Sentrix

Platform · Integrations

Evidence from your real stack, not screenshots.

Read-only API connections pull cryptographically timestamped evidence continuously from your cloud, identity, devops, HR and ticketing tools, with no agents.

Integration catalog

Connect your stack. Evidence flows automatically.

Sentrix connects to the tools your team already runs. No agents. No configuration scripts. OAuth in, evidence out.

  • Cloud infrastructure: AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud
  • Identity and access: Okta, Azure AD / Entra, Google Workspace, JumpCloud
  • Developer and devops: GitHub, GitLab, Jira, Azure DevOps
  • Endpoint and MDM: SentinelOne, Microsoft Defender, CrowdStrike, Microsoft Intune
  • HR and people: Workday and other HR information systems
  • Security tools: vulnerability management and cloud security posture tools

Zero agents to deploy: read-only OAuth connections only, with no access beyond evidence collection. Evidence refreshes automatically, with no manual triggering and no quarterly screenshots.

Read-only by design

We read evidence. We never write to your systems.

Every Sentrix integration uses read-only OAuth scopes. We request the minimum permissions required to collect evidence and nothing more. Your security team can review every scope before connecting. No agents. No write access.

  • Read-only OAuth scopes documented for every integration
  • Sub-processor list published and kept current
  • Revoke access instantly from your identity provider: Sentrix stops collecting immediately

Custom integrations and API

Not in the catalog? Build it with the API.

The Sentrix API lets your engineering team pipe evidence from any internal system directly into your compliance program. Homegrown tools, custom SIEM events, internal audit logs: all treated as first-class evidence with the same cryptographic guarantees.

  • REST API with full OpenAPI documentation and sandbox environment
  • Webhook support for real-time evidence push from custom systems
  • Custom evidence schema builder: map any data structure to any control
  • Dedicated integration support during onboarding

Example of a custom evidence push:

POST /v1/evidence
{
  "control_id": "CC6.1",
  "source": "internal-siem",
  "title": "Privileged access review",
  "passed": true,
  "collected_at": "2026-04-19T14:22:07Z",
  "evidence_url": "https://siem.internal/r/8421"
}

The evidence is received and mapped to the equivalent controls across SOC 2, ISO 27001 and HIPAA.

See your stack connected and evidence flowing.

We connect to one of your cloud or identity tools live during the demo.

Contact us

Frequently asked questions

Do Sentrix integrations need agents or write access?
No. Every Sentrix integration uses read-only OAuth scopes. We request the minimum permissions required to collect evidence and nothing more, and your security team can review every scope before connecting. No agents are deployed and no configuration scripts are run: OAuth in, evidence out. Sentrix reads evidence and never writes to your systems.
How do we revoke Sentrix's access?
Revoke access instantly from your identity provider. Sentrix stops collecting immediately. Because connections are read-only OAuth grants rather than installed software, there is nothing to uninstall on your side, and the scopes granted to each integration are documented so you can see exactly what stops being read.
What if a tool is not in the catalog?
The Sentrix API lets your engineering team pipe evidence from any internal system directly into your compliance program. Homegrown tools, custom SIEM events and internal audit logs are treated as first-class evidence with the same cryptographic guarantees. The REST API comes with OpenAPI documentation and a sandbox, webhooks push evidence in real time, and a schema builder maps any data structure to any control.
How often is evidence refreshed?
Continuously. Evidence refreshes automatically on a configurable schedule with no manual triggering and no quarterly screenshots. Each item is timestamped cryptographically when collected, which gives your auditor a defensible record of when a configuration state was observed and from which source it was read.

Let's talk about your compliance program.

Last updated: 2026-09-17