Wherever your data lives, your AI can probably reach it. Tasirio connects read-only to each platform below and reads the security model — configuration and permission metadata — to show exactly what copilots, agents, and people can reach. Here's the honest list, in plain English.
That second number answers the strict question: the product ran end to end against this platform and recorded governed findings. The platform band on the home page answers an easier one — we held a real credential and reached the vendor's own system. More platforms clear that bar than this one, which is why the two counts differ.
Maps NAV permission sets and raw table access to flag over-broad SUPER rights, static web-service keys and AI-reachable financial data — read-only, through an outbound-only agent.
Reads Business Central permission sets and user assignments through the Automation API to surface over-broad SUPER rights, segregation-of-duties conflicts and direct table access that bypasses page controls — read-only, permission metadata only.
Reads Entra identities, SharePoint sharing, and sensitivity labels to reveal what Microsoft 365 Copilot and connected apps can reach.
Reviews Dynamics 365 Customer Engagement security roles to show which records Copilot for Sales and Service can surface.
Analyses Finance & Operations roles, duties, and segregation-of-duties to surface over-privileged access and data-entity export exposure.
Reviews Okta users, admin roles, and policies to expose the identity weaknesses every downstream app and AI inherits.
Reviews the health of the compliance programme itself — control tests that are failing, disabled or left unowned, high-severity vulnerabilities past their remediation SLA, evidence-collection integrations that have quietly stopped reporting, and third-party vendors left high-risk or unassessed.
Checks Azure SQL network exposure, auditing, encryption, and admin setup to flag databases open to over-broad or AI access.
Reviews Azure Synapse network, firewall, and access controls to surface analytics data exposed to over-broad roles or exfiltration.
Checks IAM policies, public storage, and Bedrock access to show what data your AWS AI services and roles can reach.
Reviews Unity Catalog grants, Delta Sharing, and model serving to show what Genie and Mosaic AI can reach.
Reviews Google Cloud identity, BigQuery, and storage to reveal what Vertex AI and Gemini can access across your projects.
Inspects Oracle Cloud access policies, public buckets, and network posture to surface over-broad access and AI-reachable data.
Examines Oracle Database roles and privileges to flag admin sprawl and data reachable by Select AI and APEX AI.
Analyses Snowflake roles, grants, and data shares to reveal which data Cortex AI and external shares can reach.
Checks Azure AI Foundry and Azure OpenAI for public access, weak authentication, disabled safety guardrails, and over-connected agents.
Reviews Fabric and Power BI row-level security and OneLake access to reveal reports and data Copilot data agents can reach.
Audits SAS Viya authorization, shared data libraries, and shared reports to surface sensitive analytics exposed broadly or through models.
Reviews Anthropic and OpenAI workspaces — owner sprawl, missing SSO/SCIM, stale members who still hold access, unrotated console keys, and project API keys that reach uploaded files and vector stores.
Reviews dbt Cloud service tokens and deployment credentials — tokens that are over-scoped or long-lived and unrotated, production credentials still on static password auth, and one credential shared across multiple environments.
Maps who can actually reach each folder on an on-premises file server — on Windows, share permissions intersected with NTFS permissions with Active Directory groups expanded to the people inside them; on Linux/Samba, the smb.conf share rules intersected with POSIX permissions. Read-only permission metadata through an outbound-only agent; no file is ever opened. Built and proven on our own Windows and Linux/Samba servers only — not yet offered to customers, and NAS appliances (NetApp, Isilon and similar) are not supported.
Reviews Google Workspace directory, OAuth grants, and Drive sharing to reveal what Gemini and third-party apps can access.
Checks the Notion pages and databases you list for public web publishing that exposes sensitive content to anyone, including AI.
Scans Smartsheet sheets and workspaces for public or external sharing and AI-reachable columns holding personal, credit, or bank data.
Reviews Airtable roles, tokens, and workspace sharing to surface bases exposed broadly and reachable by connected AI.
Reviews Box admin roles and external-collaboration settings to flag broad content that Box AI and outside parties can reach.
Reviews DocuSign users and webhooks to flag signed agreements that can egress externally or be opened by every admin.
Reviews Dropbox Business admin roles to flag team members whose broad content reach Dropbox Dash and Dropbox AI inherit.
Reviews Slack apps and the OAuth scopes they hold — apps that can read and index message history and files, Discovery-API apps with org-wide message reach, apps holding workspace-admin scopes, unapproved apps requesting broad access, and apps that can export the member directory.
Reviews Zoom admin roles and dormant licensed accounts to flag who can reach cloud recordings and Zoom AI Companion.
Reviews Addepar users for permission to access all current and future portfolio data, and for privileged or password-login accounts without two-factor authentication.
Checks the Supabase projects behind a property-management stack for a database reachable from the whole internet, SSL enforcement switched off, public storage buckets, anonymous sign-ins and outstanding security-advisor errors — plus Buildium staff accounts that are still active but have never signed in.
Reviews HubSpot roles, tokens, and record properties to surface sensitive data reachable by Breeze AI and external users.
Reviews Salesforce profiles, permission sets, and sharing rules to show which records Agentforce and connected apps can reach.
Reviews Zoho CRM sharing rules and roles to flag records exposed org-wide and reachable by Zia AI.
Reviews Retool groups, resource grants, and public apps to surface admin sprawl and data reachable by AI agents.
Reviews legal and contract systems for webhooks streaming client, matter and signed-contract data to outside endpoints, matter workspaces readable across the whole library, and expired agreements still held in an AI extraction store.
Reviews Guidewire users and roles for external users holding carrier-internal roles, deactivated accounts that kept their grants, and externally-assignable roles carrying far more permission than the work needs.
