Docs · Integrations
Evidence connectors.
All connectors are read-only and currently in beta. AuditVanguard never requests write access to your infrastructure, and ingested evidence is scoped to the client workspace you connect it to.
AWS
BetaHow it works
- Create a read-only IAM role with the policies below and authorize AuditVanguard via OAuth / role assumption.
- AuditVanguard ingests IAM findings, CloudTrail events and Security Hub alerts on a scheduled pull.
- Each finding is mapped to the matching control in the client workspace — no hand-tagging.
Required read-only permissions
- SecurityAudit (AWS managed, read-only)
- iam:Get*, iam:List*
- cloudtrail:LookupEvents
- securityhub:GetFindings
GitHub
BetaHow it works
- Install the AuditVanguard GitHub App on the organisation with read-only scopes.
- AuditVanguard ingests secret-scanning alerts, Dependabot alerts and branch-protection settings.
- Alerts land on the secure-development and vulnerability-management controls automatically.
Required read-only permissions
- Repository metadata: read
- Secret scanning alerts: read
- Dependabot alerts: read
- Administration (branch protection): read
Okta
BetaHow it works
- Create an API token scoped to the read-only admin role below.
- AuditVanguard ingests user lifecycle events, MFA enrollment status and sign-on policies.
- Evidence attaches to access-control and authentication controls on every sync.
Required read-only permissions
- Read-only Administrator role
- okta.users.read
- okta.logs.read
- okta.policies.read
Questions about a connector or need one we don't list yet? Talk to us.