50+ integrations
Evidence collected from the tools you already run
Connect cloud, identity, code, ticketing and security tooling once. Certifyi pulls the configuration and activity evidence auditors ask for, timestamps and hashes it, and maps it to the controls it proves. No screenshots, no agents to babysit.
Cloud
Cloud infrastructure
AWS, Microsoft Azure, Google Cloud, Cloudflare
Encryption at rest, logging, IAM configuration, network rules, backup settings, MFA on root and privileged accounts.
Identity
Identity and access
Okta, Auth0, Google Workspace, Microsoft Entra
User inventory, MFA enforcement, joiner and leaver timing, privileged roles, and the access-review evidence auditors sample first.
Code
Source control and CI
GitHub, GitLab
Branch protection, code review on every merge, secret scanning, dependency alerts and deployment approvals for change management.
Work
Ticketing and collaboration
Jira, Linear, Asana, Slack, Notion, Zoom
Change tickets, incident timelines, approvals and policy acknowledgement campaigns linked to the people who completed them.
Security
Security and observability
Datadog, Splunk, CrowdStrike, Snyk
Endpoint protection coverage, vulnerability findings with remediation SLAs, alert configuration and log retention evidence.
Runtime
Containers and platforms
Kubernetes, Docker, MongoDB, PostgreSQL, Stripe
Configuration baselines, image scanning, database encryption and access, and payment-provider attestations for PCI scope.
How it works
Connect once, prove continuously
- Read-only connections. Certifyi requests the minimum scopes needed to read configuration and activity; it never changes your systems.
- Evidence hashed on arrival. Each collected artefact carries a digest and a timestamp, so the auditor can verify it is the file that was collected.
- Mapped to controls. One piece of evidence satisfies every framework that needs it: SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR.
- Drift alerts. When a setting changes, the control shows it the same day, not at the next audit.
Not on the list?
Certifyi adds connectors on request when a customer’s scope needs them, and evidence from any tool can be collected through scheduled exports or the API. Tell us what you run and we will confirm coverage before you commit.
Book a readiness call or email [email protected].
Integration questions
Do integrations need an agent installed?
No. All connectors are API-based and read-only. There is nothing to deploy on servers or laptops for evidence collection.
What if our cloud account is shared with other products?
Scope is set at connection time by account, project or organisation unit, so only in-scope resources are collected and shown to the auditor.
How often is evidence refreshed?
Configuration evidence daily and on change; activity evidence such as access reviews and tickets as they happen. Auditors sample from the collected history rather than from screenshots taken before the audit.
See your evidence collecting in the first week
Integrations are connected in week two of every engagement so the audit trail starts while controls are still being built.