Connect the platforms you already run. Evidence collects itself.
RealCISO pulls live configuration every 12 hours, snapshots it as audit evidence, and grades it against automated pass/fail tests mapped to your frameworks — with read-only access and credentials it never holds longer than a sync.
Start Free Book a Demo

4.8/5 across 223 reviews on SourceForge · #1 vCISO platform on G2, Summer 2026
Counts from the live ruleset, production-confirmed August 2026. Per-provider test counts overlap where Azure and Microsoft 365 share Entra ID tests.
Collectors gather. Tests judge. You decide.
Three layers, deliberately kept separate.
1 · Evidence
Automated jobs pull live configuration on a schedule and store a timestamped snapshot straight from the provider's API. No judgment — "here are your 23 S3 buckets and their encryption settings." Changes between syncs are recorded in a timeline.
2 · Tests
Pass/fail checks evaluated against each snapshot: "all S3 buckets are encrypted", "MFA is enforced for privileged roles." Every result surfaces against the control, the question and the framework it affects, with full history.
3 · Control assessment
Your team's call. Tests and evidence are inputs; the control status is always a human decision. A control can have every test passing and still be Partially Met because of systems the integration cannot see.
If evidence and tests were combined, the platform would tell you "your AWS MFA is compliant" while 50 employees sit on local Active Directory that AWS has never seen. If tests and assessment were combined, the platform would be making audit decisions on your behalf. Three layers keep the product honest about what it can and cannot see — and keep you in control.
Fifteen integrations, live today
Cloud, identity, endpoint management, EDR, vulnerability management and network — plus evidence from RealCISO itself.
Microsoft Azure
VMs, storage, SQL, Key Vault, networking, NSGs, RBAC, backup, Defender, AKS, Cosmos DB, Entra ID, conditional access
Amazon Web Services
IAM, S3, EC2, RDS, KMS, CloudTrail, GuardDuty, Secrets Manager, backup, security alerting
Google Cloud
IAM, Cloud SQL, GKE, KMS, firewall, logging & alerting, DNS, API keys, service accounts
Microsoft 365
Entra ID identity & MFA, conditional access, authentication methods, session controls, guest access, app credential hygiene, SSO coverage, access review
Iru (formerly Kandji)
Whole-fleet inventory (Macs, iPhones, iPads, Windows and Android); Mac security posture — FileVault & key escrow, application firewall, Gatekeeper & XProtect, SIP, secure boot — plus profiles, blueprints, admins and audit log
Google Workspace
Admin roles, 2SV/MFA enrollment & enforcement, Drive external sharing, Gmail security, group governance, SSO, domain verification
Enclave by SideChannel
Asset inventory & discovery, installed software with CVE exposure, vulnerability scan currency, network microsegmentation, host firewall coverage, TLS certificate discovery
Okta
MFA enforcement, password & session policy, SSO coverage, network zones, device & access review
Microsoft Intune
Managed device inventory, compliance state & policies, disk encryption, app protection & BYOD workspace separation, configuration profiles, detected software
RealCISO Platform
Policy reviews, risk register, vendor inventory, classifications & TPRM assessments — evidence from the platform itself
ConnectWise Platform
Managed endpoint inventory, antivirus, firewall & TPM state, OS and third-party patch compliance, endpoint CVEs, installed software, sites, device groups & policies
Jamf Pro
Mac inventory with FileVault, SIP, Gatekeeper, firewall & secure boot state, enrolled Apple fleet, smart & static groups, configuration profiles, API role privileges
Tenable Vulnerability Management
Findings with severity & remediation age, CIS and STIG benchmark results, scan schedules & coverage, agent deployment, authenticated scanning, user & role access
Qualys VMDR
Detections with severity, detection age & CVE mapping, vulnerability definitions, asset inventory with scan recency and cloud agent coverage
CrowdStrike Falcon
Endpoint protection coverage — sensor inventory with OS and sensor version, sensor contact currency, reduced functionality mode, applied prevention policy
Good to know: Entra ID identity coverage (MFA, conditional access, privileged roles) ships through either a Microsoft 365 or an Azure connection — whichever you connect first — so those two cards overlap and sum to more than the 386 distinct tests. Endpoint integrations describe the machines themselves, including on-premises servers and laptops that never appear in a cloud API. Iru inventories your whole fleet, Windows and Android included; its detailed security posture comes from Iru's Prism reporting, which covers macOS only.
