Platform · Integrations

Connect your stack. Evidence collects itself.

Read-only connections to the systems your programme already runs on: cloud, identity, code, workspace and ticketing. Continuous checks feed the same control model, so a passing check satisfies every framework it maps to.

  • 01Read-only scopes, revocable per tenant, never write access.
  • 02Machine evidence lands beside document evidence, same expiry semantics.
  • 03A failing check opens a task with a named owner, never a silent fix.

The connector library

The systems your programme already runs on

Cloud, identity, workspace, code and delivery. Each connector reads the state your controls depend on, and nothing more.

AWS

Cloud

IAM and MFA state, public bucket exposure, encryption flags

Azure

Cloud

Role assignments, storage access, disk encryption state

GCP

Cloud

IAM bindings, bucket exposure, key management state

Okta

Identity

MFA enrolment, admin roles, deprovisioning lag

Microsoft Entra

Identity

Conditional access, guest accounts, privileged roles

Google Workspace

Workspace

Two-step verification, sharing defaults, admin roles

Microsoft 365

Workspace

Mailbox auditing, external sharing, DLP state

GitHub

Code

Branch protection, review requirements, secret scanning

Jira

Delivery

Change tickets, approvals, closure trails

A system without a connector is not second-class: document evidence with validity tracking covers it, and custom checks can be authored the way custom frameworks are.

How it works

From connection to computed posture

Four steps, none of them silent.

  1. 01

    Connect, read-only

    A scoped, revocable connection per tenant. Compli-Once reads state; it never writes to your systems.

  2. 02

    Checks run continuously

    Each connector carries a library of checks against live configuration, on a cadence, not once a year.

  3. 03

    One check, one control

    A check maps to a control through the crosswalk. The result lands in the vault as machine evidence with a validity window.

  4. 04

    Every framework follows

    The control updates every framework it satisfies at the same moment. The category maps per framework; Compli-Once maps once.

Cloud, identity, code and workspace

AWS, Azure and GCP beside Okta, Microsoft Entra, Google Workspace, Microsoft 365, GitHub and Jira. Read-only scopes, revocable per tenant, never write access.

Continuous checks, one control model

Each check maps to controls through the crosswalk, so one passing check updates every framework that control satisfies. The category maps per framework; Compli-Once maps once.

Machine evidence beside document evidence

Check results land in the same vault with timestamps and validity windows. Expiry semantics are identical, so the auditor reads one story.

Failures raise work, not noise

A failing check opens a task with a named owner, exactly as an expiring document does. Nothing is remediated silently.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

The guarantee

Integrations automate collection, never decisions. A failing check raises work with an owner; an AI-proposed mapping waits for approval. Nothing changes your programme silently, including us.

Frequently asked questions

Are the integrations read-only?

Yes. Connections request read scopes only, are revocable per tenant at any time, and never write to your systems.

What about systems without an integration?

Document evidence with validity tracking covers them, and custom checks can be authored the same way custom frameworks are. There is no second-class evidence in Compli-Once.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.