Connectors explained: the apps Compliance One plugs into
The whole promise of modern compliance is that evidence should collect itself. No more chasing colleagues for screenshots, no more pasting console grabs into a folder the night before an audit. For that to be real, the platform has to plug into the systems where the proof actually lives: your cloud, your identity provider, the HR system that holds your joiners and leavers, the laptops your team works on, the ticketing tool where change gets approved, and the chat app where alerts land.
Compliance One ships more than 180 connectors, across a catalogue of close to 300 supported apps teams use every day: cloud, identity, HR, device management, change management, chat and security tooling. We add more regularly. This guide covers what a connector does, the categories we cover, a few of the most popular ones, and how we keep the whole thing secure and genuinely free of per-connector fees.
What a connector actually does
A connector is a read-only link between Compliance One and one of your systems. Once an org admin authorises it, the platform pulls the specific signals that prove a control is working, on a schedule you set, and files each piece of evidence with a timestamp against the controls it satisfies across every framework you run.
So instead of a human attesting that multi-factor authentication is enforced, your identity connector shows it, continuously. Instead of swearing that leavers are deprovisioned, your HR and identity connectors line up the dates. The evidence maintains itself, and when a control drifts you hear about it the week it happens, not eleven months later in front of an auditor.
The categories we cover
- Cloud: the big public clouds, for posture, configuration and logging evidence.
- Identity and single sign-on: who has access, how they authenticate, and whether MFA is enforced.
- HR information systems (HRIS): your source of truth for joiners, movers and leavers.
- Device management (MDM): encryption, screen-lock and patch status across company laptops.
- Change management and development: how code and infrastructure changes get reviewed and approved.
- Chat and alerting: so findings and reminders reach people where they already work.
- Security tooling: password managers, background checks and security-awareness training.
A few you will recognise
We will not list every connector here, and the set keeps growing, but these are some of the widely used apps most companies already run that Compliance One connects to:
- AWS, Microsoft Azure and Google Cloud
- Okta, Microsoft Entra ID and Google Workspace
- GitHub and Jira
- Slack and Microsoft Teams
- 1Password
- BambooHR and Workday
If the app you care about is not in that short list, there is a good chance it is still supported, because the catalogue is broader than the household names above and expands as customers ask. The point is not to collect logos. It is that the systems holding your real evidence are the ones we plug into.
Secure by default
Connectors are configured by org admins, never by individual users, and they request least-privilege, read-only access wherever the vendor supports it. Authorise with per-service OAuth in a click or a scoped API key, and secrets are stored encrypted and never exposed back to the interface. You can disconnect at any time, and you decide whether to keep or purge the evidence a connector collected when you do.
Included, not metered
Here is the part that tends to surprise people coming from other GRC tools: every connector is included. We do not charge per connector, we do not gate integrations behind a higher tier, and there are zero implementation charges to switch them on. Connect as many as you need, because the value of continuous evidence only shows up when the whole stack is plugged in.
The connectors are the difference between a dashboard that claims you are compliant and one that proves it.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.