Microsoft Graph
Microsoft Entra ID
Users, groups and enterprise applications with their assignments. The basis for ownership, RACI and awareness campaigns.
Integrations
KaitoSec connects the systems where your security posture actually lives, from identity and endpoints through cloud and CMDB to monitoring and documents. The platform derives metrics and risk indicators from them automatically. Scope, permissions and mapping are settled with you per connection.
What the connections carry
Catalog
Each source connects through its own driver and normalizes into the same inventory: people, systems, devices, vendors, evidence. What a source reports stays attached to the record with origin and timestamp.
Identity & HR
Microsoft Graph
Users, groups and enterprise applications with their assignments. The basis for ownership, RACI and awareness campaigns.
Microsoft Graph
Managed Windows and macOS devices with assigned user, inventory metadata and reported compliance state.
Graph Security
Endpoint posture and device inventory from Defender XDR. Selected alerts become findings in the register, not a telemetry copy.
REST API
Employee directory with joiners and leavers, department and position. People stay current without manual upkeep.
CMDB & IT documentation
JSON-RPC
CMDB objects by type allowlist, with categories. Your maintained inventory becomes the starting point instead of duplicate work.
REST API
Computer and asset stock, paginated with change detection between runs.
REST API
Hardware and IP hosts from automated IT documentation.
Cloud platforms
Cross-account role
Resource discovery across enabled regions and a curated set of read-only configuration checks. Results attach to controls as technical evidence.
Subscriptions & management groups
Resource discovery and configuration checks across subscriptions and management groups.
Project to organization
Discovery and checks at project, folder or organization level.
Monitoring & network
HTTP API
Live state of monitored devices, polled by the minute. An outage is visible in risk and BCM context, not only in monitoring.
REST API
Devices on the network, identified through network access control. What is missing from the inventory stands out.
DNS & HTTP
Registered web properties are scanned on schedule: DNS, response headers, loaded scripts. Discovered third parties enter the vendor register as candidates.
Documents & collaboration
Microsoft Graph
Explicitly selected sites and libraries, linked or snapshotted with version and hash. SharePoint stays the source of truth, the evidence stays reproducible.
REST API
Selected spaces; pages and attachments as evidence or controlled documentation.
REST API
KaitoSec tasks and Jira issues in two-way sync: status, assignee, due date, deep link. IT keeps working in Jira.
Microsoft Graph
Notifications for tasks, reviews and incidents in the channels you choose. A personal bot handles your own compliance work without putting organisation data into shared chats.
API, import & export
OpenAPI
Documented interface with API keys for your own automation and exports.
Import / export
Import and export assets, people and custom lists by template. The way out of the spreadsheet world without losing data.
OSCAL
Assessment results as machine-readable OSCAL for auditors and authorities.
Every connection is scoped together during rollout: which data flows, which permissions apply, which mapping holds. Your system is not listed? Name the source and your current evidence path. New sources are built on the same driver foundation, so a special system becomes another driver rather than a project of its own.
For developers and AI agents
Your assistants and business systems read and write the register directly instead of parsing PDF exports. Open interfaces, open formats, tight permissions.
mcp · kaitosec
$ mcp connect kaitosec
tools: register · risks · evidence
scope: workspace/grc · delegated
AI assistants reach registers, risks and evidence through the MCP server. What an agent proposes stays justified and traceable.
openapi.json
GET /api/v1/controls?framework=bsi-gs
200 OK · application/json
typed operations · stable error codes
Documented interface with API keys for your own automation and exports.
catalog.oscal.json
"catalog": { "uuid": "…" }
profile · assessment-results
machine-readable Grundschutz: prepared
Catalogues and results, machine-readable. Prepared for the machine-readable Grundschutz.
working-rules.md
least privilege · scoped per connection
every change traceable
revocation: immediate
Least privilege, traceable, revocable. Every connection is scoped together at rollout.
SAML SSO · Trust Center · Built and hosted in Germany · Details in pricing
Working rules
The same rules apply to every connection. They decide whether an integration produces audit-grade evidence or just another data copy.
01
Each driver requests read access to the minimum. SharePoint for example only to explicitly approved sites, never the whole tenant. Write access only where it is the purpose, as in the Jira sync.
02
Findings become candidates, not an unrequested import. You review, activate or archive; only then does an object enter the inventory.
03
Every imported state carries its source, time, version and hash. Evidence you have shown in an audit stays reproducible even when the source changes afterwards.
04
Connection test, schedule, sync runs with logs, pause and revoke per connection. Credentials are stored encrypted (AES-256-GCM).
Process documentation
No driver can read how decisions, escalations and approvals actually happen in your organisation. AI-assisted process documentation captures exactly that and keeps the map current while the company changes. Only on that basis can you decide which process to digitise, which to rebuild and which to hand to an agent. No software makes a process resilient that nobody can describe.
Process knowledge comes from the systems where the work happens and from the people doing it. No interview marathon, and no consultant map nobody recognises two years later.
The result is a living process model in BPMN that updates while the company works.
The process map feeds the BIA, the risk register, the RoPA and the SoA. Criticality, dependencies and owners end up where the management systems need them instead of being captured three times over.
In one call we walk through your system landscape: what gets connected, which permissions are needed, which manual evidence paths disappear.