Integrations
Continuous compliance monitoring. Evidence comes out signed.
Connect your stack read-only and the checks run on a schedule instead of the week before an audit. Every native check is a test that produces a signed, timestamped evidence artifact mapped to SOC 2, ISO 27001, and HIPAA controls, not a green checkmark you have to trust.
60+ integrations · 650+ native compliance checks across 30+ providers
Native checks
Deep, audit-grade scans, not shallow connections.
Cloud & infrastructure
144 checksAWS
IAM, S3 encryption, CloudTrail, security groups, password policy
115 checksAzure
RBAC, storage encryption, activity logs, network security groups
Microsoft 365
Entra ID, Defender, Exchange, SharePoint, and Teams security posture
55 checksGoogle Cloud
IAM, storage encryption, audit logging, firewall rules
Kubernetes
API server, RBAC, etcd, kubelet, and pod security configuration
Supabase
Row-level security, SSL enforcement, encryption at rest, backups, org MFA
Cloudflare
SSL/TLS posture, DNSSEC, WAF, account 2FA, member roles
Version control & CI
Identity & access
Okta
MFA enforcement, password policy, session controls, user lifecycle
10 checksGoogle Workspace
2-step verification, sharing policies, mobile management, audit logs
Auth0
MFA, brute-force protection, password policies
JumpCloud
MFA, conditional access, device trust
OneLogin
MFA, password requirements, session timeouts
Security & monitoring
HR & people ops
BambooHR
Employee lifecycle, onboarding and offboarding evidence
Gusto
Employee lifecycle and payroll records
Deel
Employee and contractor lifecycle, contract compliance
Rippling
Employee lifecycle and device management
5 checksCheckr
Background check completion and adjudication status
Evidence & document sources
The long tail comes in through the tools you already use.
Jira
Tickets as change-management and remediation evidence
Linear
Issues as remediation and change evidence
Notion
Import policy and process documentation
Confluence
Import pages and runbooks
Google Drive
Import files and documents as evidence
Zendesk
Support tickets and help-center content
Intercom
Customer conversations as process evidence
Freshdesk
Support tickets as operational evidence
Email inbox
Forward to your org address, auto-classified and filed
What a check produces
A test, a finding, a signed artifact.
Read-only by construction
OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your infrastructure.
Signed findings
SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.
Mapped to controls
One MFA scan satisfies SOC 2 CC6.1 and HIPAA §164.312(d) via the shared control catalog, collected once.
Don’t see your stack?
New providers ship regularly, and guided evidence collection covers anything without a native integration, step-by-step walkthroughs with the result recorded and signed like any other artifact.
Connect and see
Fifteen minutes after connecting, you know your real posture.
Connect GitHub and cloud read-only. Vera runs the native checks and shows your control matrix, gaps, and prioritized next actions before you commit to anything.

