Microsoft
Connect Microsoft environments across identity, Microsoft 365 security and Azure resource posture through one shared tenant connection.
* Intune and Defender require suitable licensing and further licensed-tenant validation.
Security posture doesn't live in a spreadsheet. Connect the platforms your organisation already uses and turn supported technical signals into meaningful control assurance.
Five provider connections, each with a clear scope. Choose the capabilities your organisation needs and has permission to access.
Connect Microsoft environments across identity, Microsoft 365 security and Azure resource posture through one shared tenant connection.
* Intune and Defender require suitable licensing and further licensed-tenant validation.
Collect selected account, identity, resource and security-service information using an AWS account connection and independent capabilities.
* Availability depends on the services enabled, account permissions and individual capability readiness.
Connect a Google Workspace organisation through administrator-authorised OAuth to collect accessible identity and activity evidence.
Access depends on Workspace edition, granted scopes and available audit streams.
Connect your organisation with a GitHub App. Collect repository controls and available code-security signals with optional event-driven refresh.
Repository-event refresh is validated. Some code-security and audit streams may return partial coverage.
Bring vulnerability findings and associated source information into PurpleWASP to support asset and exposure workflows.
Requires a suitable Qualys subscription, enabled integration and permitted API access.
Showing 5 platforms
Integrations are not a shortcut around governance. They reduce manual collection and add traceable technical context.
An authorised administrator configures an optional provider connection and grants only the necessary access.
PurpleWASP collects supported facts and records limitations when an API, permission or licensed stream is unavailable.
Applicable, adopted organisation controls can be evaluated against relevant observations using defined automated rules.
Control results and provenance remain traceable and can support multiple mapped compliance frameworks.
A successful connection does not mean every security requirement is met. PurpleWASP distinguishes successful collection, partial coverage, and inconclusive control tests when required facts are unavailable.
Explore our governance platformSet the right expectations before connecting a platform.
No. Integrations are optional. Manual evidence remains supported, and administrators can enable only the providers and capabilities they need.
No. A connection supplies technical observations. Controls still need to be applicable and adopted, and an automated test addresses a specific condition rather than an entire framework.
PurpleWASP can report partial collection or an inconclusive test. Unavailable evidence should not be treated as proof that there is no issue.
For supported GitHub events, the tenant administrator can opt in to Auto-Refresh. When turned off, supported signed event metadata can still be recorded without queueing a webhook-triggered collection.
See how PurpleWASP can fit your tools, controls and compliance workflows together.