---
title: "Integrations: Cloud, Security, GRC, and AI"
description: "PolicyCortex integrates with AWS, Azure, GCP, Azure Government, GovCloud, ServiceNow, Jira, Slack, Teams, Splunk, Sentinel, and more."
url: https://policycortex.com/integrations
sealed: 2026-09-02
amended: 2026-09-05
register: integrations
records: 7
digest: sha3:874d6365bb5757418e6b26d40cb189af0bd8e3494094298350658d425f108bea
---

# Native where it counts. Webhooks where it does not.

INTEGRATIONS / WHAT IS READ, WHAT IS WRITTEN

PolicyCortex reads configuration and events from the cloud providers most defense and regulated organizations already run: Azure, AWS, and GCP, including GovCloud, Azure Government, and GCC High, through the providers' own APIs, and writes approved remediation through the providers' own primitives. Findings, tickets, notifications, and evidence exports move through the security, GRC, notification, and SIEM tools listed below.

[Request Access](https://app.policycortex.com/auth?mode=request-access) · [Read the architecture](https://policycortex.com/architecture)

## Cloud providers

Native integration means consuming events directly and applying remediation through the provider's own primitives, not screen-scraping consoles.

**Cloud providers**

| Provider | What is read | What is written |
|---|---|---|
| AWS, including AWS GovCloud | Resource configuration and events, through the provider APIs, read only. | Approved remediation through the provider's own primitives, each action with a rollback identifier. |
| Azure, including Azure Government and GCC High | Resource configuration and events, through the provider APIs, read only. | Approved remediation through the provider's own primitives, each action with a rollback identifier. |
| GCP, including Assured Workloads | Resource configuration and events, through the provider APIs, read only. | Approved remediation through the provider's own primitives, each action with a rollback identifier. |

3 providers

AWS and Azure boundaries are supported for ATO packaging; GCP support covers governance, remediation, and control-linked evidence, not an ATO workflow.

## Security posture

Posture platforms already in the environment feed the evidence record; no write-back is on record.

**Security posture**

| Provider | What is read | What is written |
|---|---|---|
| Microsoft Defender for Cloud | Findings. | None on record |
| AWS Security Hub | Findings. | None on record |
| GCP Security Command Center | Findings. | None on record |
| Wiz | Findings. | None on record |
| Prisma | Findings. | None on record |

5 providers

## Ticketing and GRC

Work items go to the ticketing system your teams already watch; evidence can be imported into an existing GRC tool.

**Ticketing and GRC**

| Provider | What is read | What is written |
|---|---|---|
| ServiceNow ITSM and GRC | None on record | Tickets. |
| Jira | None on record | Tickets. |
| Linear | None on record | Tickets. |
| Azure DevOps | None on record | Tickets. |
| Drata | None on record | Evidence, imported into the GRC tool. |
| Vanta | None on record | Evidence, imported into the GRC tool. |

6 providers

## Notifications

Outbound only.

**Notifications**

| Provider | What is read | What is written |
|---|---|---|
| Slack | None on record | Notifications. |
| Microsoft Teams | None on record | Notifications. |
| PagerDuty | None on record | Notifications. |
| Email | None on record | Notifications. |
| Webhook | None on record | Notifications, as events. |

5 providers

## AI and ML platforms

The AI estate inventory enumerates every model and agent in scope with identities, channels, egress paths, and binding envelope, as of a timestamp the customer chooses.

**AI and ML platforms**

| Provider | What is read | What is written |
|---|---|---|
| Azure OpenAI | Models and agents in scope, for the AI estate inventory. | None on record |
| AWS Bedrock | Models and agents in scope, for the AI estate inventory. | None on record |
| GCP Vertex AI | Models and agents in scope, for the AI estate inventory. | None on record |
| OpenAI API | Models and agents in scope, for the AI estate inventory. | None on record |
| Anthropic | Models and agents in scope, for the AI estate inventory. | None on record |
| Hugging Face | Models and agents in scope, for the AI estate inventory. | None on record |
| MLflow | Models and agents in scope, for the AI estate inventory. | None on record |

7 providers

## Audit and evidence

Packages export as OSCAL 1.1.2 with SSP, SAR, POA&M, eMASS XML, and evidence indexes generated from one implementation record.

**Audit and evidence**

| Provider | What is read | What is written |
|---|---|---|
| OSCAL 1.1.2 | None on record | SSP, SAR, POA&M, and evidence indexes. |
| eMASS | None on record | eMASS XML, for the assessor's submission. |
| Splunk | None on record | Chained records, as events. |
| Microsoft Sentinel | None on record | Chained records, as events. |
| Datadog | None on record | Chained records, as events. |
| Custom SIEM via webhook | None on record | Chained records, as events. |

6 providers

## What this record is not

If your tool exposes an API, we can almost certainly integrate. Webhooks for outbound events; REST or GraphQL for inbound.

**Stated limit.** What is not connected is not observed, and the record says so. Integrations not listed here are not represented on this site.

Missing one? Tell us what you run. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | CLOUD PROVIDERS | 193b05ebd6f4 | 480ea6ab4dd6 |
| REC 0001 | SECURITY POSTURE | 7cd34116914c | 193b05ebd6f4 |
| REC 0002 | TICKETING AND GRC | d96aeb459c8b | 7cd34116914c |
| REC 0003 | NOTIFICATIONS | 9f7ebdfebb6b | d96aeb459c8b |
| REC 0004 | AI AND ML PLATFORMS | 730aabe0268d | 9f7ebdfebb6b |
| REC 0005 | AUDIT AND EVIDENCE | 8f283ab0ea0b | 730aabe0268d |
| REC 0006 | STATED LIMIT | 874d6365bb57 | 8f283ab0ea0b |

Head sha3:874d6365bb5757418e6b26d40cb189af0bd8e3494094298350658d425f108bea. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
