Register:Integrations7 recordsSHA3-256 chainedSealed Amended head sha3:874d6365bb5757418e6b26d40cb189af0bd8e3494094298350658d425f108beaIntact

INTEGRATIONS / WHAT IS READ, WHAT IS WRITTEN

Native where it counts. Webhooks where it does not.

PolicyCortex reads configuration and events from the cloud providers most defense and regulated organizations already run: Azure, AWS, and GCP, including GovCloud, Azure Government, and GCC High, through the providers' own APIs, and writes approved remediation through the providers' own primitives. Findings, tickets, notifications, and evidence exports move through the security, GRC, notification, and SIEM tools listed below.

REC 0000CLOUD PROVIDERSsha3-256193b05ebd6f42b3fcf1b3aa8935caa6efb6dc7ede7667c5897d2fc4d151e4f1dprev:480ea6ab4dd6

Cloud providers

Native integration means consuming events directly and applying remediation through the provider's own primitives, not screen-scraping consoles.

Cloud providers3 providers
ProviderWhat is readWhat is written
AWS, including AWS GovCloudResource configuration and events, through the provider APIs, read only.Approved remediation through the provider's own primitives, each action with a rollback identifier.
Azure, including Azure Government and GCC HighResource configuration and events, through the provider APIs, read only.Approved remediation through the provider's own primitives, each action with a rollback identifier.
GCP, including Assured WorkloadsResource configuration and events, through the provider APIs, read only.Approved remediation through the provider's own primitives, each action with a rollback identifier.

AWS and Azure boundaries are supported for ATO packaging; GCP support covers governance, remediation, and control-linked evidence, not an ATO workflow.

REC 0001SECURITY POSTUREsha3-2567cd34116914c338ab3cc77f45bcf0632dd455406719405be0349267fb46bbeb2prev:193b05ebd6f4

Security posture

Posture platforms already in the environment feed the evidence record; no write-back is on record.

Security posture5 providers
ProviderWhat is readWhat is written
Microsoft Defender for CloudFindings.None on record
AWS Security HubFindings.None on record
GCP Security Command CenterFindings.None on record
WizFindings.None on record
PrismaFindings.None on record
REC 0002TICKETING AND GRCsha3-256d96aeb459c8b12322cbe42f353f85442fca9e8ec3b8a6c9dd90a8167a93fee37prev:7cd34116914c

Ticketing and GRC

Work items go to the ticketing system your teams already watch; evidence can be imported into an existing GRC tool.

Ticketing and GRC6 providers
ProviderWhat is readWhat is written
ServiceNow ITSM and GRCNone on recordTickets.
JiraNone on recordTickets.
LinearNone on recordTickets.
Azure DevOpsNone on recordTickets.
DrataNone on recordEvidence, imported into the GRC tool.
VantaNone on recordEvidence, imported into the GRC tool.
REC 0003NOTIFICATIONSsha3-2569f7ebdfebb6bb462b60dd262392af90fe99c2184ba27e03f4a63642ec43ef6ddprev:d96aeb459c8b

Notifications

Outbound only.

Notifications5 providers
ProviderWhat is readWhat is written
SlackNone on recordNotifications.
Microsoft TeamsNone on recordNotifications.
PagerDutyNone on recordNotifications.
EmailNone on recordNotifications.
WebhookNone on recordNotifications, as events.
REC 0004AI AND ML PLATFORMSsha3-256730aabe0268daa105e9597ab158690dff8136dc538033926ce3753fe0a41eaf1prev:9f7ebdfebb6b

AI and ML platforms

The AI estate inventory enumerates every model and agent in scope with identities, channels, egress paths, and binding envelope, as of a timestamp the customer chooses.

AI and ML platforms7 providers
ProviderWhat is readWhat is written
Azure OpenAIModels and agents in scope, for the AI estate inventory.None on record
AWS BedrockModels and agents in scope, for the AI estate inventory.None on record
GCP Vertex AIModels and agents in scope, for the AI estate inventory.None on record
OpenAI APIModels and agents in scope, for the AI estate inventory.None on record
AnthropicModels and agents in scope, for the AI estate inventory.None on record
Hugging FaceModels and agents in scope, for the AI estate inventory.None on record
MLflowModels and agents in scope, for the AI estate inventory.None on record
REC 0005AUDIT AND EVIDENCEsha3-2568f283ab0ea0b086a6d9bd446c1f721fe113e37faf918c1eafb4f7d3c00d5a408prev:730aabe0268d

Audit and evidence

Packages export as OSCAL 1.1.2 with SSP, SAR, POA&M, eMASS XML, and evidence indexes generated from one implementation record.

Audit and evidence6 providers
ProviderWhat is readWhat is written
OSCAL 1.1.2None on recordSSP, SAR, POA&M, and evidence indexes.
eMASSNone on recordeMASS XML, for the assessor's submission.
SplunkNone on recordChained records, as events.
Microsoft SentinelNone on recordChained records, as events.
DatadogNone on recordChained records, as events.
Custom SIEM via webhookNone on recordChained records, as events.
REC 0006STATED LIMITsha3-256874d6365bb5757418e6b26d40cb189af0bd8e3494094298350658d425f108beaprev:8f283ab0ea0b

What this record is not

If your tool exposes an API, we can almost certainly integrate. Webhooks for outbound events; REST or GraphQL for inbound.

Missing one? Tell us what you run.

Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000CLOUD PROVIDERS193b05ebd6f4480ea6ab4dd6
REC 0001SECURITY POSTURE7cd34116914c193b05ebd6f4
REC 0002TICKETING AND GRCd96aeb459c8b7cd34116914c
REC 0003NOTIFICATIONS9f7ebdfebb6bd96aeb459c8b
REC 0004AI AND ML PLATFORMS730aabe0268d9f7ebdfebb6b
REC 0005AUDIT AND EVIDENCE8f283ab0ea0b730aabe0268d
REC 0006STATED LIMIT874d6365bb578f283ab0ea0b

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:874d6365bb57. The product does the same thing to your evidence.

Photograph: Bill Hrybyk, NASA Goddard Space Flight Center, Public domain (NASA, 17 U.S.C. 105). Source