PURPLEWASP INTEGRATIONS

Your tools.
Your evidence.
One connected view.

Security posture doesn't live in a spreadsheet. Connect the platforms your organisation already uses and turn supported technical signals into meaningful control assurance.

Explore integrations
Optional connections Control-aligned evidence Honest coverage status
CONNECTED ASSURANCE
PURPLEWASP CONTROL PLANECollect. Evaluate. Evidence.
Controls
Evidence
Framework mappings
Facts remain scoped by permission, coverage and the controls an organisation has adopted.
One connectionMultiple independently enabled capabilities where supported
One controlEvidence reused through applicable framework mappings
Your choiceManual, scheduled or supported event-driven refresh
CONNECTED PLATFORMS

Integrations that turn signals into insight.

Five provider connections, each with a clear scope. Choose the capabilities your organisation needs and has permission to access.

Supported providers, not blanket compliance claims
Identity / SaaS / Cloud

Microsoft

Connect Microsoft environments across identity, Microsoft 365 security and Azure resource posture through one shared tenant connection.

Capability areas
Entra IDMicrosoft 365AzureIntune*Defender*

* Intune and Defender require suitable licensing and further licensed-tenant validation.

Cloud posture

Amazon Web Services

Collect selected account, identity, resource and security-service information using an AWS account connection and independent capabilities.

Capability areas
Account & IAMResource inventoryCloudTrailAWS ConfigGuardDutySecurity Hub*Inspector*

* Availability depends on the services enabled, account permissions and individual capability readiness.

Identity / Collaboration

Google Workspace

Connect a Google Workspace organisation through administrator-authorised OAuth to collect accessible identity and activity evidence.

Capability areas
Workspace identityAudit activityAdministrator-approved OAuth

Access depends on Workspace edition, granted scopes and available audit streams.

Developer security

GitHub

Connect your organisation with a GitHub App. Collect repository controls and available code-security signals with optional event-driven refresh.

Capability areas
Organisation securityRepository rulesCode securityAudit scopeWebhook Auto-Refresh

Repository-event refresh is validated. Some code-security and audit streams may return partial coverage.

Vulnerability / Exposure

Qualys

Bring vulnerability findings and associated source information into PurpleWASP to support asset and exposure workflows.

Capability areas
Vulnerability findingsAsset contextRisk linkage

Requires a suitable Qualys subscription, enabled integration and permitted API access.

Showing 5 platforms

HOW IT WORKS

From a provider signal to a defensible control test.

Integrations are not a shortcut around governance. They reduce manual collection and add traceable technical context.

01

Connect

An authorised administrator configures an optional provider connection and grants only the necessary access.

02

Collect

PurpleWASP collects supported facts and records limitations when an API, permission or licensed stream is unavailable.

03

Evaluate

Applicable, adopted organisation controls can be evaluated against relevant observations using defined automated rules.

04

Evidence

Control results and provenance remain traceable and can support multiple mapped compliance frameworks.

BUILT FOR REAL ASSURANCE

No pretend green ticks.

A successful connection does not mean every security requirement is met. PurpleWASP distinguishes successful collection, partial coverage, and inconclusive control tests when required facts are unavailable.

Explore our governance platform
Understand the scopePermissions, subscriptions and repository selection matter.
Preserve the historyEvidence and test runs retain their provenance as newer results arrive.
Reduce repeat effortOne collected fact can inform a control used by several frameworks.
GOOD TO KNOW

A few useful answers.

Set the right expectations before connecting a platform.

Do I have to connect every provider?

No. Integrations are optional. Manual evidence remains supported, and administrators can enable only the providers and capabilities they need.

Does connecting a provider make us compliant?

No. A connection supplies technical observations. Controls still need to be applicable and adopted, and an automated test addresses a specific condition rather than an entire framework.

What happens when an API is unavailable?

PurpleWASP can report partial collection or an inconclusive test. Unavailable evidence should not be treated as proof that there is no issue.

Can GitHub refresh evidence when something changes?

For supported GitHub events, the tenant administrator can opt in to Auto-Refresh. When turned off, supported signed event metadata can still be recorded without queueing a webhook-triggered collection.

READY TO CONNECT THE DOTS?

Make your existing security investments work harder.

See how PurpleWASP can fit your tools, controls and compliance workflows together.