Reviews SpotOn point-of-sale staff for terminated employees whose login still works, and active staff omitted from labour reporting — a working till account nobody is accounting for.
Reviews Medius supplier bank details and accounts-payable access to surface payment fraud risk and over-broad or stale approvals.
Checks BILL payment controls — whether money can leave without approval, whether AP events are streamed to an outside endpoint, whether the organisation enforces MFA, and how many BILL organisations one credential reaches. Configuration only; never reads a bill, payment, or vendor record.
Reviews Acumatica data access and inquiries to surface sensitive vendor, cost, and margin data exposed through exports and broad scope.
Reviews Oracle Fusion data roles to surface org-wide access, reporting data-security bypass, and finance segregation-of-duties gaps.
Reviews NetSuite roles and tokens to surface over-broad access, cross-subsidiary overreach, and data reachable by AI and reporting.
Checks Oracle Utilities web-service endpoints for missing authentication, plaintext connections, and weak default security.
Reviews SAP S/4HANA and BTP identities to surface over-privileged finance and integration access and data reachable by AI.
Reviews BambooHR fields and users to flag regulated employee data reachable by one integration key and dormant accounts.
Checks the ADP worker data model to flag regulated employee data reachable by a single integration credential with only masking.
Reads Paychex company configuration to show how many payroll companies one integration credential reaches, and where a company's legal identifier is a personal Social Security Number. Deliberately never reads worker records.
Reviews SAP SuccessFactors roles and tokens to surface over-broad access and sensitive HR data reachable by AI and integrations.
Reviews Workday roles and integration tokens to surface over-broad access and HR data reachable by AI and agents.
Reviews ServiceNow privileged accounts and roles to flag admins without multi-factor authentication and excessive or dormant access.
Audits Zendesk roles, tokens, and data settings to surface weak authentication and ticket data reachable by AI agents.
Reviews Azure DevOps pipelines and service connections to surface secrets and code exposed to over-broad automation and AI agents.
Reviews GitHub organisation roles, Copilot policy, and repo protections to surface over-privileged access and code reachable by AI.
Scans the Softbase Evolution dealer database to surface stored card, bank, and identity data reachable by broad read access.
Reviews John Deere Operations Center organizations, partnerships, users, and equipment telematics to reveal what one dealer integration credential — and any AI grounded on it — can reach across customers' machine, location, and operations data. Built for ag-equipment dealers; reads the access model only, never field or agronomic content.
Reviews Geotab MyGeotab user clearances and data scopes to find accounts that can see every vehicle’s location and every driver’s details — drivers scoped to the entire fleet, full-reach accounts still signing in with a password instead of single sign-on, and dormant administrators that are still active.
In development
Built and grounded against each vendor's real API, waiting on a live tenant to prove them against. Want one sooner? Design partners get early access — and shape what we prove first.
Airtable · File share (on-premises) — Windows or Linux/Samba · Slack
Hospitality & Travel · Insurance · Legal & Contract (CLM) · Real Estate & Property · Wealth & Investment Mgmt
Acumatica ERP · Oracle Fusion Cloud · Oracle NetSuite · Oracle Utilities · SAP S/4HANA
Tell us which one matters most — click it above, or ask for something we haven't listed. Early-access partners get theirs built first, try it on their own systems, and pay nothing extra for it.
Coverage expands continuously, and some connectors are in live-certification — a handful of enterprise systems (e.g. SAP, Workday, NetSuite) are built and grounded on the real API but pending a live environment to certify. Each connector reads the security and configuration model, and each card says what that means for that platform — three of them read more than metadata because the check cannot exist without it: Medius reads supplier bank-account numbers (stored masked), Softbase Evolution reads cardholder column names and row counts (never a value), and Notion reads the body text of pages you have Published to the web, pattern-matched in memory so we can tell you a public page holds regulated data (only the labels are stored). Ask us about the status of any specific platform, or request one we don't list yet.
All product and company names shown are trademarks™ or registered® trademarks of their respective owners. The colored initials are Tasirio's own marks; their use here indicates read-only integration compatibility only and does not imply any affiliation with, sponsorship by, or endorsement from these companies.
Compliance Audit Engine
Tasirio checks your environment against the frameworks below and maps each open finding to the specific compliance controls it affects — tracked, owned, and regenerated on every scan.
Risk-tiered rules for deploying AI — transparency, safety, and accountability for AI agents and Copilots.
The international standard for AI Management Systems (AIMS) — responsible development and use of AI.
Framework for managing the risk and trustworthiness of AI systems across their whole lifecycle.
The top critical security risks specific to large language models and generative-AI applications.
Trust-services criteria: security, availability, processing integrity, confidentiality, and privacy.
The global standard for managing information security through a comprehensive ISMS.
Catalog of security & privacy controls for information systems — baseline protection against threats.
The Cybersecurity Framework — govern, identify, protect, detect, respond, and recover.
Consensus-driven best practices for securely configuring IT systems and hardening infrastructure.
US government program standardizing security assessment and authorization for cloud services.
EU regulation governing data protection and privacy for individuals in the EU and EEA.
California privacy laws granting consumers rights over their personal data and secure handling.
US law protecting the privacy and security of protected health information (PHI).
Regulates the collection, use, and accuracy of consumer credit information.
Requires financial institutions to safeguard consumers’ nonpublic personal information.
Protects investors through stronger corporate financial disclosure and data controls.
Security standard for organizations handling branded credit-card (cardholder) data.
Safeguards Federal Tax Information handled by state and local agencies.
Framework coverage expands continuously. Mapping shows the controls a finding implicates — it is not a certification of your organization, and Tasirio is not affiliated with or endorsed by these bodies.