sha3:874d6365bb5757418e6b26d40cb189af0bd8e3494094298350658d425f108beaIntactINTEGRATIONS / WHAT IS READ, WHAT IS WRITTEN
Native where it counts. Webhooks where it does not.
PolicyCortex reads configuration and events from the cloud providers most defense and regulated organizations already run: Azure, AWS, and GCP, including GovCloud, Azure Government, and GCC High, through the providers' own APIs, and writes approved remediation through the providers' own primitives. Findings, tickets, notifications, and evidence exports move through the security, GRC, notification, and SIEM tools listed below.
193b05ebd6f42b3fcf1b3aa8935caa6efb6dc7ede7667c5897d2fc4d151e4f1dprev:480ea6ab4dd6Cloud providers
Native integration means consuming events directly and applying remediation through the provider's own primitives, not screen-scraping consoles.
| Provider | What is read | What is written |
|---|---|---|
| AWS, including AWS GovCloud | Resource configuration and events, through the provider APIs, read only. | Approved remediation through the provider's own primitives, each action with a rollback identifier. |
| Azure, including Azure Government and GCC High | Resource configuration and events, through the provider APIs, read only. | Approved remediation through the provider's own primitives, each action with a rollback identifier. |
| GCP, including Assured Workloads | Resource configuration and events, through the provider APIs, read only. | Approved remediation through the provider's own primitives, each action with a rollback identifier. |
AWS and Azure boundaries are supported for ATO packaging; GCP support covers governance, remediation, and control-linked evidence, not an ATO workflow.
7cd34116914c338ab3cc77f45bcf0632dd455406719405be0349267fb46bbeb2prev:193b05ebd6f4Security posture
Posture platforms already in the environment feed the evidence record; no write-back is on record.
| Provider | What is read | What is written |
|---|---|---|
| Microsoft Defender for Cloud | Findings. | None on record |
| AWS Security Hub | Findings. | None on record |
| GCP Security Command Center | Findings. | None on record |
| Wiz | Findings. | None on record |
| Prisma | Findings. | None on record |
d96aeb459c8b12322cbe42f353f85442fca9e8ec3b8a6c9dd90a8167a93fee37prev:7cd34116914cTicketing and GRC
Work items go to the ticketing system your teams already watch; evidence can be imported into an existing GRC tool.
| Provider | What is read | What is written |
|---|---|---|
| ServiceNow ITSM and GRC | None on record | Tickets. |
| Jira | None on record | Tickets. |
| Linear | None on record | Tickets. |
| Azure DevOps | None on record | Tickets. |
| Drata | None on record | Evidence, imported into the GRC tool. |
| Vanta | None on record | Evidence, imported into the GRC tool. |
9f7ebdfebb6bb462b60dd262392af90fe99c2184ba27e03f4a63642ec43ef6ddprev:d96aeb459c8bNotifications
Outbound only.
| Provider | What is read | What is written |
|---|---|---|
| Slack | None on record | Notifications. |
| Microsoft Teams | None on record | Notifications. |
| PagerDuty | None on record | Notifications. |
| None on record | Notifications. | |
| Webhook | None on record | Notifications, as events. |
730aabe0268daa105e9597ab158690dff8136dc538033926ce3753fe0a41eaf1prev:9f7ebdfebb6bAI and ML platforms
The AI estate inventory enumerates every model and agent in scope with identities, channels, egress paths, and binding envelope, as of a timestamp the customer chooses.
| Provider | What is read | What is written |
|---|---|---|
| Azure OpenAI | Models and agents in scope, for the AI estate inventory. | None on record |
| AWS Bedrock | Models and agents in scope, for the AI estate inventory. | None on record |
| GCP Vertex AI | Models and agents in scope, for the AI estate inventory. | None on record |
| OpenAI API | Models and agents in scope, for the AI estate inventory. | None on record |
| Anthropic | Models and agents in scope, for the AI estate inventory. | None on record |
| Hugging Face | Models and agents in scope, for the AI estate inventory. | None on record |
| MLflow | Models and agents in scope, for the AI estate inventory. | None on record |
8f283ab0ea0b086a6d9bd446c1f721fe113e37faf918c1eafb4f7d3c00d5a408prev:730aabe0268dAudit and evidence
Packages export as OSCAL 1.1.2 with SSP, SAR, POA&M, eMASS XML, and evidence indexes generated from one implementation record.
| Provider | What is read | What is written |
|---|---|---|
| OSCAL 1.1.2 | None on record | SSP, SAR, POA&M, and evidence indexes. |
| eMASS | None on record | eMASS XML, for the assessor's submission. |
| Splunk | None on record | Chained records, as events. |
| Microsoft Sentinel | None on record | Chained records, as events. |
| Datadog | None on record | Chained records, as events. |
| Custom SIEM via webhook | None on record | Chained records, as events. |
874d6365bb5757418e6b26d40cb189af0bd8e3494094298350658d425f108beaprev:8f283ab0ea0bWhat this record is not
If your tool exposes an API, we can almost certainly integrate. Webhooks for outbound events; REST or GraphQL for inbound.
Missing one? Tell us what you run.