Fits the toolchain you already run
No agents to deploy, no pipeline rewrites. Connect a repository and a read-only cloud role, and the first drift report lands in minutes.
Amazon Web Services
Organisations, multi-account role chaining, 240+ resource types, CloudTrail attribution of who made each change.
Google Cloud
Folder and project hierarchies, service account impersonation, asset inventory cross-checks.
Microsoft Azure
Management groups, subscriptions and resource groups with managed identity authentication.
GitHub
App installation, remediation pull requests with plan output and change table, automatic rebase, CODEOWNERS-based reviewer assignment.
GitHub Enterprise Server
Self-hosted instances reachable from an Enterprise runner inside your network.
S3 + DynamoDB
Locking-aware refresh that defers when your pipelines hold the lock.
Terraform Cloud / Enterprise
Workspace discovery, state version reads, run cross-referencing to suppress expected changes.
Terragrunt
Directory-tree discovery, dependency-aware ordering, per-module scan intervals.
GCS and Azure Blob
Versioned remote state with server-side encryption respected end to end.
Slack
Per-environment channel routing, severity thresholds, inline acknowledge, ignore and open-PR actions.
PagerDuty
CRITICAL findings escalate to the on-call rotation with deduplication keys per resource.
Webhooks
Signed JSON payloads for every event so you can drive your own automation.
Email digests
Daily or weekly summaries per environment for MEDIUM and LOW findings.
Anything missing?
The webhook and REST APIs cover integrations we do not ship natively, and the roadmap is driven by customer requests. Tell us what you need or read the documentation.