Continuous Compliance Integrations

Connect the platforms you already run. Evidence collects itself.

RealCISO pulls live configuration every 12 hours, snapshots it as audit evidence, and grades it against automated pass/fail tests mapped to your frameworks — with read-only access and credentials it never holds longer than a sync.

Start Free Book a Demo
No screenshotsNo spreadsheetsRead-only, alwaysTests never change your assessment
G2 Summer 2026 High Performer badges — RealCISO ranked #1 vCISO platformSourceForge Leader Award, Summer 2026
4.8/5 · 223 reviews · Read reviews on SourceForge

4.8/5 across 223 reviews on SourceForge · #1 vCISO platform on G2, Summer 2026

15
Supported integrations
155
Evidence collectors
386
Distinct automated tests
12h
Default sync cadence

Counts from the live ruleset, production-confirmed August 2026. Per-provider test counts overlap where Azure and Microsoft 365 share Entra ID tests.

How It Works

Collectors gather. Tests judge. You decide.

Three layers, deliberately kept separate.

Layer one

1 · Evidence

Automated jobs pull live configuration on a schedule and store a timestamped snapshot straight from the provider's API. No judgment — "here are your 23 S3 buckets and their encryption settings." Changes between syncs are recorded in a timeline.

Layer two

2 · Tests

Pass/fail checks evaluated against each snapshot: "all S3 buckets are encrypted", "MFA is enforced for privileged roles." Every result surfaces against the control, the question and the framework it affects, with full history.

Layer three

3 · Control assessment

Your team's call. Tests and evidence are inputs; the control status is always a human decision. A control can have every test passing and still be Partially Met because of systems the integration cannot see.

If evidence and tests were combined, the platform would tell you "your AWS MFA is compliant" while 50 employees sit on local Active Directory that AWS has never seen. If tests and assessment were combined, the platform would be making audit decisions on your behalf. Three layers keep the product honest about what it can and cannot see — and keep you in control.

What Each Integration Delivers

Fifteen integrations, live today

Cloud, identity, endpoint management, EDR, vulnerability management and network — plus evidence from RealCISO itself.

Microsoft Azure

38Collectors
105Tests

VMs, storage, SQL, Key Vault, networking, NSGs, RBAC, backup, Defender, AKS, Cosmos DB, Entra ID, conditional access

Amazon Web Services

32Collectors
97Tests

IAM, S3, EC2, RDS, KMS, CloudTrail, GuardDuty, Secrets Manager, backup, security alerting

Google Cloud

19Collectors
63Tests

IAM, Cloud SQL, GKE, KMS, firewall, logging & alerting, DNS, API keys, service accounts

Microsoft 365

16Collectors
36Tests

Entra ID identity & MFA, conditional access, authentication methods, session controls, guest access, app credential hygiene, SSO coverage, access review

Iru (formerly Kandji)

7Collectors
17Tests

Whole-fleet inventory (Macs, iPhones, iPads, Windows and Android); Mac security posture — FileVault & key escrow, application firewall, Gatekeeper & XProtect, SIP, secure boot — plus profiles, blueprints, admins and audit log

Google Workspace

6Collectors
15Tests

Admin roles, 2SV/MFA enrollment & enforcement, Drive external sharing, Gmail security, group governance, SSO, domain verification

Enclave by SideChannel

6Collectors
14Tests

Asset inventory & discovery, installed software with CVE exposure, vulnerability scan currency, network microsegmentation, host firewall coverage, TLS certificate discovery

Okta

6Collectors
13Tests

MFA enforcement, password & session policy, SSO coverage, network zones, device & access review

Microsoft Intune

5Collectors
13Tests

Managed device inventory, compliance state & policies, disk encryption, app protection & BYOD workspace separation, configuration profiles, detected software

RealCISO Platform

5Collectors
7Tests

Policy reviews, risk register, vendor inventory, classifications & TPRM assessments — evidence from the platform itself

ConnectWise Platform

4Collectors
11Tests

Managed endpoint inventory, antivirus, firewall & TPM state, OS and third-party patch compliance, endpoint CVEs, installed software, sites, device groups & policies

Jamf Pro

4Collectors
9Tests

Mac inventory with FileVault, SIP, Gatekeeper, firewall & secure boot state, enrolled Apple fleet, smart & static groups, configuration profiles, API role privileges

Tenable Vulnerability Management

4Collectors
9Tests

Findings with severity & remediation age, CIS and STIG benchmark results, scan schedules & coverage, agent deployment, authenticated scanning, user & role access

Qualys VMDR

2Collectors
4Tests

Detections with severity, detection age & CVE mapping, vulnerability definitions, asset inventory with scan recency and cloud agent coverage

CrowdStrike Falcon

1Collectors
4Tests

Endpoint protection coverage — sensor inventory with OS and sensor version, sensor contact currency, reduced functionality mode, applied prevention policy

Good to know: Entra ID identity coverage (MFA, conditional access, privileged roles) ships through either a Microsoft 365 or an Azure connection — whichever you connect first — so those two cards overlap and sum to more than the 386 distinct tests. Endpoint integrations describe the machines themselves, including on-premises servers and laptops that never appear in a cloud API. Iru inventories your whole fleet, Windows and Android included; its detailed security posture comes from Iru's Prism reporting, which covers macOS only.

