● Connectors

Coverage for the platforms your AI actually uses.

Wherever your data lives, your AI can probably reach it. Tasirio connects read-only to each platform below and reads the security model — configuration and permission metadata — to show exactly what copilots, agents, and people can reach. Here's the honest list, in plain English.

58connectors
22live-proven on real data
11categories

That second number answers the strict question: the product ran end to end against this platform and recorded governed findings. The platform band on the home page answers an easier one — we held a real credential and reached the vendor's own system. More platforms clear that bar than this one, which is why the two counts differ.

Live-proven We have run Tasirio end to end against a real server for this platform and it produced governed findings. Beta Built against this vendor's documented API, endpoint by endpoint — but we have not yet completed a run that recorded findings, so nothing here proves a check fires on a real estate. Expect corrections on first contact with yours. Available to pilot at a reduced rate. Some platforms named on the home page appear here as Beta: that list means we held a real credential and reached the vendor; this badge is the stricter, separate question of whether the product has run end to end. In development Built, but you cannot connect it yet — it has no self-serve setup, so it is not available to pilot. Talk to us if you need it next.

Microsoft 365 & Dynamics

5 connectors · 4 live-proven
Dynamics NAV (on-premises)Live-proven

Maps NAV permission sets and raw table access to flag over-broad SUPER rights, static web-service keys and AI-reachable financial data — read-only, through an outbound-only agent.

Dynamics 365 Business Central (online)Live-proven

Reads Business Central permission sets and user assignments through the Automation API to surface over-broad SUPER rights, segregation-of-duties conflicts and direct table access that bypasses page controls — read-only, permission metadata only.

Microsoft 365 & Entra IDLive-proven

Reads Entra identities, SharePoint sharing, and sensitivity labels to reveal what Microsoft 365 Copilot and connected apps can reach.

Microsoft Dataverse & Dynamics 365 CELive-proven

Reviews Dynamics 365 Customer Engagement security roles to show which records Copilot for Sales and Service can surface.

Dynamics 365 Finance & OperationsBeta

Analyses Finance & Operations roles, duties, and segregation-of-duties to surface over-privileged access and data-entity export exposure.

Identity & access

2 connectors · 1 live-proven
OktaLive-proven

Reviews Okta users, admin roles, and policies to expose the identity weaknesses every downstream app and AI inherits.

Vanta, Drata & SecureframeIn development

Reviews the health of the compliance programme itself — control tests that are failing, disabled or left unowned, high-severity vulnerabilities past their remediation SLA, evidence-collection integrations that have quietly stopped reporting, and third-party vendors left high-risk or unassessed.

Cloud & data platforms

8 connectors · 5 live-proven
Azure SQLBeta

Checks Azure SQL network exposure, auditing, encryption, and admin setup to flag databases open to over-broad or AI access.

Azure Synapse AnalyticsLive-proven

Reviews Azure Synapse network, firewall, and access controls to surface analytics data exposed to over-broad roles or exfiltration.

Amazon Web ServicesLive-proven

Checks IAM policies, public storage, and Bedrock access to show what data your AWS AI services and roles can reach.

DatabricksLive-proven

Reviews Unity Catalog grants, Delta Sharing, and model serving to show what Genie and Mosaic AI can reach.

Google CloudLive-proven

Reviews Google Cloud identity, BigQuery, and storage to reveal what Vertex AI and Gemini can access across your projects.

Oracle Cloud InfrastructureBeta

Inspects Oracle Cloud access policies, public buckets, and network posture to surface over-broad access and AI-reachable data.

Oracle DatabaseBeta

Examines Oracle Database roles and privileges to flag admin sprawl and data reachable by Select AI and APEX AI.

SnowflakeLive-proven

Analyses Snowflake roles, grants, and data shares to reveal which data Cortex AI and external shares can reach.

AI, analytics & BI

5 connectors · 2 live-proven
Azure AI FoundryLive-proven

Checks Azure AI Foundry and Azure OpenAI for public access, weak authentication, disabled safety guardrails, and over-connected agents.

Microsoft Fabric & Power BILive-proven

Reviews Fabric and Power BI row-level security and OneLake access to reveal reports and data Copilot data agents can reach.

SAS ViyaBeta

Audits SAS Viya authorization, shared data libraries, and shared reports to surface sensitive analytics exposed broadly or through models.

AI Platforms & Assistants · bundleIn development

Reviews Anthropic and OpenAI workspaces — owner sprawl, missing SSO/SCIM, stale members who still hold access, unrotated console keys, and project API keys that reach uploaded files and vector stores.

dbtIn development

Reviews dbt Cloud service tokens and deployment credentials — tokens that are over-scoped or long-lived and unrotated, production credentials still on static password auth, and one credential shared across multiple environments.

