Command59 connections · 12 categories · No agents Advisory & software · Led by a practicing CISO and CIO
CommandIntegrations

Connect the stack
you already run.

Command reads live configuration from the identity, cloud, endpoint, code and email tools you already pay for, and turns it into control evidence. No agents to babysit, no quarterly screenshot request.

Browse all 59

Fig. 01 · Program metrics, read from live connections

Command Program Metrics
Program metricsTracked automatically
Secure score · identity86.89%On track· Target 80%Entra · 08-02
Zones at minimum TLS88.89%Off track· Target 100%Cloudflare · 08-02
Open Dependabot alerts1No goal setGitHub · 08-02
DKIM signing enabled100%On track· Target 100%Workspace · 08-02
EDR coverage+11.0pp95%Off track· Target 100%CrowdStrike · 08-02
Admin accounts with MFA-1.4pp94.4%Off track· Target 100%Okta · 08-02
Control efficacy gaps9 failing SLA
Default branches have a protection ruleConfiguration management · GitHub · PR.PS-010% → 100% Repositories have secret scanning enabledNetwork monitoring · GitHub · DE.CM-010% → 100% AWS Config recorder enabledAsset inventory · AWS · CIS 1.10% → 100% At least one conditional access policy is enabledAuthentication · Entra · PR.AA-030% → 100% S3 buckets block public accessData protection · AWS · CIS 2.1.50% → 100% Root account has no active access keysPrivileged access · AWS · CIS 1.40% → 100% All zones enforce TLS 1.2 or higherData in transit · Cloudflare · PR.DS-0289% → 100% Endpoint agents reported in the last 24hEndpoint protection · CrowdStrike · DE.CM-0195% → 100% Admin sign-ins require phishing-resistant MFAAuthentication · Okta · PR.AA-0394% → 100%

An integration that only imports alerts gives you one more inbox. Command reads the configuration behind the tool, and asks whether the control you claim is actually implemented, so a connection produces evidence instead of noise.

§ 01What a connection does

Connections become
control evidence.

You connect a tool once. Command reads its live configuration, decides which controls that configuration evidences, attaches the proof, and raises a finding the moment the configuration drifts away from what the control requires.

Command Monitoring Connections
Attack surface, operations, connections and technology in one placeMonitoring
+ Add connection
Attack surfaceOperationsConnectionsTechnology
EntraActiveMicrosoft Entra IDLast synced Jul 24, 11:00 PM
AWSActiveAmazon Web ServicesLast synced Jul 24, 11:00 PM
GitHubActiveGitHubLast synced Jul 24, 11:00 PM
CloudflareActiveCloudflareLast synced Jul 24, 11:00 PM
GCPActiveGoogle CloudLast synced Jul 24, 11:00 PM
WorkspaceActiveGoogle WorkspaceLast synced Jul 24, 11:00 PM
Command Controls CC6.1
SOC 2 · access controlsLogical access is restricted to authorized users
PartialNIST PR.AA-03CIS v8 · 6.5
Evidence · read from connections
MFA enrollment · 202 of 214 usersEntra
Conditional access policy · 6 rules activeEntra
Admin role assignments · 9 accountsAWS
Refreshed nightlyDrift raises a finding
The control, evidenced

Command decides which controls a connection speaks to, attaches the live reading as evidence, and re-reads it nightly.

12 of 214 users are exempt from MFA.

That is not an alert. It is a control you are claiming, partially implemented, with the number attached and someone to fix it. The moment that number moves the wrong way, it is a finding with a due date.

01 · Connect

Five minutes a tool.

Each connection is an OAuth consent screen and a read-only scope. No agents to deploy, no network changes, nothing for your team to maintain afterwards.

02 · Validate

Read the live config.

Command scans each connection to test whether the control is genuinely implemented, turning real configuration into evidence and drift into findings.

03 · Act

Metrics, then movement.

Live metrics land on the Command dashboard the moment a tool is connected. Findings route into the ticketing and on-call queues that own the fix, and briefings arrive in the channels your team already uses.

§ 02The directory

All 59,
by category.

Twelve categories, weighted toward the systems that actually carry control evidence: identity, cloud, endpoint and code. More are added every release.

OktaIdentity & access

Sync users, groups and MFA enrollment to validate access and authentication controls.

Microsoft Entra IDIdentity & access

Pull identities and conditional-access policy as live evidence for your access controls.

Cisco DuoIdentity & access

Verify multi-factor coverage across the workforce and flag the exemptions automatically.

JumpCloudIdentity & access

Validate directory, SSO and device policy from a single connected source.

OneLoginIdentity & access

Confirm SSO and access-policy enforcement across your application estate.

Ping IdentityIdentity & access

Evidence SSO and MFA enforcement across the apps Ping protects.

1PasswordIdentity & access

Validate vault policy and confirm workforce credential hygiene across the team.

LastPassIdentity & access

Confirm password manager enrollment and vault security policy across users.

