Integration setup guides
Connect your tools to replace empty dashboards with your real metrics. Integrations only ever read — most providers offer narrowly-scoped tokens and we request exactly those; where a provider has no scoped token tier, the guide says so plainly and recommends a short expiration. Each guide walks through creating the credential and connecting it — step by step.
Each guide carries an honest verification badge. 2 of 18 integrations have been run against the real provider API with a real credential; the rest are built and tested against the documented API shape but have not yet met a live tenant, and say so on their card.
DevOps & Code
GitHub
Reads repositories, pull requests, GitHub Actions, security alerts, and repo artifact signals to compute Delivery Health, Technical Debt, IT Modernization, Lifecycle Risk, and Security Readiness from real data.
Live-verifiedGitLab
Pulls groups, projects, merge requests, pipelines, deployments, releases, and security findings to feed Delivery Health, Technical Debt, and Security Readiness.
Built · awaiting live verificationGitea
Reads repositories, pull requests, releases, and CI-workflow presence from a self-hosted (or gitea.com) Gitea instance — GitHub-style API — to feed Delivery Health (PR lead time) and Technical Debt (legacy-code + test debt).
Built · awaiting live verificationVercel
Reads production deployments and projects from the Vercel REST API to feed Delivery Health with real release data — deployment frequency and change-failure rate, the two DORA metrics Vercel can prove.
Built · awaiting live verificationAtlassian (Jira + Bitbucket)
Jira Cloud delivery analytics (throughput, lead time, open/aging) plus optional Bitbucket pipeline cadence + change-failure rate — feeding Delivery Health. Atlassian posture also underpins compliance control evidence — Bitbucket change management, Guard access governance, JSM incident response, Confluence policy docs, Opsgenie resilience, Compass asset inventory, and Atlassian AI governance — via the posture collectors (activating on live credentials + plan).
Built · awaiting live verificationAzure DevOps
Reads Azure DevOps Boards, Repos, Pipelines, and Advanced Security alerts — work-item throughput & lead time, build/deployment frequency, change-failure rate, repository staleness, and native SAST/dependency/secret findings — to compute Delivery Health, Technical Debt, and Security Readiness from real data.
Built · awaiting live verificationCloud
Supabase
Authenticates a personal access token against the Supabase Management API and reads each project's security advisors (RLS, exposed tables, auth) plus the Postgres version to feed Security Readiness, Cloud Health, and the Lifecycle (EOL) inventory.
Live-verifiedAmazon Web Services
SigV4-signed read-only access to Security Hub (active findings) and Cost Explorer (spend) to compute Security Readiness and Cloud Health (security posture).
Built · awaiting live verificationMicrosoft Azure
Reads Azure Resource Manager + Microsoft Defender for Cloud: resource inventory, secure score, security assessments, and Advisor recommendations to compute Cloud Health and Security Readiness.
Built · awaiting live verificationGoogle Cloud
Authenticates a read-only service account (JWT-bearer) to read Cloud Resource Manager + Compute inventory and Security Command Center findings — feeding Security Readiness and Cloud Health.
Built · awaiting live verificationOracle Cloud Infrastructure
Signs read-only OCI API calls (HTTP-signature, no SDK) to read Cloud Guard problems, IAM posture, compartments, resource inventory, monitoring alarms, spend, and database-service posture (availability, versions, backups) — feeding Cloud Health, Security Readiness, and the Lifecycle (EOL) inventory.
Built · awaiting live verificationDatadog
Reads Datadog monitors, SLOs, incidents, and optional usage cost summaries to feed Delivery Health and Cloud Health from aggregate observability signals.
Built · awaiting live verificationDynatrace
Reads Dynatrace entities, problems, and SLOs to feed Delivery Health and Cloud Health with aggregate reliability and incident signals.
Built · awaiting live verificationElastic
Reads Elastic cluster health plus aggregate alerting and Elastic Security detection summaries where available, without storing raw logs or event bodies.
Built · awaiting live verificationOpenSearch
Reads OpenSearch cluster health plus aggregate Alerting and Security Analytics summaries where available, without storing raw documents.
Built · awaiting live verificationSplunk
Reads Splunk server info, saved-search/alert summaries, fired-alert summaries, and optional index counts without exporting raw events.
Built · awaiting live verificationAI & Data
AI Spend (OpenAI + Anthropic)
Pulls AI tooling spend from provider billing/usage admin APIs (OpenAI Costs, Anthropic Cost Report) and, when a Cursor Admin API key is supplied, Cursor team seats at the published list price — the spend input to AI ROI.
Built · awaiting live verificationCursor
Reads Cursor Admin API per-member usage (active users, seats, tab suggestions/acceptances over a 28-day window) so AI ROI Adoption is measured from connected data rather than a typed percentage.
Built · awaiting live verification