Collaboration & content

10 connectors · 2 live-proven
File share (on-premises) — Windows or Linux/SambaIn development

Maps who can actually reach each folder on an on-premises file server — on Windows, share permissions intersected with NTFS permissions with Active Directory groups expanded to the people inside them; on Linux/Samba, the smb.conf share rules intersected with POSIX permissions. Read-only permission metadata through an outbound-only agent; no file is ever opened. Built and proven on our own Windows and Linux/Samba servers only — not yet offered to customers, and NAS appliances (NetApp, Isilon and similar) are not supported.

Google WorkspaceLive-proven

Reviews Google Workspace directory, OAuth grants, and Drive sharing to reveal what Gemini and third-party apps can access.

NotionBeta

Checks the Notion pages and databases you list for public web publishing that exposes sensitive content to anyone, including AI.

SmartsheetLive-proven

Scans Smartsheet sheets and workspaces for public or external sharing and AI-reachable columns holding personal, credit, or bank data.

AirtableIn development

Reviews Airtable roles, tokens, and workspace sharing to surface bases exposed broadly and reachable by connected AI.

BoxBeta

Reviews Box admin roles and external-collaboration settings to flag broad content that Box AI and outside parties can reach.

DocuSignBeta

Reviews DocuSign users and webhooks to flag signed agreements that can egress externally or be opened by every admin.

Dropbox BusinessBeta

Reviews Dropbox Business admin roles to flag team members whose broad content reach Dropbox Dash and Dropbox AI inherit.

SlackIn development

Reviews Slack apps and the OAuth scopes they hold — apps that can read and index message history and files, Discovery-API apps with org-wide message reach, apps holding workspace-admin scopes, unapproved apps requesting broad access, and apps that can export the member directory.

ZoomBeta

Reviews Zoom admin roles and dormant licensed accounts to flag who can reach cloud recordings and Zoom AI Companion.

CRM & business apps

9 connectors · 2 live-proven
AddeparIn development

Reviews Addepar users for permission to access all current and future portfolio data, and for privileged or password-login accounts without two-factor authentication.

Buildium & SupabaseIn development

Checks the Supabase projects behind a property-management stack for a database reachable from the whole internet, SSL enforcement switched off, public storage buckets, anonymous sign-ins and outstanding security-advisor errors — plus Buildium staff accounts that are still active but have never signed in.

HubSpotLive-proven

Reviews HubSpot roles, tokens, and record properties to surface sensitive data reachable by Breeze AI and external users.

SalesforceLive-proven

Reviews Salesforce profiles, permission sets, and sharing rules to show which records Agentforce and connected apps can reach.

Zoho CRMBeta

Reviews Zoho CRM sharing rules and roles to flag records exposed org-wide and reachable by Zia AI.

RetoolBeta

Reviews Retool groups, resource grants, and public apps to surface admin sprawl and data reachable by AI agents.

Clio, Ironclad & iManageIn development

Reviews legal and contract systems for webhooks streaming client, matter and signed-contract data to outside endpoints, matter workspaces readable across the whole library, and expired agreements still held in an AI extraction store.

GuidewireIn development

Reviews Guidewire users and roles for external users holding carrier-internal roles, deactivated accounts that kept their grants, and externally-assignable roles carrying far more permission than the work needs.

SpotOnIn development

Reviews SpotOn point-of-sale staff for terminated employees whose login still works, and active staff omitted from labour reporting — a working till account nobody is accounting for.

Finance & ERP

7 connectors · 2 live-proven
Medius AP AutomationLive-proven

Reviews Medius supplier bank details and accounts-payable access to surface payment fraud risk and over-broad or stale approvals.

BILL (Bill.com)Live-proven

Checks BILL payment controls — whether money can leave without approval, whether AP events are streamed to an outside endpoint, whether the organisation enforces MFA, and how many BILL organisations one credential reaches. Configuration only; never reads a bill, payment, or vendor record.

AcumaticaIn development

Reviews Acumatica data access and inquiries to surface sensitive vendor, cost, and margin data exposed through exports and broad scope.

Oracle Fusion CloudIn development

Reviews Oracle Fusion data roles to surface org-wide access, reporting data-security bypass, and finance segregation-of-duties gaps.

Oracle NetSuiteIn development

Reviews NetSuite roles and tokens to surface over-broad access, cross-subsidiary overreach, and data reachable by AI and reporting.

Oracle UtilitiesIn development

Checks Oracle Utilities web-service endpoints for missing authentication, plaintext connections, and weak default security.

SAP S/4HANAIn development

Reviews SAP S/4HANA and BTP identities to surface over-privileged finance and integration access and data reachable by AI.

HR & payroll

5 connectors
BambooHRBeta

Reviews BambooHR fields and users to flag regulated employee data reachable by one integration key and dormant accounts.

ADPBeta

Checks the ADP worker data model to flag regulated employee data reachable by a single integration credential with only masking.

PaychexBeta

Reads Paychex company configuration to show how many payroll companies one integration credential reaches, and where a company's legal identifier is a personal Social Security Number. Deliberately never reads worker records.

SAP SuccessFactorsIn development

Reviews SAP SuccessFactors roles and tokens to surface over-broad access and sensitive HR data reachable by AI and integrations.

