Product · GRC integrations
Evidence into Drata and Vanta
A phase-gated path for sending sanitized AI-tool identity records to the GRC platform your evidence reviewers already use.
Planned export path
The register goes where evidence work already happens
The integration surface stays phase-gated until the connector work ships. The local evidence file remains available for manual upload.
Drata first
A future Custom Connection will receive sanitized register rows as evidence records. No live connection or sync state is shown today.
Vanta second
A future partner integration will carry the same bounded identity fields after its platform review and test-tenant work are complete.
Data boundary
Tool identity only
The export boundary is the same as the dashboard and device evidence contract.
Eligible fields
Tool id, type, version, provider, scope, evidence label, collection source, framework tags, and artifact provenance.
Never exported
Code, prompts, config content, absolute paths, tool arguments and outputs, and secret values.
Where it stops
No payloads are read. A tool the collectors cannot defensibly match is counted as unattributable rather than guessed into a category.
Related
Each surface feeds the next: what the scan finds becomes a finding, and a finding becomes a reversible change.
FAQs about GRC integrations
Is a connector available today?
No. This page remains outside site navigation while WS-R7 is held. The working path today is keeprails report --evidence followed by manual upload.
What will be sent?
Sanitized tool-identity metadata only. Code, prompts, config content, tool arguments, outputs, and secrets stay on the machine.
What does the export prove?
It delivers the dated register as one evidence input. It is evidence, not certification.
See what your fleet is actually running
The scan runs locally and reports in your terminal. No account, no upload.
keeprails scan