Skip to content
Automated Evidence Collection

Connect your cloud

Automated evidence collection from AWS, GitHub, Azure, GCP, and identity providers. Each integration installs as a standalone companion skill.

AWS Integration

Available Now

15 Automated Security Checks

Connect your AWS account and AuditClaw continuously monitors your infrastructure for compliance.

01

IAM

Password policies, MFA, access keys

02

S3

Bucket encryption, public access, versioning

03

CloudTrail

Logging enabled, multi-region

04

VPC

Flow logs, security groups, NACLs

05

KMS

Key rotation, key policies

06

EC2

EBS encryption, public instances

07

RDS

Encryption at rest, backups, public access

08

SecurityHub

Findings, standards compliance

09

GuardDuty

Threat detection status

10

Lambda

Function policies, VPC config

11

CloudWatch

Log groups, alarms, metrics

12

Config

Recording status, rules

13

EKS/ECS

Container security, task definitions

14

ELB

SSL termination, access logs

15

Credential Report

User credential status

Setup

Connect via IAM Role; no access keys needed. AuditClaw handles the rest.

Mapped Frameworks

SOC 2 ISO 27001 HIPAA NIST CSF FedRAMP

GitHub Integration

Available Now

9 Automated Repository Checks

Monitor your GitHub organization's security posture automatically.

01

Branch Protection

Protected branches, review requirements

02

Secret Scanning

Exposed secrets detection

03

Dependabot

Vulnerability alerts, auto-updates

04

Two-Factor Auth

Organization 2FA enforcement

05

Deploy Keys

Key management and rotation

06

Audit Log

Activity monitoring

07

Webhooks

Webhook security configuration

08

CODEOWNERS

Code review ownership

09

CI/CD

Actions workflow security

Setup

Provide a GitHub token with read-only permissions.

Mapped Frameworks

SOC 2 ISO 27001 CIS Controls CMMC

Azure Integration

Available Now

7 Automated Security Checks

Monitor your Azure subscription for storage, networking, Key Vault, and Defender compliance.

01

Storage

Blob encryption, HTTPS-only, access tiers

02

Network

NSG rules, open ports, flow logs

03

Key Vault

Soft delete, purge protection, access policies

04

SQL

TDE encryption, auditing, firewall rules

05

Compute

Disk encryption, extensions, managed identity

06

App Service

HTTPS-only, TLS version, authentication

07

Defender

Security Center recommendations, secure score

Setup

Create a Service Principal with Reader + Security Reader roles.

Mapped Frameworks

SOC 2 ISO 27001 HIPAA CIS Controls

Google Cloud

Available Now

9 Automated Security Checks

01

Cloud Storage

Bucket encryption, public access, uniform access

02

Firewall

Open ports, default deny, VPC rules

03

IAM

Service account keys, over-privileged roles

04

Logging

Audit logs enabled, log sinks configured

05

KMS

Key rotation, key ring policies

06

DNS

DNSSEC enabled, zone configuration

07

BigQuery

Dataset access controls, encryption

08

Compute

Instance metadata, serial port access

09

Cloud SQL

SSL enforcement, public IP, backups

SOC 2 ISO 27001 NIST CSF CIS Controls

Identity Providers

Available Now

8 Checks: Google Workspace + Okta

01

Google MFA

MFA enrollment status across all users

02

Google Admins

Admin role audit, super admin count

03

Google Inactive

Inactive user detection, last login

04

Google Passwords

Password policy compliance

05

Okta MFA

MFA factor enrollment status

06

Okta Passwords

Password policy strength

07

Okta Inactive

Inactive user accounts

08

Okta Sessions

Session lifetime, idle timeout

SOC 2 ISO 27001 HIPAA NIST 800-53

How integrations work

Three steps from zero to continuous compliance monitoring.

01

Register

$ add integration --provider aws --name "Production"

Connect your provider with a single command. IAM Roles, GitHub Apps, and certificate-based auth are supported, so you can avoid long-lived static credentials.

02

Sync

Collecting evidence...

AuditClaw collects evidence automatically on your schedule. Daily, hourly, or on-demand.

03

Monitor

Drift detected: S3 public access

Drift detection alerts you to any configuration regressions before auditors find them.

Integration health

Real-time visibility into the status of every connected integration.

AWS Production

Healthy

Last sync: 2 hours ago 45 items

GitHub Main Org

Healthy

Last sync: 6 hours ago 28 items

Azure Subscription

Healthy

Last sync: 4 hours ago 21 items

Google Cloud

Healthy

Last sync: 1 hour ago 18 items

Identity Providers

Healthy

Last sync: 3 hours ago 16 items

Connect your first integration

Start collecting compliance evidence automatically. 48 security checks across 5 providers, set up in under five minutes each.