WorkdayIn development

Reviews Workday roles and integration tokens to surface over-broad access and HR data reachable by AI and agents.

ITSM & ticketing

2 connectors
ServiceNowBeta

Reviews ServiceNow privileged accounts and roles to flag admins without multi-factor authentication and excessive or dormant access.

ZendeskBeta

Audits Zendesk roles, tokens, and data settings to surface weak authentication and ticket data reachable by AI agents.

DevOps & code

2 connectors · 2 live-proven
Azure DevOpsLive-proven

Reviews Azure DevOps pipelines and service connections to surface secrets and code exposed to over-broad automation and AI agents.

GitHubLive-proven

Reviews GitHub organisation roles, Copilot policy, and repo protections to surface over-privileged access and code reachable by AI.

Agriculture & equipment

3 connectors · 2 live-proven
Softbase EvolutionLive-proven

Scans the Softbase Evolution dealer database to surface stored card, bank, and identity data reachable by broad read access.

John Deere Operations CenterLive-proven

Reviews John Deere Operations Center organizations, partnerships, users, and equipment telematics to reveal what one dealer integration credential — and any AI grounded on it — can reach across customers' machine, location, and operations data. Built for ag-equipment dealers; reads the access model only, never field or agronomic content.

GeotabIn development

Reviews Geotab MyGeotab user clearances and data scopes to find accounts that can see every vehicle’s location and every driver’s details — drivers scoped to the entire fleet, full-reach accounts still signing in with a password instead of single sign-on, and dormant administrators that are still active.

In development

19 more connectors in the build queue.

Built and grounded against each vendor's real API, waiting on a live tenant to prove them against. Want one sooner? Design partners get early access — and shape what we prove first.

Don't see a system you use?

Tell us which one matters most — click it above, or ask for something we haven't listed. Early-access partners get theirs built first, try it on their own systems, and pay nothing extra for it.

Request early access

Coverage expands continuously, and some connectors are in live-certification — a handful of enterprise systems (e.g. SAP, Workday, NetSuite) are built and grounded on the real API but pending a live environment to certify. Each connector reads the security and configuration model, and each card says what that means for that platform — three of them read more than metadata because the check cannot exist without it: Medius reads supplier bank-account numbers (stored masked), Softbase Evolution reads cardholder column names and row counts (never a value), and Notion reads the body text of pages you have Published to the web, pattern-matched in memory so we can tell you a public page holds regulated data (only the labels are stored). Ask us about the status of any specific platform, or request one we don't list yet.

All product and company names shown are trademarks™ or registered® trademarks of their respective owners. The colored initials are Tasirio's own marks; their use here indicates read-only integration compatibility only and does not imply any affiliation with, sponsorship by, or endorsement from these companies.

Compliance Audit Engine

Every finding, mapped to the controls it implicates.

Tasirio checks your environment against the frameworks below and maps each open finding to the specific compliance controls it affects — tracked, owned, and regenerated on every scan.

AI Governance

EU AI Act

Risk-tiered rules for deploying AI — transparency, safety, and accountability for AI agents and Copilots.

AI Governance

ISO 42001

The international standard for AI Management Systems (AIMS) — responsible development and use of AI.

AI Governance

NIST AI RMF

Framework for managing the risk and trustworthiness of AI systems across their whole lifecycle.

AI Governance

OWASP LLM Top 10

The top critical security risks specific to large language models and generative-AI applications.

Security

SOC 2

Trust-services criteria: security, availability, processing integrity, confidentiality, and privacy.

Security

ISO 27001

The global standard for managing information security through a comprehensive ISMS.

Security

NIST 800-53

Catalog of security & privacy controls for information systems — baseline protection against threats.

Security

NIST CSF 2.0

The Cybersecurity Framework — govern, identify, protect, detect, respond, and recover.

Security

CIS Benchmarks

Consensus-driven best practices for securely configuring IT systems and hardening infrastructure.

Security

FedRAMP

US government program standardizing security assessment and authorization for cloud services.

Data Privacy

GDPR

EU regulation governing data protection and privacy for individuals in the EU and EEA.

Data Privacy

CCPA / CPRA

California privacy laws granting consumers rights over their personal data and secure handling.

Data Privacy

HIPAA

US law protecting the privacy and security of protected health information (PHI).

Data Privacy

FCRA

Regulates the collection, use, and accuracy of consumer credit information.

Financial & Regulated

GLBA

Requires financial institutions to safeguard consumers’ nonpublic personal information.

Financial & Regulated

SOX

Protects investors through stronger corporate financial disclosure and data controls.

Financial & Regulated

PCI DSS

Security standard for organizations handling branded credit-card (cardholder) data.

Financial & Regulated

IRS 1075 (FTI)

Safeguards Federal Tax Information handled by state and local agencies.

Framework coverage expands continuously. Mapping shows the controls a finding implicates — it is not a certification of your organization, and Tasirio is not affiliated with or endorsed by these bodies.