Connect one source, then verify one client
- Open Integrations and add the intended product. Give the connection a name that identifies its account, controller or region.
- Enter the fields for that product below. Obtain credentials through the vendor administrator responsible for the intended account; a field list does not grant API entitlement or permissions.
- Review the saved connection outcome, then use Clients & sites to discover and explicitly assign the correct source records. Compare identifiers as well as names.
- For evidence sources, use Sync now, inspect Sync history, and check one client’s source and observation time. Directory sources instead use Import clients and Refresh client records.
- Compare the available observations with the control’s requirements before running checks.
Choose your product
Veeam
Veeam
This connection targets Veeam Service Provider Console, not an arbitrary Veeam Backup & Replication server. Supply a read-only VSPC account and reachable console URL; the connector assumes port 1280. A successful backup is not proof of successful restoration.Map: Each VSPC client company instanceUid.
Available observations: Backup protection provider, Last successful backup, Backup job state, Protected workload.Use the vendor’s current instructions for credential preparation: VSPC authentication reference.
Acronis Cyber Protect Cloud
Acronis Cyber Protect Cloud
Use the datacentre URL associated with the API client. An optional Root tenant ID restricts traversal; blank traverses accessible customer tenants. Verify the resulting client list. Protection and successful-backup observations do not prove recoverability.Map: Each accessible Acronis customer tenant UUID.
Available observations: Backup protection provider, Last successful backup, Backup job state.
SentinelOne
SentinelOne
Use a token for the intended management console and site access. The connector reports EDR presence/health; RMM management is a separate observation.Map: Each SentinelOne site ID.
Available observations: EDR installed, EDR health, EDR version, EDR policy group, Reported threat, Open threat count.
Huntress
Huntress
The current Alignr connector uses the public/private API key pair for Huntress API v1. Huntress has announced newer user-based credentials; confirm that the issued credentials support this path before rollout. Inspect organization mappings. See Huntress’s credential update. Health is derived from callback recency. Agent version is deliberately not emitted; absence of that predicate is not a setup failure.Map: Each Huntress organization ID.
Available observations: EDR installed, Last EDR check-in, EDR health, Reported threat.Vendor preparation: Huntress current API reference.
CrowdStrike Falcon
CrowdStrike Falcon
This connector uses Flight Control child CIDs. Prepare credentials able to enumerate the intended children and use the correct cloud region. It does not supply RMM management, EDR version or EDR check-in observations.Map: Each Flight Control child CID.
Available observations: EDR installed, EDR health, Reported threat.
ConnectSecure
ConnectSecure
Use the V4 tenant/application credentials and correct pod. The current company-discovery endpoint requires validation against your pod’s API documentation; do not treat saving credentials as production acceptance. Confirm one company mapping and real findings before broad rollout.Map: Each discovered company ID.
Available observations: Missing patch, Reported vulnerability, Highest vulnerability severity, Open vulnerability count.
Tenable Vulnerability Management
Tenable Vulnerability Management
This connector is designed for an MSSP Portal container and discovers child containers. Its parent credential needs the ability to mint read-only child keys. It supplies vulnerability findings and maximum severity, not open-count or missing-patch observations.Map: Each MSSP child container UUID.
Available observations: Reported vulnerability, Highest vulnerability severity.Vendor preparation: Tenable MSSP child-key requirements.