Skip to content
Integrations

Automate Evidence Collection from the Systems You Already Run

Stop chasing screenshots. Aurora connects to your tools and keeps evidence current automatically. Every artifact carries a source, timestamp, and review history your team can explain to any reviewer.

143+ integrationsRead-only API accessFramework-mapped evidenceFreshness tracking

Have a deadline?Tell us the review target and the systems in scope. We'll show what is connector-backed, export-based, or manual before you buy.

Inside Aurora Command
Connector Health Visible at a Glance

See which systems are connected, how evidence arrives, and which export-backed workflows need manual follow-up before a reviewer asks.

Collection modes
Automated, export-based, and manual
Every connector shows its method upfront so your team knows what runs hands-off.
Evidence lineage
Source, timestamp, owner, and cadence
Each artifact carries provenance a reviewer can verify without follow-up questions.
Control mapping
Linked back to frameworks and reviewer asks
Evidence maps to controls once, then reuses across frameworks and review cycles.
Follow-up visibility
Gaps turn into owned work instead of ad hoc notes
Outstanding items surface as tasks with owners and due dates, not buried email threads.

Find your stack

Find Your Stack in the Connector Library

Each connector page shows what evidence it captures, sync frequency, and setup time before you commit.

Need something else? Request a Connector. We will confirm fit quickly and recommend the best path when a direct connector is not the right move.
Full catalog
Browse All Connectors by Category
56 connectors
23 connectors
Core Security Platforms
Identity, cloud, endpoint, vulnerability, logging, and ticketing connectors used to keep evidence continuously current.
Cloud
Amazon Web Services (AWS)
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: AWS CloudTrail is enabled in all regions, AWS CloudTrail is enabled and healthy, AWS CloudTrail log file validation is enabled
every 1 hour · about 5 minAurora Essentials (Baseline Control Set) and 117 more
Security: Read-only API; scoped credentials.
View details
Logging
Azure Monitor Logs (Pull)
Log collection
AutomatedEvidence captureContinuous checks
Verifies: Centralized logging is receiving events within last 24 hours, Centralized logging has received events within last 24 hours, Azure Monitor Logs pull ingestion has events within last 7 days
every 15 minutes · about 15 minAdobe Common Controls Framework (Adobe CCF) and 101 more
Security: Collector token; scoped to required sources.
View details
Source control
Bitbucket Cloud
Direct connection
AutomatedEvidence capture
Collects: Repositories
every 1 hour · about 15 minNot listed
Security: Read-only API; scoped credentials.
View details
Endpoint security
CrowdStrike Falcon
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Endpoint security is installed on at least 95% of corporate endpoints
every 15 minutes · about 5 minAnecdotes AI Framework (AAIF) and 50 more
Security: Read-only API; scoped credentials.
View details
Logging
Datadog (Audit Trail and Logs)
Log collection
AutomatedEvidence captureContinuous checks
Verifies: Centralized logging is receiving events within last 24 hours, Centralized logging has received events within last 24 hours, Datadog audit log ingestion has events within last 7 days
every 15 minutes · about 15 minAdobe Common Controls Framework (Adobe CCF) and 101 more
Security: Collector token; scoped to required sources.
View details
Source control
GitLab
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Dependabot alerts are triaged within SLA (30 days)
every 1 hour · about 15 minAdobe Common Controls Framework (Adobe CCF) and 23 more
Security: Read-only API; scoped credentials.
View details
Cloud
Google Cloud Platform (GCP)
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: GCP audit logs enabled, GCP Storage Public Access Prevention enforced
every 1 hour · about 5 minAurora Essentials (Baseline Control Set) and 32 more
Security: Read-only API; scoped credentials.
View details
Identity
Google Workspace (Directory)
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Multi factor authentication is enabled for all active human users, Multi factor authentication is enabled for all admin users, At least 1 break-glass account exists and is monitored
every 30 minutes · about 5 minAustralian Energy Sector Cyber Security Framework (AESCSF) and 97 more
Security: Read-only API; scoped credentials.
View details
Ticketing
Jira Cloud
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: High findings create tickets, Incidents are tracked with deterministic timelines