Automated Coverage

More than half your assessment, from cloud and identity alone

57%
of the 289-question assessment library evidenced by cloud + identity providers alone (measured July 2026)

Connecting AWS, Azure or Google Cloud alongside Microsoft 365, Google Workspace or Okta evidences up to 57% of a full security assessment without a single document upload; technical domains such as access control, platform security and monitoring run 80–96% automated. Endpoint management, EDR and vulnerability-management integrations add coverage on top of that figure. Results depend on which integrations you connect and how your environment is configured.

Tuning & Security

Built for your security team's review

Turn things off without disconnecting

Each collector has a "collect evidence" switch and an "evaluate tests" switch; each test has its own. Disabled items freeze — nothing is deleted, history is never rewritten. Archive hides evidence but never deletes it.

Waive a test, with a reason

A test that flags an accepted risk can be waived with a documented reason and an optional expiration, so accepted risks stop appearing as failures without losing the collector.

Credentials you never really hand over

Envelope encryption at rest; decryption in memory only during a sync; AWS via IAM role assumption with an external ID (no stored secret); Azure and Microsoft 365 secrets exchanged for short-lived tokens at each sync.

A fixed egress IP to allowlist

All collection traffic originates from a fixed IP. Pin the credentials you give RealCISO to it and a leaked credential is unusable anywhere else. 30 days' notice before the address ever changes.

Failure handling that doesn't page you

Throttling and single-collector errors retry next cycle. Only after three consecutive syncs with dead credentials does the integration go to Error and pause — with a message saying what to fix.

Per-environment scoping

Integrations are managed per environment, so a production AWS account can feed your SOC 2 environment while a staging account feeds a development one.

Roadmap

More integrations shipping

Additional categories in active development.

Version control systemsTask trackersHRISSecurity awareness training
Common Questions

Integrations FAQ

What does RealCISO actually collect from a connected account?

Point-in-time snapshots of configuration — which S3 buckets exist and whether they are encrypted, which users have MFA, which devices are enrolled and encrypted. Collectors run every 12 hours by default and store the snapshot as evidence; automated tests then grade it pass or fail. RealCISO never reads file contents, mailboxes, or device data beyond configuration.

Can an automated test change my control assessment?

No. Tests are informational. When one flips from pass to fail the result appears on the Tests page and the control page and is recorded in history, but the control's assessment stays exactly where you set it until a person changes it. A test can only see what is connected — it cannot vouch for the 50 employees on a local directory it has never heard of.

Is the access read-only, and how are credentials stored?

Every integration uses read-only permissions — SecurityAudit for AWS, Reader for Azure, Viewer for GCP, read-only scopes for identity providers. Credentials are envelope-encrypted at rest, decrypted in memory only for the duration of a sync, and AWS uses IAM role assumption with an external ID so no long-lived AWS secret is stored. All collection traffic originates from a single fixed IP you can allowlist, with 30 days' notice before it ever changes.

What if a test flags something we've accepted as a risk?

Waive the test with a documented reason and an optional expiry, or switch off an individual test — or a whole collector — without disconnecting the integration. Disabled items freeze at their last collected state; nothing is deleted and history is never rewritten.

How much of an assessment can integrations cover?

Connecting just cloud and identity providers evidences up to 57% of RealCISO's 289-question assessment library, measured July 2026, with technical domains like access control and monitoring running 80–96%. Endpoint, EDR and vulnerability-management integrations add coverage on top of that. Pen-test reports, training records and physical-security evidence still need a human to upload them.

Which plans include Continuous Compliance?

It is a $100-per-month add-on on Essentials and Professional, included on Enterprise and Enterprise Plus, and bundled into the partner Complete client licence. Every future connector is included at no extra charge.

Explore the Platform

Go deeper on any capability

Where automated evidence goes once it is collected.

Trusted by 3,000+ Organizations

See your own tests within hours

Connect an integration and watch your assessment fill itself in — live tests, real configuration, mapped to your frameworks.

Start Free Book a Demo