More than half your assessment, from cloud and identity alone
Connecting AWS, Azure or Google Cloud alongside Microsoft 365, Google Workspace or Okta evidences up to 57% of a full security assessment without a single document upload; technical domains such as access control, platform security and monitoring run 80–96% automated. Endpoint management, EDR and vulnerability-management integrations add coverage on top of that figure. Results depend on which integrations you connect and how your environment is configured.
Built for your security team's review
Turn things off without disconnecting
Each collector has a "collect evidence" switch and an "evaluate tests" switch; each test has its own. Disabled items freeze — nothing is deleted, history is never rewritten. Archive hides evidence but never deletes it.
Waive a test, with a reason
A test that flags an accepted risk can be waived with a documented reason and an optional expiration, so accepted risks stop appearing as failures without losing the collector.
Credentials you never really hand over
Envelope encryption at rest; decryption in memory only during a sync; AWS via IAM role assumption with an external ID (no stored secret); Azure and Microsoft 365 secrets exchanged for short-lived tokens at each sync.
A fixed egress IP to allowlist
All collection traffic originates from a fixed IP. Pin the credentials you give RealCISO to it and a leaked credential is unusable anywhere else. 30 days' notice before the address ever changes.
Failure handling that doesn't page you
Throttling and single-collector errors retry next cycle. Only after three consecutive syncs with dead credentials does the integration go to Error and pause — with a message saying what to fix.
Per-environment scoping
Integrations are managed per environment, so a production AWS account can feed your SOC 2 environment while a staging account feeds a development one.
More integrations shipping
Additional categories in active development.
Integrations FAQ
What does RealCISO actually collect from a connected account?
Point-in-time snapshots of configuration — which S3 buckets exist and whether they are encrypted, which users have MFA, which devices are enrolled and encrypted. Collectors run every 12 hours by default and store the snapshot as evidence; automated tests then grade it pass or fail. RealCISO never reads file contents, mailboxes, or device data beyond configuration.
Can an automated test change my control assessment?
No. Tests are informational. When one flips from pass to fail the result appears on the Tests page and the control page and is recorded in history, but the control's assessment stays exactly where you set it until a person changes it. A test can only see what is connected — it cannot vouch for the 50 employees on a local directory it has never heard of.
Is the access read-only, and how are credentials stored?
Every integration uses read-only permissions — SecurityAudit for AWS, Reader for Azure, Viewer for GCP, read-only scopes for identity providers. Credentials are envelope-encrypted at rest, decrypted in memory only for the duration of a sync, and AWS uses IAM role assumption with an external ID so no long-lived AWS secret is stored. All collection traffic originates from a single fixed IP you can allowlist, with 30 days' notice before it ever changes.
What if a test flags something we've accepted as a risk?
Waive the test with a documented reason and an optional expiry, or switch off an individual test — or a whole collector — without disconnecting the integration. Disabled items freeze at their last collected state; nothing is deleted and history is never rewritten.
How much of an assessment can integrations cover?
Connecting just cloud and identity providers evidences up to 57% of RealCISO's 289-question assessment library, measured July 2026, with technical domains like access control and monitoring running 80–96%. Endpoint, EDR and vulnerability-management integrations add coverage on top of that. Pen-test reports, training records and physical-security evidence still need a human to upload them.
Which plans include Continuous Compliance?
It is a $100-per-month add-on on Essentials and Professional, included on Enterprise and Enterprise Plus, and bundled into the partner Complete client licence. Every future connector is included at no extra charge.
Go deeper on any capability
Where automated evidence goes once it is collected.
See your own tests within hours
Connect an integration and watch your assessment fill itself in — live tests, real configuration, mapped to your frameworks.
Start Free Book a Demo