every 30 minutes · about 5 minAPRA CPS 230 & CPS 234 and 88 more
Security: Read-only API; scoped credentials.
View details
Identity
JumpCloud
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Multi factor authentication is enabled for all active human users, Password policy has minimum length >= 12, At least 1 break-glass account exists and is monitored
every 1 hour · about 5 minAustralian Energy Sector Cyber Security Framework (AESCSF) and 100 more
Security: Read-only API; scoped credentials.
View details
Device management
Kandji
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Disk encryption is enabled on all endpoints
every 30 minutes · about 5 minFDA 21 CFR Part 11 (Electronic Records; Electronic Signatures) and 100 more
Security: Read-only API; scoped credentials.
View details
Cloud
Microsoft Azure (ARM)
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Azure Activity Log export configured, Azure Storage public access prevention enforced
every 1 hour · about 5 minAurora Essentials (Baseline Control Set) and 41 more
Security: Read-only API; scoped credentials.
View details
Identity
Microsoft Entra ID (Azure AD) and Microsoft 365
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Multi factor authentication is enabled for all active human users, Multi factor authentication is enabled for all admin users, At least 1 break-glass account exists and is monitored
every 15 minutes · about 5 minAustralian Energy Sector Cyber Security Framework (AESCSF) and 97 more
Security: Read-only API; scoped credentials.
View details
Identity
Okta
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Multi factor authentication is enabled for all active human users, Multi factor authentication is enabled for all admin users, At least 1 break-glass account exists and is monitored
every 15 minutes · about 5 minAustralian Energy Sector Cyber Security Framework (AESCSF) and 100 more
Security: Read-only API; scoped credentials.
View details
Incident management
PagerDuty
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Incidents are tracked with deterministic timelines
every 1 hour · about 15 minAPRA CPS 230 & CPS 234 and 88 more
Security: Read-only API; scoped credentials.
View details
Identity
PingOne
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Multi factor authentication is enabled for all active human users, Multi factor authentication is enabled for all admin users, At least 1 break-glass account exists and is monitored
every 30 minutes · about 5 minAustralian Energy Sector Cyber Security Framework (AESCSF) and 100 more
Security: Read-only API; scoped credentials.
View details
Vulnerability
Qualys VMDR
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Vulnerability scans run within last 7 days
every 6 hours · about 5 minAdobe Common Controls Framework (Adobe CCF) and 82 more
Security: Read-only API; scoped credentials.
View details
Ticketing
ServiceNow (ITSM)
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: High findings create tickets, Incidents are tracked with deterministic timelines
every 30 minutes · about 5 minAPRA CPS 230 & CPS 234 and 88 more
Security: Read-only API; scoped credentials.
View details
Logging
Slack Audit Logs (Enterprise Grid)
Log collection
AutomatedEvidence captureContinuous checks
Verifies: Centralized logging is receiving events within last 24 hours, Centralized logging has received events within last 24 hours, Slack audit log ingestion has events within last 7 days
every 15 minutes · about 5 minAdobe Common Controls Framework (Adobe CCF) and 101 more
Security: Collector token; scoped to required sources.
View details
Logging
Splunk HEC Compatible Receiver
Log collection
AutomatedEvidence captureContinuous checks
Verifies: Centralized logging is receiving events within last 24 hours, Centralized logging has received events within last 24 hours, Splunk HEC receiver is receiving logs within last 60 minutes
continuous · about 5 minAdobe Common Controls Framework (Adobe CCF) and 101 more
Security: Collector token; scoped to required sources.
View details
Logging
Syslog over TLS Receiver
Log collection
AutomatedEvidence captureContinuous checks
Verifies: Centralized logging is receiving events within last 24 hours, Centralized logging has received events within last 24 hours, Syslog/TLS receiver is receiving logs within last 60 minutes
continuous · about 5 minAdobe Common Controls Framework (Adobe CCF) and 101 more
Security: Collector token; scoped to required sources.
View details
Vulnerability
Tenable.io
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Vulnerability scans run within last 7 days
every 6 hours · about 5 minAdobe Common Controls Framework (Adobe CCF) and 82 more
Security: Read-only API; scoped credentials.
