Skip to content

Integrations

The evidence sits in your systems, not in a spreadsheet folder.

KaitoSec connects the systems where your security posture actually lives, from identity and endpoints through cloud and CMDB to monitoring and documents. The platform derives metrics and risk indicators from them automatically. Scope, permissions and mapping are settled with you per connection.

What the connections carry

Connections in the catalogue
20
Default access to source systems
Read-only
Evidence checked against the audit calendar
continuous
Credentials encrypted
AES-256-GCM

Catalog

One driver per system. One data model behind it.

Each source connects through its own driver and normalizes into the same inventory: people, systems, devices, vendors, evidence. What a source reports stays attached to the record with origin and timestamp.

Identity & HR

Microsoft Graph

Microsoft Entra ID

Users, groups and enterprise applications with their assignments. The basis for ownership, RACI and awareness campaigns.

Microsoft Graph

Microsoft Intune

Managed Windows and macOS devices with assigned user, inventory metadata and reported compliance state.

Graph Security

Microsoft Defender

Endpoint posture and device inventory from Defender XDR. Selected alerts become findings in the register, not a telemetry copy.

REST API

Personio

Employee directory with joiners and leavers, department and position. People stay current without manual upkeep.

CMDB & IT documentation

JSON-RPC

i-doit

CMDB objects by type allowlist, with categories. Your maintained inventory becomes the starting point instead of duplicate work.

REST API

Matrix42

Computer and asset stock, paginated with change detection between runs.

REST API

Docusnap 365

Hardware and IP hosts from automated IT documentation.

Cloud platforms

Cross-account role

AWS

Resource discovery across enabled regions and a curated set of read-only configuration checks. Results attach to controls as technical evidence.

Subscriptions & management groups

Microsoft Azure

Resource discovery and configuration checks across subscriptions and management groups.

Project to organization

Google Cloud

Discovery and checks at project, folder or organization level.

Monitoring & network

HTTP API

PRTG

Live state of monitored devices, polled by the minute. An outage is visible in risk and BCM context, not only in monitoring.

REST API

macmon NAC

Devices on the network, identified through network access control. What is missing from the inventory stands out.

DNS & HTTP

Web discovery

Registered web properties are scanned on schedule: DNS, response headers, loaded scripts. Discovered third parties enter the vendor register as candidates.

Documents & collaboration

Microsoft Graph

SharePoint Online

Explicitly selected sites and libraries, linked or snapshotted with version and hash. SharePoint stays the source of truth, the evidence stays reproducible.

REST API

Confluence

Selected spaces; pages and attachments as evidence or controlled documentation.

REST API

Jira

KaitoSec tasks and Jira issues in two-way sync: status, assignee, due date, deep link. IT keeps working in Jira.

Microsoft Graph

Microsoft Teams

Notifications for tasks, reviews and incidents in the channels you choose. A personal bot handles your own compliance work without putting organisation data into shared chats.

API, import & export

OpenAPI

REST API

Documented interface with API keys for your own automation and exports.

Import / export

Excel & CSV

Import and export assets, people and custom lists by template. The way out of the spreadsheet world without losing data.

OSCAL

OSCAL export

Assessment results as machine-readable OSCAL for auditors and authorities.

Every connection is scoped together during rollout: which data flows, which permissions apply, which mapping holds. Your system is not listed? Name the source and your current evidence path. New sources are built on the same driver foundation, so a special system becomes another driver rather than a project of its own.

For developers and AI agents

Built for the AI era, not for 2010.

Your assistants and business systems read and write the register directly instead of parsing PDF exports. Open interfaces, open formats, tight permissions.

  • mcp · kaitosec

    $ mcp connect kaitosec

    tools: register · risks · evidence

    scope: workspace/grc · delegated

    MCP server

    AI assistants reach registers, risks and evidence through the MCP server. What an agent proposes stays justified and traceable.

    Documentation

  • openapi.json

    GET /api/v1/controls?framework=bsi-gs

    200 OK · application/json

    typed operations · stable error codes

    REST API · OpenAPI

    Documented interface with API keys for your own automation and exports.

    See the interfaces

  • catalog.oscal.json

    "catalog": { "uuid": "…" }

    profile · assessment-results

    machine-readable Grundschutz: prepared

    OSCAL

    Catalogues and results, machine-readable. Prepared for the machine-readable Grundschutz.

    OSCAL at KaitoSec

  • working-rules.md

    least privilege · scoped per connection

    every change traceable

    revocation: immediate

    Working rules

    Least privilege, traceable, revocable. Every connection is scoped together at rollout.

    Review the permissions

Connected systems

  • Microsoft Entra ID
  • Microsoft Intune
  • Microsoft Defender
  • Personio
  • i-doit
  • Microsoft Azure
  • AWS
  • Google Cloud
  • Jira
  • Confluence
  • SharePoint Online
  • Microsoft Teams
  • macmon NAC
  • Matrix42
  • Docusnap 365
  • PRTG
All integrations

SAML SSO · Trust Center · Built and hosted in Germany · Details in pricing

Working rules

Read-only, traceable, revocable.

The same rules apply to every connection. They decide whether an integration produces audit-grade evidence or just another data copy.

01

Least privilege

Each driver requests read access to the minimum. SharePoint for example only to explicitly approved sites, never the whole tenant. Write access only where it is the purpose, as in the Jira sync.

02

Discovery with approval

Findings become candidates, not an unrequested import. You review, activate or archive; only then does an object enter the inventory.

03

Provenance on the record

Every imported state carries its source, time, version and hash. Evidence you have shown in an audit stays reproducible even when the source changes afterwards.

04

Operations with history

Connection test, schedule, sync runs with logs, pause and revoke per connection. Credentials are stored encrypted (AES-256-GCM).

Process documentation

The process map is built automatically and stays current.

No driver can read how decisions, escalations and approvals actually happen in your organisation. AI-assisted process documentation captures exactly that and keeps the map current while the company changes. Only on that basis can you decide which process to digitise, which to rebuild and which to hand to an agent. No software makes a process resilient that nobody can describe.

Captured, not drawn

Process knowledge comes from the systems where the work happens and from the people doing it. No interview marathon, and no consultant map nobody recognises two years later.

BPMN instead of wall art

The result is a living process model in BPMN that updates while the company works.

Straight into the registers

The process map feeds the BIA, the risk register, the RoPA and the SoA. Criticality, dependencies and owners end up where the management systems need them instead of being captured three times over.

Which systems carry your evidence?

In one call we walk through your system landscape: what gets connected, which permissions are needed, which manual evidence paths disappear.