Scan results, asset vulnerability state and remediation age.

  • Qualys VMDR

    In catalogue

    qualys.vmdr.v1

    Detections by severity, asset coverage and patch currency.

  • Rapid7 InsightVM

    In catalogue

    rapid7.insightvm.v1

    Vulnerability findings and remediation SLA state.

  • Microsoft Defender Vulnerability Management

    In catalogue

    defender.vm.v1

    Device weaknesses, exposure score and recommended actions.

  • Greenbone

    In catalogue

    greenbone.v1

    Open-source scan results and host findings.

  • Acunetix (DAST)

    In catalogue

    acunetix.v1

    Web application scan findings by severity.

SIEM and detection

  • Microsoft Sentinel

    In catalogue

    azure.sentinel.v1

    Analytics rule coverage, incident volume and data connector health.

  • Splunk

    In catalogue

    splunk.v1

    Saved search results, index coverage and detection state.

  • IBM QRadar

    In catalogue

    qradar.v1

    Offence counts, rule state and log source health.

  • Elastic Security

    In catalogue

    elastic.security.v1

    Detection rule status and alert volume.

  • LogRhythm

    In catalogue

    logrhythm.v1

    Alarm state and log source coverage.

  • Exabeam

    In catalogue

    exabeam.v1

    Analytics coverage and case state.

  • Cortex XSIAM

    In catalogue

    cortex.xsiam.v1

    Incident state and detection coverage.

Endpoint and EDR

  • CrowdStrike

    In catalogue

    crowdstrike.falcon.v1

    Sensor coverage, host health and detection state.

  • SentinelOne

    In catalogue

    sentinelone.v1

    Agent deployment, policy state and threat detections.

Code and AppSec

  • Snyk

    In catalogue

    snyk.v1

    Dependency, container and IaC findings by project.

  • SonarQube

    In catalogue

    sonarqube.v1

    Quality gate state and security hotspot counts.

  • GitHub Advanced Security

    In catalogue

    github.advanced-security.v1

    Code scanning alerts, secret scanning and Dependabot state.

ITSM

  • ServiceNow ITSM

    In catalogue

    servicenow.itsm.v1

    Change and incident records used as control evidence.

  • Jira Service Management

    In catalogue

    jira.sm.v1

    Request and change workflow state.

  • ManageEngine ServiceDesk Plus

    In catalogue

    manageengine.sdp.v1

    Ticket and change approval records.

  • Freshservice

    In catalogue

    freshservice.v1

    Change records and approval trails.

Key management

  • Azure Key Vault

    In catalogue

    azure.keyvault.v1

    Key rotation age, expiry and access policy state.

  • AWS KMS

    In catalogue

    aws.kms.v1

    Key rotation state, grants and key policy configuration.

  • HashiCorp Vault

    In catalogue

    hashicorp.vault.v1

    Secret engine configuration and lease state.

  • Thales CipherTrust

    In catalogue

    thales.ciphertrust.v1

    Key lifecycle state and policy configuration.

Workflow integrations

These post events to the tools your team works in. Slack and Microsoft Teams are available today; Jira, ServiceNow, Microsoft 365 and Google Workspace are planned.

  • Slack

    Platform events, such as incident alerts, posted to a channel you choose.

    Available
  • Microsoft Teams

    Platform events, such as incident alerts, posted to a channel you choose.

    Available
  • Jira

    Treatment milestones and findings as tracked issues.

    Planned
  • ServiceNow

    Findings and remediation tasks into your existing queues.

    Planned
  • Microsoft 365

    Calendar items for reviews and mail through your own tenant.

    Planned
  • Google Workspace

    Calendar items for reviews and mail through your own domain.

    Planned

Build your own

  • Generic REST connector

    Any JSON endpoint you can reach, mapped by a rule you write and version yourself.

  • Inbound webhook

    For tools that push rather than wait to be polled. The result enters the same control result model.

  • Outbound webhook subscriptions

    Push results and events to subscribed systems, with a delivery log you can inspect.

  • API tokens

    A REST API with tenant-scoped tokens, for anything a connector does not cover.

  • OData v4 feed

    A live, token-authenticated feed that Power BI or any BI tool reads directly.

A note for air-gapped sites

In an air-gapped installation, connectors run inside the platform on your network and each connection can reach only the internal hosts on its allowlist, so continuous control monitoring works without internet access. Secrets are encrypted and stored per tenant.

Hosting and operations

About this catalogue

Every connector listed here has a driver in the platform. Confirm the connectors your programme relies on during scoping. Product names are trademarks of their owners, used for identification only, and imply no partnership, certification or endorsement.

See monitoring running on your own tools.

Bring the list of what you run and we will go through it connector by connector.