View details
Ticketing
Trello
Direct connection
AutomatedEvidence capture
Collects: User accounts, Tickets and workflows, Incident
every 1 hour · about 5 minNot listed
Security: Read-only API; scoped credentials.
View details
10 connectors
People, Training & Collaboration
HR and collaboration connectors that help prove training completion, account governance, and communications posture.
eSignature
DocuSign
Direct connection
AutomatedEvidence capture
Collects: Evidence and settings relevant to your controls
every 1 hour · about 5 minNot listed
Security: Read-only API; scoped credentials.
View details
Training
KnowBe4 Security Awareness Training
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Security training completed within last 12 months
daily · about 15 minFDA 21 CFR Part 11 (Electronic Records; Electronic Signatures) and 76 more
Security: Read-only API; scoped credentials.
View details
Phone and video
RingCentral
Direct connection
AutomatedEvidence capture
Collects: Evidence and settings relevant to your controls
every 1 hour · about 15 minNot listed
Security: Read-only API; scoped credentials.
View details
Human resources
Rippling
Direct connection
AutomatedEvidence capture
Collects: User accounts, Employment Event
daily · about 5 minNot listed
Security: Read-only API; scoped credentials.
View details
Human resources
TriNet
Direct connection
AutomatedEvidence capture
Collects: User accounts, Employment Event
daily · about 15 minNot listed
Security: Read-only API; scoped credentials.
View details
Phone and video
Twilio
Direct connection
AutomatedEvidence capture
Collects: Evidence and settings relevant to your controls
every 1 hour · about 15 minNot listed
Security: Read-only API; scoped credentials.
View details
Phone and video
Vonage
Direct connection
AutomatedEvidence capture
Collects: Evidence and settings relevant to your controls
every 1 hour · about 15 minNot listed
Security: Read-only API; scoped credentials.
View details
Collaboration
Webex
Direct connection
AutomatedEvidence capture
Collects: Evidence and settings relevant to your controls
every 1 hour · about 15 minNot listed
Security: Read-only API; scoped credentials.
View details
Human resources
Workday (RaaS)
Direct connection
AutomatedEvidence capture
Collects: User accounts, Employment Event
daily · about 5 minNot listed
Security: Read-only API; scoped credentials.
View details
Collaboration
Zoom
Direct connection
AutomatedEvidence capture
Collects: Evidence and settings relevant to your controls
every 1 hour · about 15 minNot listed
Security: Read-only API; scoped credentials.
View details
19 connectors
Industry Systems
Line-of-business platforms Aurora can connect to for inventory, workflow evidence, and operational context.
Payments / PCI
Adyen
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Insurance AMS
Applied Epic
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Payments / PCI
BigCommerce
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Auto DMS
CDK Fortellis / APIs
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Insurance AMS
EZLynx
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Contact center
Five9
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Contact center
Genesys Cloud
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Insurance AMS
HawkSoft
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Mortgage / Title
ICE Encompass (LOS)
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
RIA/BD supervision
Microsoft Purview (Retention/eDiscovery)
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Insurance AMS
QQCatalyst
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Auto DMS
Reynolds & Reynolds (RCI ecosystem)
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Payments / PCI
Shopify
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Payments / PCI
Square
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Payments / PCI
Stripe
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 5 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Auto DMS
Tekion Partner Cloud APIs
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Insurance AMS
Vertafore AMS360 (WSAPI)
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
RIA/BD supervision
Wealthbox CRM
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details
Payments / PCI
WooCommerce
Direct connection
AutomatedEvidence captureContinuous checks
Verifies: Admin users are approved explicitly, Terminated users are removed or deprovisioned, Single sign on is enforced for the application
every 1 hour · about 15 minCSA Consensus Assessments Initiative Questionnaire (CAIQ) v4.0.3 and 94 more
Security: Read-only API; scoped credentials.
View details

