Skip to content
Back
Docs · Integrations

Evidence connectors.

All connectors are read-only and currently in beta. AuditVanguard never requests write access to your infrastructure, and ingested evidence is scoped to the client workspace you connect it to.

AWS

Beta
How it works
  1. Create a read-only IAM role with the policies below and authorize AuditVanguard via OAuth / role assumption.
  2. AuditVanguard ingests IAM findings, CloudTrail events and Security Hub alerts on a scheduled pull.
  3. Each finding is mapped to the matching control in the client workspace — no hand-tagging.
Required read-only permissions
  • SecurityAudit (AWS managed, read-only)
  • iam:Get*, iam:List*
  • cloudtrail:LookupEvents
  • securityhub:GetFindings

GitHub

Beta
How it works
  1. Install the AuditVanguard GitHub App on the organisation with read-only scopes.
  2. AuditVanguard ingests secret-scanning alerts, Dependabot alerts and branch-protection settings.
  3. Alerts land on the secure-development and vulnerability-management controls automatically.
Required read-only permissions
  • Repository metadata: read
  • Secret scanning alerts: read
  • Dependabot alerts: read
  • Administration (branch protection): read

Okta

Beta
How it works
  1. Create an API token scoped to the read-only admin role below.
  2. AuditVanguard ingests user lifecycle events, MFA enrollment status and sign-on policies.
  3. Evidence attaches to access-control and authentication controls on every sync.
Required read-only permissions
  • Read-only Administrator role
  • okta.users.read
  • okta.logs.read
  • okta.policies.read

Questions about a connector or need one we don't list yet? Talk to us.