CyberArkPrivileged access

Validate privileged-access controls and vault policy across admin and service accounts.

BeyondTrustPrivileged access

Evidence privileged session control and least-privilege enforcement across the estate.

Amazon Web ServicesCloud

Scan account configuration for control validation and catch drift as it happens.

Microsoft AzureCloud

Validate cloud posture and resource configuration against your control set.

Google CloudCloud

Check GCP configuration and IAM against control requirements continuously.

CloudflareCloud

Verify edge, DNS and WAF configuration against your network control baseline.

WizCloud security

Bring cloud risks and misconfigurations in as findings, tracked to closure.

Palo Alto NetworksNetwork security

Read firewall and threat-prevention policy to evidence perimeter controls at their current setting.

FortinetNetwork security

Confirm firewall rule, segmentation and threat-feed configuration across the FortiGate estate.

ZscalerSecure edge

Evidence web and private-access policy enforcement for every user, on or off the network.

NetskopeSecure edge

Validate SaaS, web and data policy across the apps your workforce actually reaches.

CrowdStrikeEndpoint & device

Pull endpoint coverage and detections into findings, mapped to your controls.

SentinelOneEndpoint & device

Confirm agent coverage across the fleet and surface detections automatically.

Microsoft DefenderEndpoint & device

Validate endpoint protection coverage and pull alerts into the program.

Microsoft IntuneEndpoint & device

Evidence device compliance and MDM enrollment across managed endpoints.

JamfEndpoint & device

Evidence Apple device compliance and MDM enrollment across the Mac fleet.

HuntressManaged EDR

Pull managed detection coverage and analyst-reviewed incidents into the findings queue.

QualysVulnerability

Bring vulnerability scan results in as tracked findings with owners and due dates.

Rapid7Vulnerability

Sync vulnerability findings and remediation status into the security program.

TenableVulnerability

Ingest exposure data and track remediation through to closure.

AxoniusAsset management

Reconcile the full asset inventory and surface the gaps your controls do not cover.

JiraTicketing

Push remediation into the queues your team already works, with status synced back.

ServiceNowITSM

Route findings and changes through the ITSM workflows your org already runs.

PagerDutyOn-call

Track incidents against runbooks and connect on-call response to the program.

SlackCommunication

Deliver briefings, approvals and alerts where your team already talks.

Microsoft TeamsCommunication

Send briefings and approval requests straight to your Teams channels.

Google WorkspaceProductivity

Sync documents and evidence, and validate workspace security configuration.

GitHubCode

Scan repository and org settings, and connect code controls to your program.

GitLabCode

Scan repository, group and CI/CD settings, and tie code controls to your program.

BitbucketCode

Scan repository and workspace settings, and tie code controls to your program.

SemgrepCode

Pull static analysis findings into the program and confirm scanning coverage.

SnykCode

Bring dependency and code vulnerability findings into one remediation queue.

Aikido SecurityCode

Pull code, dependency and container findings into one queue, and confirm scanning coverage.

ProofpointEmail & awareness

Confirm email threat protection and data-loss policies are enforced across users.

MimecastEmail & awareness

Validate email security gateway and DMARC enforcement straight from live configuration.

Abnormal SecurityEmail & awareness

Bring inbound email attack and account-takeover signals into findings for triage.

KnowBe4Email & awareness

Evidence security-awareness training completion across the workforce.

BarracudaEmail & awareness

Confirm email gateway protection and inbound threat filtering are enforced.

ForcepointData loss prevention

Confirm data-loss-prevention and web-security policy enforcement across users.

VeeamBackup & recovery

Evidence backup coverage and recovery readiness across protected workloads.

AWS BackupBackup & recovery

Confirm backup policy and retention are enforced across your AWS accounts.

SplunkSIEM & monitoring

Pull detection signals and log-based findings into a single remediation queue.

Microsoft SentinelSIEM & monitoring

Confirm log ingestion and analytics-rule coverage, and bring incidents in as findings.

Elastic SecuritySIEM & monitoring

Evidence detection-rule coverage and pull log-based findings into the remediation queue.

NebulockThreat hunting

Bring hunt results and detection coverage gaps in as findings, tracked to closure.

ZeroFoxExternal threats

Track brand impersonation and external exposure alongside the rest of the program.

WorkdayHR & people

Sync the workforce record so access reviews and offboarding track real joiners and leavers.

HiBobHR & people

Sync the employee roster and joiner-mover-leaver events to keep access reviews current.

BambooHRHR & people

Pull HR records and onboarding events into your access review workflows.

GustoHR & people

Sync workforce records so access reviews and offboarding stay tied to real headcount.

RipplingHR & people

Sync headcount, devices and app access so joiner-mover-leaver events stay current.

Showing all 59 integrationsMore added every release

§ 03Next

Don't see
a tool you run?

Send us the stack. If something you depend on is not here yet, it goes on the roadmap, and we will tell you honestly whether it is weeks or quarters away.

Command overview