Vertical connector bands

Industry-Specific Connectors for Regulated Workflows

Aurora covers common SaaS systems and the regulated operator systems that drive renewal, diligence, and procurement pressure in your vertical.

Insurance and agency systems

Show carrier-facing proof with AMS, renewal, and diligence evidence linked back to the same proof record.

Auto, dealer, and lender workflows

Support distributed operations, procurement asks, and reviewer-safe exports across dealership and lender review cycles.

Mortgage, title, payments, and fintech

Tie questionnaires, lender diligence, and PCI-adjacent evidence to one reviewer-safe proof system.

Healthcare and healthtech

Keep audit-ready exports, owner history, and readiness evidence current for regulated operating teams.

Defense and regulated procurement

Map boundary-held technical proof, entity scoping, and structured exports into regulated buying motions.

Contact center and service operations

Connect communications, evidence freshness, and reviewer operations together for service-heavy teams.
Request a Connector
Need a connector we don't list?
Tell us which control(s) you need to prove and your deadline. If a connector isn't possible, we'll recommend the next-best evidence pattern (export-based or manual).
We reply within 1 business day.

Use manual review first if the request involves EU, UK, or Swiss transfer terms, public-sector terms, healthcare or PHI workflows, PCI/cardholder-data scope, student records, export-controlled or CUI-style handling, private deployment requirements, or another workflow that needs a separate Borealis-signed agreement.

We use this only to respond to your request. No mailing list unless you ask. Review the Notice at Collection and Privacy Policy.
If you need EU, UK, or Swiss transfer terms, public-sector terms, PHI, PCI/cardholder-data scope, student-record commitments, private deployment, or another regulated workflow that needs a separate written agreement, use the manual review path before sharing restricted data through this connector request.

Collection clarity

Know What Runs Hands-Off Before You Buy

Every connector shows its collection method upfront: automated, export-based, or manual. No guesswork after purchase.

Runs on schedule

Automated

Aurora collects evidence on schedule from the connected system and keeps the source, capture time, and sync history attached.

  • Cloud configuration snapshots
  • Identity and access data
  • Audit log collection
Upload and track

Export-based

Your team uploads a source export, and Aurora keeps it organized, current, and mapped to the right controls.

  • Penetration test reports
  • Insurance certificates
  • Third-party audit letters
Owner-driven

Manual

For approvals, attestations, and other human-owned proof, Aurora still tracks the owner, due date, and review history.

  • Policy approvals
  • Training completion
  • Risk acceptance decisions

Review-ready records

Full Provenance on Every Artifact, Automatically

Source system, capture time, owner, review window, and mapped controls stay attached to every artifact.

Evidence: Record Detail
Source, Freshness, and Controls on Every Record

Aurora preserves source, freshness, owner, cadence, and linked controls on the record instead of flattening context into an export table.

Every artifact is traceable. Reviewers can verify where evidence came from, when it was collected, and who owns it, without follow-up questions.

Questions

Integration Questions, Answered Plainly

Permissions, evidence sources, and ongoing collection explained in plain language.

Can we start without integrations?
Yes. Manual uploads are supported from day one. Add connectors later without redoing control mapping or losing history.
Do integrations run automatically?
Every connector shows whether collection is automated, export-based, or manual before you start. Your team can see exactly what runs hands-off and what still needs an owner.
What if an integration is export-based?
Upload exports and still keep evidence organized with source details, capture time, owners, and review history. Freshness tracking works for all evidence types.
How do integrations connect to controls and frameworks?
Each integration maps to specific controls in your library. Evidence collected through a connector links to the controls it supports. Map once, reuse across frameworks and reviews.
Can reviewers see integration data directly?
Reviewers get the evidence package you publish through the Trust Center. They do not receive direct access to the connector or the operating workspace behind it, and you control what is shared and for how long.
What about systems without an API?
Aurora supports manual uploads and export-based evidence for any system. Upload the file, assign an owner and cadence, and Aurora tracks freshness and review history.

Still have questions? Talk to the team

Live walkthrough
See What Automates and What Stays Manual in Your Stack
Share your systems and what you need to prove. We will map automated connectors, export-based workflows, and manual steps to your controls.
15-minute walkthrough. No obligation. See Aurora applied to your workflow with the exact outputs reviewers receive. (No compliance guarantees.)