Integration-led. Built for the modern growing company.

Mycroft meets you where you work. Our integrations give you the visibility and control you need to scale securely.
Find out more

Frequently asked questions

How Mycroft's integrations work, what they can see, and what they replace.
It connects to a system you already run using read-only credentials, then continuously tests the controls that depend on that system and stores the results as dated evidence. For AWS that means testing encryption, logging and IAM configuration daily; for Okta it means building the account inventory behind user access reviews; for GitHub it means capturing the pull request approval behind every production change. The evidence is what an auditor samples during fieldwork.
No. Every integration is read-only by default. Mycroft reads configuration, identity and metadata; it cannot create, modify or delete resources, reset credentials or change policy. The two optional exceptions are explicit and scoped: creating remediation tickets in one project you nominate in Jira, Linear or Asana, and posting notifications to Slack channels you invite it to.
SOC 2, ISO 27001 and HIPAA are mapped explicitly on every integration page, control by control. The same evidence also supports GDPR, PIPEDA, CPRA, CMMC, FedRAMP and ISO 42001 programs, because the underlying controls (access management, encryption, logging, change management, vulnerability remediation) are shared across frameworks rather than duplicated per framework.
Tell us. The catalogue here is the set of first-party integrations with documented control mappings, and it grows based on what customers actually run. Where no integration exists yet, evidence for that system can be collected manually into Mycroft with the same review and expiry handling, so the control isn't left unevidenced while the integration is built.
Yes. That combination covers the majority of a SOC 2 Type II report. AWS evidences the infrastructure controls (CC6.1, CC6.6, CC7.1, A1.2), GitHub evidences change management (CC8.1), and Okta supplies the identity inventory behind access provisioning and removal (CC6.1 through CC6.3). Adding an HR system closes the loop by supplying the hire and termination dates those access controls are measured against.
Compliance

Real enterprise security, compliance next.

We help you navigate SOC 2, PIPEDA, GDPR, HIPAA, CMMC, FedRAMP, FedRAMP 20X and other frameworks that we stay on top of.

We turn the compliance nightmare into a dream

Talk to us